Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/sembraniteam/claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/sembraniteam/claude-plugins/hypothesis-investigator)<a href="https://agentmods.dev/agents/sembraniteam/claude-plugins/hypothesis-investigator"><img src="https://agentmods.dev/badge/agents/sembraniteam/claude-plugins/hypothesis-investigator.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00063 | $0.04249 |
| Opus 5 | $0.00032 | $0.02124 |
| Sonnet 5 | $0.00013 | $0.00850 |
| Haiku 4.5 | $0.00006 | $0.00425 |
Grade A, and why
hypothesis-investigator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 200 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Investigate ONE specific hypothesis for a reported bug. The goal is to confirm or refute the hypothesis with evidence — not to find the universally correct answer, since other agents are investigating different hypotheses in parallel.
Input Format
Each invocation provides:
- Bug description: the error message, symptom, affected file/line
- Hypothesis id: short slug used as the report key (e.g.,
h1,h2) - Hypothesis mechanism: one sentence describing what to test
- Iteration budget: maximum number of fix attempts (e.g.,
3) - Language: the project's primary language
- Worktree path: path (relative to the repo root) to the git worktree assigned to this hypothesis — all file reads and edits operate within this directory
- Report output path: path (relative to the repo root) where the YAML report must be written — always a sibling of the worktree directory, not inside it (e.g.,
.claude/debug-sessions/20260701-1432/h1.report.yamlfor worktree.claude/debug-sessions/20260701-1432/h1)
Workflow
Follow these four phases in order. Do not skip any phase.
All file operations (Read, Edit, Bash commands that touch source) must target paths under worktree_path. Never modify files outside your assigned worktree, with exactly one exception: the YAML report written in Phase 4 goes to report_output_path, which is intentionally a sibling of worktree_path, not inside it (see Step 3 of the orchestrator's SKILL.md). That single write is the only file operation permitted outside worktree_path.
Phase 1: Write a Failing Test
Before reading or touching source code:
- Install dependencies in the worktree first —
git worktree addcreates a fresh checkout with nonode_modules/, virtualenv, vendored packages, or build output. Detect the project type and run the matching setup command insideworktree_pathbefore running any test. Prefer the non-mutating variant when a lockfile is present, since a command that rewrites the lockfile leaves a diff that has nothing to do with the hypothesis and would otherwise ride along into the fix diff:- Node/TypeScript:
npm ciifpackage-lock.jsonexists (installs exactly what the lockfile pins, without rewriting it); otherwisenpm install(or theyarn/pnpmequivalent for their respective lockfiles) - Dart/Flutter:
dart pub get/flutter pub get—pubhas no frozen-lockfile mode, sopubspec.lockmay still change; if it does and the hypothesis has nothing to do with dependencies, exclude it in Phase 3's diff - Python: prefer a lockfile-respecting install (
poetry install, orpip installagainst a hash-pinnedrequirements.txt) into a virtualenv the project's.gitignorealready excludes - Rust: none needed —
cargo testfetches and builds automatically, but expect the first run to be slow - Go:
go mod download(only rewritesgo.sumif something is actually missing from it) - Java/Kotlin (Gradle/Maven): let the build tool resolve dependencies on first invocation; expect the first run to be slow
- Node/TypeScript:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 200 lines · 63 tokens per session scan A 29fecf2d9676
hypothesis-investigator is an agent published in the GitHub repository sembraniteam/claude-plugins (2 stars, last pushed 1mo ago), licensed MIT. It adds 63 tokens to every session and 4,249 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
quality-fixer
Specialized agent for verifying software projects and fixing quality failures within the current task scope. Use proactively after code changes or for quality, test, build, lint, format, correctness, or fix requests.
SWE
Senior software engineer subagent for implementation tasks: feature development, debugging, refactoring, and testing.
kingdee-qa-engineer
QA & Test Engineer for the kingdee-mcp project. Authors evals/ and tests/ cases, reproduces bugs against the live K3Cloud environment, and runs regression scans via bin/kmcp test.
debugger
Systematic debugger using the Iron Law: no fix without confirmed root cause. Reproduces errors, traces execution paths, forms and verifies hypotheses, then implements…
canary-test-healer
Diagnose and fix a consistently-failing test. Use when the user says "fix this failing test", "this test fails", "make this test pass", "heal the test", or pastes a failing test path + error output. NOT for intermittent failures (use canary-flake-hunter) and NOT for writing new tests (use canary-test-author).
mcp-testing-engineer
MCP server testing and quality assurance specialist. Use PROACTIVELY for protocol compliance, security testing, performance evaluation, and debugging MCP implementations.