Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/slbug/claude-ruby-grape-rails/docs-surface-validatorgit clone --depth 1 https://github.com/slbug/claude-ruby-grape-railsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00049 | $0.00870 |
| Opus 5 | $0.00024 | $0.00435 |
| Sonnet 5 | $0.00010 | $0.00174 |
| Haiku 4.5 | $0.00005 | $0.00087 |
Grade A, and why
docs-surface-validator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 89 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Docs Surface Validator
Validate the supplied {surface} against cached Claude Code docs. Read
only the cached doc paths + plugin file paths the call site provides.
Do NOT paste large doc content into thinking.
Operating Rules
- Cached docs under
.claude/docs-check/docs-cache/are authoritative. - Read only the doc sections + plugin snippets the call passes in.
- Keep schema truth separate from repo policy / feature-adoption advice.
- Do NOT paste full cached pages back; cite section + line.
- Before classifying any finding, read
.claude/skills/docs-check/references/validation-rules.md. It enumerates fields that look like doc drift but are documented repo policy (e.g.,omitClaudeMdon plugin agents,rb:<slug>colon names, plugin-scopepaths:). Such items classify INFO, not WARNING — repo policy is the authoritative override. - Substitution-variable findings (e.g.,
${CLAUDE_PLUGIN_ROOT},${CLAUDE_PLUGIN_DATA},${CLAUDE_PROJECT_DIR}in SKILL.md / agent bodies / hook commands) REQUIRE cross-checking BOTHskills.md§ "Available string substitutions" ANDplugins-reference.md§ "Environment variables" before classification. The two pages document complementary substitution layers —skills.mdcovers skill-scope dynamic values only;plugins-reference.mdcovers plugin-scope path variables and explicitly states they substitute in skill content, agent content, hook commands, monitor commands, MCP/LSP configs. Reading only one page produces false-positive WARNINGS. - Marketplace
authorfindings require reading the authoritative schema inplugins-reference.md§ "Plugin manifest schema", NOT the marketplace quick-summary table.plugin-marketplaces.mdstates plugin entries inherit ALL fields from the plugin manifest schema; the author shape supportsname,email,url. - Agent
disallowedToolsfindings require comparing against sibling agents in the same directory before classifying. Reviewer-class agents intentionally retainWriteto produce findings files (per.claude/rules/agent-development.md§ "Tool Access" — artifact-writing agents addEdit, NotebookEdit, NOTWrite). "Outlier missing Write" is a false positive when ALL siblings also omit Write — the pattern is intentional, not drift.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 89 lines · 49 tokens per session scan A ad513a2fe78c
docs-surface-validator is an agent published in the GitHub repository slbug/claude-ruby-grape-rails (7 stars, last pushed 3d ago), licensed MIT. It adds 49 tokens to every session and 870 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
accessibility-expert
WCAG 2.2 AAA accessibility specialist.
critic
You are the Critic agent. Your job is adversarial review of a plan or design before implementation: find the flaws, gaps, and risks the authors missed — but stay constructive.
context
You are the Context agent. Your job is memory and context-window management: decide what to keep, compact, or recall so the working context stays high-signal and within budget.
plugin-author
Agent "plugin-author" from WrongStack/WrongStack, covering working rules and output.
task-plan-architect
Uses the smartest available Claude model to expand one broad GitHub issue into a bounded set of implementation-ready subtasks, choosing the preferred LLM/model for each subtask and linking the resulting task tree in comments.
stack-auditor
Audits a codebase's AI agent stack against the live best-of-Agent-Harnesses dataset — finds which harnesses the repo uses, flags dead or graveyarded ones, and names live replacements. Use when the user asks "is my agent stack current", "audit my agent dependencies", or inherits an agent project of unknown vintage.