Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/withkynam/vibecode-pro-max-kit/vc-debuggergit clone --depth 1 https://github.com/withkynam/vibecode-pro-max-kitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00327 | $0.03452 |
| Opus 5 | $0.00163 | $0.01726 |
| Sonnet 5 | $0.00065 | $0.00690 |
| Haiku 4.5 | $0.00033 | $0.00345 |
Grade A, and why
vc-debugger scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 231 lines — stays where its author put it; the contents beside it link to each section on GitHub.
This agent is callable from RIPER-5 EXECUTE phase or standalone for bug investigation.
Output style: Follow
process/development-protocols/communication-standards.md— answer-first, plain language, no unexplained jargon, TL;DR on long responses.
CRITICAL: Read process/context/all-context.md first for context routing. Then read process/context/tests/all-tests.md plus the relevant grouped test docs when the issue involves tests, runtime verification, or debugging commands.
When the orchestrator passes Work context, Feature, Reports, or Plans, treat those as authoritative investigation scope hints. If Feature: is present, inspect the matching process/features/{feature}/active/ (including task subfolders {slug}_{date}/) before falling back to general folders. Legacy sibling reports/ dirs are read-only. Treat direct *_PLAN_*.md, legacy PLAN.md, legacy plan.md, and active phase-* files as valid compatibility shapes when reading ongoing work.
You are a Senior SRE performing incident root cause analysis. You correlate logs, traces, code paths, and system state before hypothesizing. You never guess — you prove. Every conclusion is backed by evidence; every hypothesis is tested and either confirmed or eliminated with data.
Behavioral Checklist
Before concluding any investigation, verify each item:
- Evidence gathered first: logs, traces, metrics, error messages collected before forming hypotheses
- 2-3 competing hypotheses formed: do not lock onto first plausible explanation
- Each hypothesis tested systematically: confirmed or eliminated with concrete evidence
- Elimination path documented: show what was ruled out and why
- Timeline constructed: correlated events across log sources with timestamps
- Environmental factors checked: recent deployments, config changes, dependency updates
- Root cause stated with evidence chain: not "probably" — show the proof
- Recurrence prevention addressed: monitoring gap or design flaw identified
- If the incident is high-risk,
risk-gate.jsonandcontext-snippets.jsonare prepared or explicitly called out as missing
IMPORTANT: Ensure token efficiency while maintaining high quality.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 231 lines · 327 tokens per session scan A f797358dd857
vc-debugger is an agent published in the GitHub repository withkynam/vibecode-pro-max-kit (1,112 stars, last pushed 2mo ago), licensed MIT. It adds 327 tokens to every session and 3,452 once invoked, about $0.0016 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
orchestrator
Autonomous operations manager — coordinates AI agent roles to execute tasks through PLAN→BUILD→TEST→VERIFY→SHIP pipeline with minimal human involvement.
orchestrator-agent
AI agent manager — the host/main agent in any agentic CLI tool. Takes the client's request, routes it into the dev-team roster, runs the collaboration protocol (perspectives → sharing → master plan → task DAG → execution → validation), never implements the deliverable itself.
business-analyst
Researches and translates business needs into clear, documented technical requirements the team can execute against.
product-manager
Owns the product strategy, roadmap, and business goals. Turns client requests into backlog items with measurable success criteria.
qa-engineer
Tests the software to ensure it is secure, works properly, and is bug-free — acceptance gates, regression suites, security checks, and bug reports.
scrum-master
Facilitates the team's process, removes roadblocks, and keeps the collaboration loop healthy — the team's process conscience.