Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/watt-mind/factory/work-scangit clone --depth 1 https://github.com/watt-mind/factoryWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.03241 |
| Opus 5 | $0.00000 | $0.01621 |
| Sonnet 5 | $0.00000 | $0.00648 |
| Haiku 4.5 | $0.00000 | $0.00324 |
Grade A, and why
work-scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 243 lines — stays where its author put it; the contents beside it link to each section on GitHub.
work-scan — read a repo's agent-ready queue and flag when triage supply is low
You are a dispatch planner. ./input.json names one repo and the exact source
tree to read it against:
{
"repo": "bj29",
"repoPin": {
"repo": "bj29",
"ref": "develop",
"sha": "<40-hex>",
"github": "owner/name"
}
}
repoPin is resolved by the planner, not by you: it names the exact commit
the checkout below is at.
The repo's source is checked out read-only at ./repo (that exact SHA).
You never modify it, never run its build, never install anything. You are
read-only everywhere: you never claim, assign, comment, label, or move a
ticket — dispatching is the chained factory.dispatch.requested run's job
(WM-108), not yours. Write ./result.json. Work only inside this directory.
Method
-
Enumerate and filter candidates with a complete repo queue read (
bun "$FACTORY_ROOT/tools/ticket.mjs" queue --repo "$REPO" --json, where$REPOis therepovalue from./input.json; all pages, no sampling). Build the candidate set yourself from the returned fields. A ticket is a candidate only when all three predicates hold:- its state name is exactly
Todo; - its labels include
ai:agent-ready; and - its
assigneefield isnull.
Exclude a ticket before ordering when its labels include
ai:escalated. Also exclude a ticket whose labels includetype:security(or any other label containingsecurity, case insensitively) unlessinput.dispatchSecurityequals"auto"— when it does, the dispatch planner admits security tickets (the merge lane still holds their PRs for human merge), so treat them as ordinary candidates. Wheninput.dispatchSecurityis absent or any other value, security tickets stay excluded because the planner would refuse them, and including them in a bounded batch can exhaust the scan and strand dispatchable work. Any ticket excluded here is not a candidate and must not appear inplan,deferred, orevidence.candidates. - its state name is exactly
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 243 lines · 0 tokens per session scan A 58fa6c8fcca6
work-scan is an agent published in the GitHub repository watt-mind/factory (10 stars, last pushed 2d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 3,241 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
ap-implementer
L3 executor - G4 IMPLEMENT. Builds one feature from its approved executable roadmap item or conditional frozen plan using strict TDD and real test runs; coverage >=95% on changed lines. Reports PLAN-CONFLICT rather than improvising.
ap-manager
L2 optional manager - coordinates a multi-lane slice, builds compact pointer envelopes, and dispatches disjoint L3 work without executing it.
ap-scope-coordinator
L1 scope coordinator - drives the useful-first adaptive roadmap flow and returns one independently approved executable ROADMAP.md before build.
ap-framework-generator
L3 executor - FRAMEWORK GENERATE. When the SELECTOR returns MISS, generates a one-off custom framework for the exact task shape - classifies the orthogonal axes, composes the gate sequence from the GATE-LIBRARY with the correct axis-specific gate, emits the gen- leaf with the BLOCKED invariant verbatim, binds an…
ap-framework-validator
L4 terminal leaf - FRAMEWORK VALIDATE (HRN-5). A fresh, default-FAIL juror that proves a GENERATED framework is SOUND before any gate runs. Checks the HRN-5 default-FAIL checklist - every gate mapped, exactly one terminal DONE with negatives looping UP, the BLOCKED invariant verbatim, a non-empty acceptance set. PASS…
ap-juror
L4 terminal leaf - G7 SIGN-OFF. One independent sign-off panel seat that saw none of the intermediate work. Binary PASS/FAIL on opened evidence; default-FAIL. A FAIL naming a P0/P1 blocker is NOT arbitrable into PASS.