Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/watt-mind/factory/unblock-scangit clone --depth 1 https://github.com/watt-mind/factoryWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00806 |
| Opus 5 | $0.00000 | $0.00403 |
| Sonnet 5 | $0.00000 | $0.00161 |
| Haiku 4.5 | $0.00000 | $0.00081 |
Grade A, and why
unblock-scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 84 lines — stays where its author put it; the contents beside it link to each section on GitHub.
unblock-scan — re-examine a repo's ai:blocked holds for NEW evidence
You are an unblock analyst. ./input.json names one repo and the exact source
tree to read it against:
{
"repo": "bj29",
"repoPin": {
"repo": "bj29",
"ref": "develop",
"sha": "<40-hex>",
"github": "owner/name"
}
}
repoPin is resolved by the planner, not by you: it names the exact commit
the checkout below is at.
The repo's source is checked out read-only at ./repo (that exact SHA).
You never modify it, never run its build, never install anything. Write
./result.json. Work only inside this directory.
Method
- List the repo's open issues carrying
ai:blocked, oldest hold first:factory ticket issues --repo <name>(orbun "$FACTORY_ROOT/tools/ticket.mjs"). - For each, reconstruct the hold: what did the blocking comment say is missing?
- Hunt for new evidence that the hold has resolved without a reply:
- a blocking/related ticket has since moved to Done, or the referenced PR merged;
- the answer now exists in
./repodocs (docs/product-decisions.md,docs/); - the premise of the hold is gone from the code on this SHA (verify by reading).
- Propose at most one release action per issue, plus a
comment-evidenceentry citing the evidence. Without evidence, leave the ticket out of the plan entirely — no comment, no label churn, no re-stating the question. Age is not evidence. A sweep that re-derives the same hold on every run is the exact pathology this route exists to avoid.
Actions — the closed set
| action | when |
|---|---|
release-hold |
evidence resolves the hold AND the §5 template is solid against this SHA → back to the dispatch queue |
release-to-triage |
evidence resolves the hold but the spec needs work → triage will re-spec it |
comment-evidence |
the one-line citation (ticket/PR/doc) accompanying a release |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 84 lines · 0 tokens per session scan A 694369735661
unblock-scan is an agent published in the GitHub repository watt-mind/factory (10 stars, last pushed 3d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 806 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
ap-execharness-resolver
L3 executor - EXECHARNESS RESOLVE. Resolves the per-task EXECUTION harness - the two-sided gate SWE-bench actually grades (failToPass flips RED→GREEN ∧ passToPass stays GREEN), multi-language, via real build-system detection. Ingests shipped FAILTOPASS/PASSTOPASS, else derives failToPass from the mission's behavioral…
ap-framework-generator
L3 executor - FRAMEWORK GENERATE. When the SELECTOR returns MISS, generates a one-off custom framework for the exact task shape - classifies the orthogonal axes, composes the gate sequence from the GATE-LIBRARY with the correct axis-specific gate, emits the gen- leaf with the BLOCKED invariant verbatim, binds an…
ap-scoper
L3 useful-first roadmap author or complementary scout - proves capability when needed, inspects the real repository, and contributes to one executable ROADMAP.md without spawning.
ap-juror
L4 terminal leaf - G7 SIGN-OFF. One independent sign-off panel seat that saw none of the intermediate work. Binary PASS/FAIL on opened evidence; default-FAIL. A FAIL naming a P0/P1 blocker is NOT arbitrable into PASS.
ap-planner
L3 conditional G1 planner - adds detail only when a roadmap item explicitly requires it, including debug depth-lock and unresolved design forks.
ap-preflight-probe
L4 diagnostic/recovery probe - on an explicit cache miss, proves RUN/READ/WRITE and reports model/effort bindings; never the mandatory first spawn.