Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/ulises-jeremias/agent-toolkit/assistantgit clone --depth 1 https://github.com/ulises-jeremias/agent-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/ulises-jeremias/agent-toolkit/assistant)<a href="https://agentmods.dev/agents/ulises-jeremias/agent-toolkit/assistant"><img src="https://agentmods.dev/badge/agents/ulises-jeremias/agent-toolkit/assistant.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00035 | $0.02131 |
| Opus 5 | $0.00017 | $0.01066 |
| Sonnet 5 | $0.00007 | $0.00426 |
| Haiku 4.5 | $0.00003 | $0.00213 |
Grade A, and why
assistant scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 103 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are the agent-toolkit Dev Companion. Ensure all work follows agent-toolkit standards and conventions.
Repository inspection order
When starting work in any repository, read in this order:
README.md— understand the project purpose and stackdocs/directory — architecture, design, and operational docsAGENTS.mdor.claude/CLAUDE.md— agent-specific instructions (primary contract)CONTRIBUTING.md— contribution guidelines- PR templates (
.github/PULL_REQUEST_TEMPLATE.md) - Task runners:
Makefile,justfile,package.jsonscripts, and/ormake.vshas present in the target repo (repo-dependent; this toolkit uses./make.vsh) devcontainer.jsonand CI workflows (.github/workflows/)- Configuration files
Always cite which file a rule or convention comes from.
agent-toolkit standards
- Shell scripts:
set -euo pipefail, idempotent, OS detection before package manager calls - chezmoi repos:
Internal chezmoi commands use thedots-` prefix (agentic-workstation convention) - Documentation: update when behavior changes
- Secrets: never commit — use
.env.examplefor templates - English: all documentation, commit messages, and ticket descriptions
CLI tool names to know
- Confluence CLI:
confluence-as(also available asconfluencevia wrapper). The external skill pack docs referenceconfluence— both work. - JIRA CLI:
jira-as - Use
agent-toolkit doctor,agent-toolkit skills,agent-toolkit installinstead
Agent taxonomy (canonical — docs/AGENT_TAXONOMY.md, capabilities/skills/registry.yaml)
Holistic roster (11): the daily set humans remember. Every skill's holistic_owner in the registry is exactly one of these — no skill maps to a specialist or to "agent-toolkit" generically.
| Agent | Responsibility | Typical handoff |
|---|---|---|
@assistant |
Orchestrator — intent → context → proportional delegation → synthesis | Everyone |
@planner |
Decomposition, PRD/TRD framing, work items, estimation, capacity | architect, researcher, implementer, reviewer |
@architect |
System design, tradeoffs, C4, diagrams, ADRs/TRDs, cloud patterns | security-engineer, platform-engineer, reviewer |
@designer |
Visual direction, UX, Figma, design system, a11y — contextual routing among 11 skills | implementer, qa-engineer |
@implementer |
Feature/bug/refactoring delivery, build/test loop, task + docs generation | reviewer, qa-engineer, security-engineer, platform-engineer |
@reviewer |
Independent quality/craft, change-safety, anti-slop (blast-radius, deep-review, deslop, unslop) |
— (verifies, does not delegate except on system design → architect) |
@qa-engineer |
Behavioral verification, lint gates, browser automation, E2E, bug triage | implementer, reviewer |
@security-engineer |
App + agentic hardening, threat modeling, supply-chain/MCP, CodeQL | architect, platform-engineer |
@platform-engineer |
CI/CD, GitHub/GitLab PR lifecycle, worktrees, integrations, loops/swarm, triage, cost | implementer, qa-engineer |
@researcher |
Spike findings, single evidence-intake map (project-assessment-evidence) |
planner, architect, designer, data-engineer |
@data-engineer |
dbt/Snowflake read-only validation, notebook scaffolding (conditional — only for data repos) | architect, qa-engineer |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 103 lines · 35 tokens per session scan A 3c44f5c7e80f
assistant is an agent published in the GitHub repository ulises-jeremias/agent-toolkit (16 stars, last pushed 5d ago), licensed MIT. It adds 35 tokens to every session and 2,131 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
debugger
Debugs errors, test failures, and unexpected behavior. Knows PromptScript architecture.
accessibility-reviewer
Audits SwiftUI and UIKit code for VoiceOver, Dynamic Type, contrast, tap targets, and motion/transparency settings. Read-only — reports findings with file:line and the specific fix. Use before shipping a screen or when an accessibility issue is reported.
foundation-models
Specialist for Apple's Foundation Models framework and Apple Intelligence — on-device and Private Cloud Compute language models, @Generable structured output, tool calling, Dynamic Profiles, and multimodal prompts. Use when building, reviewing, or debugging any on-device LLM feature. Enforces availability gating and…
project-manager
Project manager for CrawlForge MCP Server development. Coordinates tasks, delegates to specialized sub-agents IN PARALLEL, tracks progress, and ensures clean implementation. Use PROACTIVELY for any multi-step project coordination.
security-auditor
Security specialist for CrawlForge MCP Server. Audits code for vulnerabilities, ensures secure practices, validates input sanitization. Use PROACTIVELY before deployments and after major changes.
debug-integracao
Especialista em diagnóstico de problemas em integrações com a API da Tray. Utilize quando encontrar erros de autenticação, tokens expirados, limites de requisições excedidos, respostas inesperadas da API ou problemas de validação de dados.