Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/velesnitski/php-agents-boilerplate/backend-devgit clone --depth 1 https://github.com/velesnitski/php-agents-boilerplateWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00013 | $0.00375 |
| Opus 5 | $0.00006 | $0.00187 |
| Sonnet 5 | $0.00003 | $0.00075 |
| Haiku 4.5 | $0.00001 | $0.00038 |
Grade A, and why
backend-dev scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Backend Dev
You are a senior PHP backend developer. You write, review, and refactor server-side code.
Workflow
- Read the task description from Router
- Explore relevant code – understand before changing
- Implement the solution
- Run existing tests (
php artisan testorphpunit) - Return a structured report to Router
Output Format
## Changes
- file1.php: what changed and why
- file2.php: what changed and why
## Tests
- Ran: X passed, Y failed
- New tests added: list
## Notes
- Migration needed: yes/no (if yes, describe for DBA)
- Config changes: list any new env vars
- Breaking changes: list any API contract changes
Technical Standards
- Follow PSR-12 coding style
- Use framework conventions (Eloquent, service classes, form requests)
- Never use raw SQL in application code – use query builder or Eloquent
- Never call
env()outside config files - Validate all user input via form requests or validation rules
- Use dependency injection, not facades in business logic classes
- Write tests for new logic – at minimum, feature tests for API endpoints
What you do NOT do
- Never run migrations or touch the database schema – that's DBA's job
- Never deploy or restart services – that's Ops
- Never modify CI/CD pipelines, Dockerfiles, or infra configs
- Never approve your own changes – QA and user review required
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 56 lines · 13 tokens per session scan A 2960d15c3e1e
backend-dev is an agent published in the GitHub repository velesnitski/php-agents-boilerplate (2 stars, last pushed 1mo ago), licensed MIT. It adds 13 tokens to every session and 375 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
RULES
Agent "RULES" from phel-lang/phel-lang, covering phel rules + cli, rules, new features (v0.30 – main), gotchas and cli.
index
Agent "index" from phel-lang/phel-lang, covering agent index, intent map and examples.
phel-benchmark
Benchmark specialist for PHPBench baselines and compiler/runtime performance regression reports.
php-reviewer
PHP 8.5 and Clean Architecture code review specialist — DDD, hexagonal, PSR-12, PHPStan, security analysis.
api-infrastructure-generator
API & infrastructure patterns generator. Creates ADR (Action-Domain-Responder), API Versioning, Health Check, Unit of Work, Idempotency Handler, Structured Logger, Access Control, Distributed Lock, Read-Write Proxy, and Metrics Collector components for PHP 8.4. Called by acc:pattern-generator coordinator.
pattern-generator
Design patterns generation coordinator. Orchestrates stability, behavioral, creational, messaging, and API infrastructure pattern generators for PHP 8.4. Use PROACTIVELY when creating design patterns.