shepherd

A persistent advisor that follows a work item through six phases and gives advice about design, trade-offs, and guiding principles. It advises workers but does not block them; questions about task routing go elsewhere.

In plain words
What is it for?
Answering substance questions and checking proposed work against the PDS whitepaper, philosophy, and ethos.
Why use it?
It keeps the project's stated philosophy in view while work progresses without stopping the team.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/rmzi/portable-dev-system/shepherd
Clone the repo
git clone --depth 1 https://github.com/rmzi/portable-dev-system
Per session 74 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,354 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 1 finding. Scan, not verified.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00074 $0.02354
Opus 5 $0.00037 $0.01177
Sonnet 5 $0.00015 $0.00471
Haiku 4.5 $0.00007 $0.00235

Measured 2d ago against content hash bb3406c03ab7, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade C, and why

shepherd scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Tells the agent never to refusehighAnti-refusal

Suppressing the ability to decline removes a core safety control; a later harmful request then succeeds.

**Degraded load.** If `docs/whitepaper.md` is absent, fall back to `CLAUDE.md` + `docs/philosophy.md` only and log the degradation as the first journal entry for the current swarm. Never refuse to operate — always give b
agents/shepherd.md · 190 lines

The source is not reproduced here

No licence file

A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.

Read it on GitHub

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 190 lines · 74 tokens per session scan C bb3406c03ab7

Subscribe to this mod's changes

shepherd is an agent published in the GitHub repository rmzi/portable-dev-system (24 stars, last pushed 28d ago), with no licence file. It adds 74 tokens to every session and 2,354 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it C with 1 finding (tells the agent never to refuse). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

explorer

Read-only codebase navigator. Maps files, traces dependencies, surfaces existing patterns. Cheap — use constantly before implementation tasks.

timgranlundmarsden/claude-agent-flow · 27 tokens

critic

Adversarial code critic. Tries to break code with edge cases and failure scenarios. Returns FAIL/PASS. Used in /build and /review loops.

timgranlundmarsden/claude-agent-flow · 34 tokens

codemap

Defines agent personalities (Orchestrator, Explorer, Librarian, etc.) and manages their configuration lifecycle. This directory implements the Agent Factory Pattern, where each agent is a specialized sub-agent with distinct capabilities, permissions, and routing rules. The Orchestrator agent (src/agents/index.ts)…

alvinunreal/oh-my-opencode-slim · 0 tokens

adapter_grok

Grok is an eagerly registered stock-TUI adapter. RimZ launches grok, installs passive global hooks in ${GROKHOME:-/.grok}/hooks/rimz.json, and enriches each session from its durable updates.jsonl, summary.json, signals.json, and optional events.jsonl files. ACP and provider-private billing APIs stay outside this…

rimio-ai/rimz · 0 tokens

librarian

External reference researcher — looks up library docs, framework conventions, OSS examples. Read-only, no memory injection. (Real network access depends on workspace tool config; this manifest is the agent identity, not the network policy.).

Timeflys2018/zeyi · 48 tokens

seo-auditor

Agent "seo-auditor" from rizvee/multimodel-dev-os, covering seo auditor agent spec and focus areas.

rizvee/multimodel-dev-os · 0 tokens