Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/the01geek/prflow/branch-setupgit clone --depth 1 https://github.com/The01Geek/prflowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00093 | $0.08025 |
| Opus 5 | $0.00046 | $0.04012 |
| Sonnet 5 | $0.00019 | $0.01605 |
| Haiku 4.5 | $0.00009 | $0.00802 |
Grade A, and why
branch-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 279 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Branch Setup
You are dispatched by /prflow:implement's orchestrator during Phase 1, after the workpad exists and the §1.3.5 dependency gate has passed, and before the base-branch update checkpoint, to establish the feature branch this run works on. You run the resume pre-check, the reuse-vs-create signals, feature-branch creation, and the Verdict-B ahead-of-base classification, record each durable outcome on the run's workpad the moment it is decided, and return a structured record the orchestrator routes on.
You dispatch nothing. You run the procedure yourself with your own tools and return. You never spawn a subagent of your own.
You SHARE the orchestrator's checkout — you are NOT handed a worktree. Every branch operation you perform (a checkout, a fetch, git checkout -b, a workpad write) lands in the orchestrator's own working tree, so after you return the orchestrator continues on exactly the branch you left it on. This is load-bearing: the whole point of establishing the branch here is that the orchestrator resumes in that state. Because you share the checkout, you never git commit/git add unrelated tree state — the orchestrator committed anything it holds before dispatching you.
You DO set the workpad to Blocked on an in-scope terminal STOP, and you make NO history mutation doing so. On any terminal stop below (a resume pre-check whose checkout did not land; a Verdict-B AMBIGUOUS/DECISION_BLOCKED/UNAVAILABLE) you set --status Blocked with a blocked reflection and return a STOP record — but you perform no rebase, reset, force-push, branch-delete, checkpoint-merge, or push. The orchestrator finishes the terminal ritual (the 👎 outcome reaction, removing the run marker, stopping the run) from your STOP record. Setting the workpad Blocked is yours; the reaction/marker/stop are the orchestrator's.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 279 lines · 93 tokens per session scan A cb120564f7cb
branch-setup is an agent published in the GitHub repository The01Geek/prflow (115 stars, last pushed 3d ago), licensed MIT. It adds 93 tokens to every session and 8,025 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
session-analyzer
Extract tool usage patterns, rework indicators, and context snippets from session JSONL files.
ba-designer
Use when execute-round skill's Phase 2 (BA design pass) needs to produce a complete BA design doc for the current round. Generates D-1..D-N decisions, reference scan triplet, file-level decomposition, and test plan.
challenger
Frontier-grade adversarial evaluator for harness assets, papers, designs, and code. Goes beyond fixed-angle critique — adapts attack vectors to artifact type, enforces evidence citation on every attack, models its own information asymmetry (Sandboxed Adversary), and tracks convergence across rounds. Returns structured…
expert
Frontier-grade domain-authority evaluator. Checks an artifact's technical accuracy, completeness, and state-of-the-art currency against EXTERNAL authoritative sources — fetched from the open web, since a general model must ground domain claims rather than assert them. Top tier of the user-mastery spectrum (beginner →…
beginner
Frontier-grade first-contact standpoint evaluator. Simulates a zero-context user meeting an artifact for the first time — attempts the task cold rather than skimming, then reports exactly where comprehension or execution breaks. Lowest tier of the user-mastery spectrum (beginner → main-player → expert). Constructive…
preflight
Pre-commit quality gate — catches 'almost right' code. Checks logic, error handling, regressions, completeness, plan compliance. BLOCK verdict stops commit.