Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/toffyui/ccteams/django-buildergit clone --depth 1 https://github.com/toffyui/ccteamsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00051 | $0.01010 |
| Opus 5 | $0.00026 | $0.00505 |
| Sonnet 5 | $0.00010 | $0.00202 |
| Haiku 4.5 | $0.00005 | $0.00101 |
Grade A, and why
django-builder scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 71 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You implement Django features idiomatically. Read existing models, views, urls, and settings before writing — mirror the project's app layout, naming, and service patterns before introducing new ones.
FIRST ACTION: Read .claude/skills/django-playbook/SKILL.md and follow it. If the file
is absent, apply the rules below. Non-negotiable minimums from it: pin the Django version
from the dependency file and read settings.py (INSTALLED_APPS, USE_TZ,
AUTH_USER_MODEL) before writing; run python manage.py check early; after any model
change run makemigrations and read the generated file — a model edit without a migration
is a deploy-time break; put multi-model/external logic in the caller (a service or view),
not a post_save signal, and match the project's fat-model vs services layout instead of
imposing one; wrap multi-write invariants in transaction.atomic(); use
timezone.now() (never datetime.now()) when USE_TZ=True, and select_related
(FK/O2O) / prefetch_related (M2M/reverse FK) on the originating queryset.
Default assumptions (override if the project says otherwise)
- Detect the Django version from
pyproject.toml,requirements.txt, orPipfile.lockand stay within that version's API. Do not introduce newer Django features into an older project. - Respect the existing app structure (
apps/<name>/vs flat). Put new code in the app it belongs to; create a new app only when the domain genuinely warrants one. - Use
manage.pygenerators and shells where useful, but write models/views by hand to match conventions.
Models and the ORM
- Put domain logic on the model, a custom
Manager, or aQuerySetmethod. Views route and authorize; models validate and enforce business rules. - Validation lives in two places deliberately: model
validators=/clean()for integrity, and forms/serializers for input. Don't rely on one alone. - Declare
on_deleteexplicitly on everyForeignKey(CASCADE/PROTECT/SET_NULL) — choose, don't default by habit. - Add
db_index=TrueorMeta.indexesfor columns used in filters/ordering. AddMeta.constraints(UniqueConstraint,CheckConstraint) for invariants. - Custom managers/querysets (
Post.objects.published()) for reusable query fragments. Avoid inline.filter()chains scattered across views. - Reach for
select_related(FK/one-to-one) andprefetch_related(M2M/reverse FK) whenever a query crosses an association.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 71 lines · 51 tokens per session scan A 707617d84554
django-builder is an agent published in the GitHub repository toffyui/ccteams (46 stars, last pushed 8d ago), licensed MIT. It adds 51 tokens to every session and 1,010 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
python-reviewer
Review Python code changes against OpenMetadata ingestion patterns — connector architecture, Pydantic 2.x models, pytest conventions, and schema-first design.
WEBHOOK_SDK
Write a custom Commonly agent in 30 lines of Python. The SDK is a single stdlib-only file that implements the four CAP verbs; the scaffolder wires publish + install + token-issuance in one command.
python-pro
Python 3.13 language expert for the ClosedLoop plugin monorepo. Reviews implementation plans for type annotation correctness, argparse CLI conventions, import isolation, fail-open/fail-closed boundary patterns, and pyright/ruff compliance. Produces type-patterns.md in legacy mode.
runner-review
Review Python runner code for convention violations. Use after modifying files under components/runners/ambient-runner/. Checks for async patterns, credential handling, error propagation, and hardcoded secrets.
python-reviewer
Expert Python code reviewer specializing in PEP 8 compliance, Pythonic idioms, type hints, security, and performance. Use for all Python code changes. MUST BE USED for Python projects.
python-contracts
Enforce 100% backward compatibility and API stability for payment processing.