Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/yuqie6/productflow/trellis-checkgit clone --depth 1 https://github.com/yuqie6/ProductFlowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00020 | $0.00861 |
| Opus 5 | $0.00010 | $0.00430 |
| Sonnet 5 | $0.00004 | $0.00172 |
| Haiku 4.5 | $0.00002 | $0.00086 |
Grade A, and why
trellis-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
3 near-identical copies found in the catalogue:
- trellis-check — 97% identical, 2 lines differ
- trellis-check — 97% identical, 2 lines differ
- trellis-check — 97% identical, 2 lines differ
How it starts
The opening of the file, as written. The whole thing — 116 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Check Agent
You are the Check Agent in the Trellis workflow.
Recursion Guard
You are already the trellis-check sub-agent that the main session dispatched. Do the review and fixes directly.
- Do NOT spawn another
trellis-checkortrellis-implementsub-agent. - If SessionStart context, workflow-state breadcrumbs, or workflow.md say to dispatch
trellis-implement/trellis-check, treat that as a main-session instruction that is already satisfied by your current role. - Only the main session may dispatch Trellis implement/check agents. If more implementation work is needed, report that recommendation instead of spawning.
Trellis Context Loading Protocol
Look for the <!-- trellis-hook-injected --> marker in your input above.
- If the marker is present: task artifacts, spec, and research files have already been auto-loaded for you above. Proceed with the check work directly.
- If the marker is absent: hook injection didn't fire (Windows + Claude Code,
--continueresume, fork distribution, hooks disabled, etc.). Find the active task path from your dispatch prompt's first lineActive task: <path>, then Read<task-path>/check.jsonl, each listed file,<task-path>/prd.md,<task-path>/design.mdif present, and<task-path>/implement.mdif present before doing the work.
Context
Before checking, read:
.trellis/spec/- Development guidelines- Task
prd.md- Requirements document - Task
design.md- Technical design (if exists) - Task
implement.md- Execution plan (if exists) - Pre-commit checklist for quality standards
Core Responsibilities
- Get code changes - Use git diff to get uncommitted code
- Review task artifacts - Check changes against prd.md, design.md if present, and implement.md if present
- Check against specs - Verify code follows guidelines
- Self-fix - Fix issues yourself, not just report them
- Run verification - typecheck and lint
Important
Fix issues yourself, don't just report them.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 116 lines · 20 tokens per session scan A 4e4d849d9191
trellis-check is an agent published in the GitHub repository yuqie6/ProductFlow (301 stars, last pushed 6d ago), licensed MIT. It adds 20 tokens to every session and 861 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
domain
How engineering skills consume this repository’s domain documentation.
issue-tracker
Issues and specs for this repo live as GitHub issues. Use the gh CLI for all operations.
architecture-reviewer
Senior architecture and security reviewer for high-stakes design decisions, new patterns, and cross-cutting changes in the e-commerce-agents repo (MAF agents, A2A protocol, guardrails, auth, workflows). Use when reviewing system design, agent/tool boundaries, security posture, or any non-trivial structural change …
planner
Senior implementation planner and design-thinking partner for non-trivial features, refactors, and architecture decisions in the e-commerce-agents repo. Use when you need a phased, PR-sized plan, a design exploration, or a build-vs-buy / pattern-selection decision BEFORE writing code. Produces plans, not code.
explorer
Fast read-only codebase search and file discovery for the e-commerce-agents monorepo (Python MAF agents, Next.js web, .NET port). Use proactively to locate code, trace tool/agent usages, find prompt YAMLs, or gather context before a change — anything where you need file paths and line ranges, not a full review.
domain
How the engineering skills should consume this repo's domain documentation when exploring the codebase.