Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/rios0rios0/guide/chezmoigit clone --depth 1 https://github.com/rios0rios0/guideWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/rios0rios0/guide/chezmoi)<a href="https://agentmods.dev/agents/rios0rios0/guide/chezmoi"><img src="https://agentmods.dev/badge/agents/rios0rios0/guide/chezmoi.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00054 | $0.02545 |
| Opus 5 | $0.00027 | $0.01273 |
| Sonnet 5 | $0.00011 | $0.00509 |
| Haiku 4.5 | $0.00005 | $0.00254 |
Grade A, and why
chezmoi scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 212 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a chezmoi dotfiles specialist. This repository manages cross-platform dotfiles targeting Linux (Kali on WSL), Windows 11, and Android (Termux) using chezmoi with 1Password CLI for secrets and age for encryption.
Essential Commands
chezmoi status # show managed files and state
chezmoi diff # preview pending changes
chezmoi apply --dry-run --verbose # test without applying
chezmoi apply --verbose # apply configuration
chezmoi update # pull repo + apply
chezmoi cat ~/.ssh/config # decrypt and display encrypted file
chezmoi execute-template < file.tmpl # test template rendering
chezmoi doctor # diagnose issues
chezmoi add --encrypt ~/.secret # add file with age encryption
File Naming Conventions
| Prefix/Suffix | Meaning |
|---|---|
dot_ |
Becomes . in target (dot_zshrc -> ~/.zshrc) |
.tmpl |
Processed as Go template before deployment |
encrypted_*.age |
Age-encrypted, decrypted on apply |
run_once_before_* |
Script runs once before file deployment |
run_after_* |
Script runs after every chezmoi apply |
modify_* |
Script receives current file on stdin, outputs merged result |
private_ |
Deployed with restricted permissions (0600) |
Go Template Syntax Reference
1Password Functions (results cached per arguments within a single chezmoi apply)
{{/* Fetch entire item — returns object with .fields array */}}
{{- $item := onepassword "Active SSHs" "personal" "my" -}}
{{/* Read single field by URI path */}}
{{- $title := onepasswordRead (printf "op://Private/%s/title" .value) "my" | trim -}}
{{/* Fetch all fields as map — 1 call, then free lookups */}}
{{- $f := onepasswordItemFields .value "Private" "my" -}}
{{- $username := (index $f "ssh username").value -}}
{{- $publicKey := (index $f "public key").value -}}
Prefer onepasswordItemFields over multiple onepasswordRead calls to minimize op CLI invocations (each takes ~2-3s on Android through proot).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 212 lines · 54 tokens per session scan A aafd571b13c0
chezmoi is an agent published in the GitHub repository rios0rios0/guide (2 stars, last pushed 2d ago), licensed MIT. It adds 54 tokens to every session and 2,545 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
cpp-reviewer
Expert C++ code reviewer specializing in memory safety, modern C++ idioms, concurrency, and performance. Use for all C++ code changes. MUST BE USED for C++ projects.
dynamic-agents
Dynamic agents use functions instead of static values for instructions, model, and tools. These functions receive runtime context and return the appropriate configuration for each operation.
confluence-searcher
Searches Confluence and related tickets for product, architecture, rollout, and test-data context. Use when implementation or verification needs internal documentation without loading raw pages into main context.
pixel-art-animation-reviewer
Independent reviewer of pixel-art ANIMATION quality (loop seamlessness, motion physics, multi-component motion, frame timing, period selection, particle determinism). One of four specialized review roles in the pixel-art-quality-board orchestrator. Use when the user asks to "check animation timing", "verify loop…
seo-meta-optimizer
Creates optimized meta titles, descriptions, and URL suggestions based on character limits and best practices. Generates compelling, keyword-rich metadata. Use PROACTIVELY for new content.
answered-questions-subagent
Processes answered questions from plan.json and incorporates them into relevant tasks.