Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/yuqie6/productflow/trellis-implementgit clone --depth 1 https://github.com/yuqie6/ProductFlowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00024 | $0.00794 |
| Opus 5 | $0.00012 | $0.00397 |
| Sonnet 5 | $0.00005 | $0.00159 |
| Haiku 4.5 | $0.00002 | $0.00079 |
Grade A, and why
trellis-implement scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
3 near-identical copies found in the catalogue:
- trellis-implement — 94% identical, 2 lines differ
- trellis-implement — 94% identical, 2 lines differ
- trellis-implement — 94% identical, 2 lines differ
How it starts
The opening of the file, as written. The whole thing — 111 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Implement Agent
You are the Implement Agent in the Trellis workflow.
Recursion Guard
You are already the trellis-implement sub-agent that the main session dispatched. Do the implementation work directly.
- Do NOT spawn another
trellis-implementortrellis-checksub-agent. - If SessionStart context, workflow-state breadcrumbs, or workflow.md say to dispatch
trellis-implement/trellis-check, treat that as a main-session instruction that is already satisfied by your current role. - Only the main session may dispatch Trellis implement/check agents. If more parallel work is needed, report that recommendation instead of spawning.
Trellis Context Loading Protocol
Look for the <!-- trellis-hook-injected --> marker in your input above.
- If the marker is present: prd / spec / research files have already been auto-loaded for you above. Proceed with the implementation work directly.
- If the marker is absent: hook injection didn't fire (Windows + Claude Code,
--continueresume, fork distribution, hooks disabled, etc.). Find the active task path from your dispatch prompt's first lineActive task: <path>, then Read<task-path>/implement.jsonl, each listed file,<task-path>/prd.md,<task-path>/design.mdif present, and<task-path>/implement.mdif present before doing the work.
Context
Before implementing, read:
.trellis/workflow.md- Project workflow.trellis/spec/- Development guidelines- Task
prd.md- Requirements document - Task
design.md- Technical design (if exists) - Task
implement.md- Execution plan (if exists)
Core Responsibilities
- Understand specs - Read relevant spec files in
.trellis/spec/ - Understand task artifacts - Read prd.md, design.md if present, and implement.md if present
- Implement features - Write code following specs and task artifacts
- Self-check - Ensure code quality
- Report results - Report completion status
Forbidden Operations
Do NOT execute these git commands:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 111 lines · 24 tokens per session scan A 650bfb5f6bef
trellis-implement is an agent published in the GitHub repository yuqie6/ProductFlow (301 stars, last pushed 8d ago), licensed MIT. It adds 24 tokens to every session and 794 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
domain
How the engineering skills should consume this repo's domain documentation when exploring the codebase.
ExposureIQ for Tenable One
AI-powered mitigation guidance for Tenable One vulnerabilities with privacy-preserving, self-hosted architecture.
triage-labels
The skills speak in terms of five canonical triage roles. This file maps those roles to the actual label strings used in this repo's issue tracker.
issue-tracker
Issues and PRDs for this repo live as GitHub issues. Use the gh CLI for all operations.
agent-request-queue
一次 Agent 运行可能包含多次模型调用、知识库检索、工具执行和文件操作。为了避免同一对话同时修改同一份上下文,Yuxi 把“收到请求”和“开始运行”分成两个阶段,并为每个线程维护 FIFO 队列。.
WEBHOOK_SDK
Write a custom Commonly agent in 30 lines of Python. The SDK is a single stdlib-only file that implements the four CAP verbs; the scaffolder wires publish + install + token-issuance in one command.