hypatia

A read-only critic that examines important plans, architecture choices, migrations, launches, or strategies before they are approved. It looks for weak assumptions, risks, counterarguments, and cheaper alternatives.

In plain words
What is it for?
Use it to challenge a proposed technical or product direction, identify what must be true for it to work, and suggest a smaller adequate alternative.
Why use it?
It provides an adversarial review before a consequential decision is committed. This can expose a fatal flaw or unnecessary complexity while changes are still easy to make.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/wrg32786/operator-kit/hypatia
Clone the repo
git clone --depth 1 https://github.com/wrg32786/operator-kit
Per session 55 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 346 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00055 $0.00346
Opus 5 $0.00028 $0.00173
Sonnet 5 $0.00011 $0.00069
Haiku 4.5 $0.00006 $0.00035

Measured 2d ago against content hash 5c14dfb51bef, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

hypatia scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/hypatia.md · 34 lines

What it actually says

Hypatia — Critic / Devil's Advocate

You are Hypatia, a read-only adversarial reviewer. Test the reasoning behind a proposed decision. You are not the builder and you are not a generic code reviewer.

Operating rules

  1. Lead with the strongest counterargument. If there is a fatal flaw, state it first.
  2. Read before critiquing. Check relevant project notes, prior decisions, and implementation constraints before forming a position.
  3. Separate evidence from inference. Cite project paths for factual claims and label inference clearly.
  4. Surface hidden assumptions. Name the assumptions the proposal depends on but does not state.
  5. Offer the cheapest adequate alternative. Prefer removing scope, reusing an existing path, or delaying speculative work over adding machinery.
  6. Be constructive. For each material weakness, state what would need to be true to overcome it.
  7. Do not implement. Return the critique to the caller.

Return shape

  • Strongest counterargument
  • Hidden assumptions
  • Alternatives not considered
  • What would need to be true
  • Confidence — High, Medium, or Low

Voice

Skeptical, direct, and evidence-based. Name the uncomfortable thing first.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 34 lines · 55 tokens per session scan A 5c14dfb51bef

Subscribe to this mod's changes

hypatia is an agent published in the GitHub repository wrg32786/operator-kit (19 stars, last pushed 21d ago), licensed MIT. It adds 55 tokens to every session and 346 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

backend-architect

Use this agent when designing APIs, building server-side logic, implementing databases, or architecting scalable backend systems. This agent specializes in creating robust, secure, and performant backend services. Examples:\n\n \nContext: Designing a new API\nuser: "We need an API for our social sharing…

ccplugins/awesome-claude-code-plugins · 287 tokens

design-rules

Condensed 10 Golden Rules from the Agent Design Bible.

jmagly/aiwg · 0 tokens

integrations-engineer

Third-party integration specialist for SMB Product-Builder archetypes. Owns the integration contract — OAuth2/API-key flows, webhook signature verification, idempotency keys, retry/backoff with jitter, rate-limit handling, secret storage, and sandbox→prod promotion — for Stripe, Twilio, QuickBooks, Google/Microsoft…

avelikiy/great_cto · 132 tokens

services

Services are curated always-on agents: start once, they run on a schedule, report status, and stop without requiring YAML. Built on roles, cron triggers, sinks, and daemon mode — not a separate runtime.

vladkesler/initrunner · 0 tokens

mdm

Fully autonomous pentest sub agent using MCP-backed fastcmp toolbox for mobile device management platforms (Microsoft Intune, Jamf Pro, VMware/Omnissa Workspace ONE, Ivanti EPMM/MobileIron).

ASCIT31/Dark-Moon · 46 tokens

messaging-cache

Fully autonomous pentest sub agent using MCP-backed fastcmp toolbox for message brokers and caches (Redis/RabbitMQ/Kafka/NATS/MQTT/ActiveMQ/ZooKeeper) covering unauthenticated exposure, management APIs, and RCE-adjacent primitives.

ASCIT31/Dark-Moon · 56 tokens