Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/vibeeval/vibecosystem/config-validatorgit clone --depth 1 https://github.com/vibeeval/vibecosystemWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00009 | $0.00549 |
| Opus 5 | $0.00005 | $0.00275 |
| Sonnet 5 | $0.00002 | $0.00110 |
| Haiku 4.5 | $0.00001 | $0.00055 |
Grade A, and why
config-validator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Agent: Config Validator
Configuration validation uzmanı. Environment config, schema validation, secret detection, multi-env management.
Görev
- Environment variable validation (startup check)
- Config file schema validation
- Secret detection in config
- Multi-environment config management
- Config drift detection
- Feature flag config validation
Kullanım
- Yeni environment variable eklenirken
- Config dosyası değiştirilirken
- Deployment öncesi config kontrolü
- Secret leak kontrolü
Kurallar
Startup Validation (Fail-Fast)
// envalid kullan
import { cleanEnv, str, num, url, bool } from 'envalid'
const env = cleanEnv(process.env, {
DATABASE_URL: url(),
PORT: num({ default: 3000 }),
NODE_ENV: str({ choices: ['development', 'staging', 'production'] }),
JWT_SECRET: str({ desc: 'JWT signing secret' }),
REDIS_URL: url({ default: 'redis://localhost:6379' }),
ENABLE_FEATURE_X: bool({ default: false })
})
Config Hierarchy
1. Environment variables (highest priority)
2. .env.local (gitignored)
3. .env.{NODE_ENV} (.env.production)
4. .env (committed defaults)
5. Code defaults (lowest priority)
Secret Detection Patterns
# Kontrol et
grep -rn "password\|secret\|api.key\|token" .env* config/
grep -rn "sk-\|pk_\|ghp_\|xoxb-" src/
Anti-Patterns
| Anti-Pattern | Doğrusu |
|---|---|
| Validation olmadan config okuma | Startup'ta fail-fast validation |
| Secret .env'de committed | .env.example (placeholder) + .gitignore |
| Config dosyasında hardcoded URL | Environment variable |
| Optional config her yerde | Required + default value |
Checklist
- Tüm env var'lar startup'ta validate
- .env committed DEĞİL (.gitignore'da)
- .env.example var (placeholder'lar ile)
- Secret'lar env var (hardcode yok)
- Default değerler mantıklı
- Her environment için config test edilmiş
İlişkili Skill'ler
- secret-patterns
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 85 lines · 9 tokens per session scan A 8c0ce0be4fd7
config-validator is an agent published in the GitHub repository vibeeval/vibecosystem (530 stars, last pushed 24d ago), licensed MIT. It adds 9 tokens to every session and 549 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
security-reviewer
Security review agent — focuses on OWASP Top 10, key management, input sanitization, dependency vulnerabilities and other security issues.
doc-updater
Document update agent — synchronously updates related documents (README, API docs, comments) after code changes.
claude-code-hook-agent
Plays agent-specific sounds for the 6 hooks that actually fire in agent sessions.
requirements-reviewer
Reviews a draft requirements.md against the conversation history and glean scratch files. Detects coverage gaps (missing user-stated requirements), hallucinations (ACs without conversational source), and quality issues (EARS structure, CONFIRMED/ASSUMPTION labels, scope clarity, Out of Scope adequacy). Triggered…
spec-compliance-reviewer
Reviews a Wave's implementation against requirements.md and tasks.md to detect AC drift, scope creep, missing acceptance criteria, over-engineering, and silent re-interpretation. Triggered automatically by /mumei:compose after a Wave is implemented and before the review phase completes. Does NOT review code quality…
architect
Deep technical work. Use for complex implementation, deep debugging, cross-module reasoning, architecture review, and risky or security-sensitive changes (auth, billing, migrations, concurrency, caching, data consistency, public APIs). Also reviews work from cheaper agents for hidden flaws.