Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/aadivar/shiplogWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/aadivar/shiplog/review)<a href="https://agentmods.dev/commands/aadivar/shiplog/review"><img src="https://agentmods.dev/badge/commands/aadivar/shiplog/review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00375 |
| Opus 5 | $0.00000 | $0.00187 |
| Sonnet 5 | $0.00000 | $0.00075 |
| Haiku 4.5 | $0.00000 | $0.00038 |
Grade A, and why
review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/shiplog review
Manually trigger all background agents.
Trigger
User runs /shiplog review
Behavior
Step 1: Validate setup
Check that .shiplog/config.json exists. If not:
"Shiplog is not initialized. Run
/shiplog initfirst."
Step 2: Read config
Read .shiplog/config.json to determine:
- Which agents are enabled
- What model to use
Step 3: Launch agents
For each enabled agent, launch it using the Agent tool with run_in_background: true:
- Specs Agent — Read prompt from
agents/specs-agent.md, launch with configured model - PRD Agent — Read prompt from
agents/prd-agent.md, launch with configured model - Security Agent — Read prompt from
agents/security-agent.md, launch with configured model - Memory Agent — Read prompt from
agents/memory-agent.md, launch with configured model
Launch specs, PRD, and security in parallel. Launch memory after the others.
Step 4: Confirm
Shiplog review started!
Launching agents (model: {model}):
- Specs Agent: updating docs/SPECS.md
- PRD Agent: updating docs/PRD.md
- Security Agent: updating docs/SECURITY.md
- Memory Agent: updating memory files
Agents are running in the background. Continue working — they won't interrupt you.
Rules
- If no agents are enabled, inform the user: "No agents are enabled. Run
/shiplog configto enable them." - This is a manual trigger — it works the same as the automatic hook-based trigger
- Don't wait for agents to complete before confirming to the user
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 46 lines · 0 tokens per session scan A 0679bcc543ae
review is a command published in the GitHub repository aadivar/shiplog (3 stars, last pushed 6mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 375 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
sm-buff
You usually don't run buff directly — run sm sail. sm sail drives the whole PR to green and calls buff watch / triage for you, stopping only when it needs you to act (see /sm-sail). Reach for sm buff here only for surgical work: inspecting a specific failure, or resolving a single review thread when sail has parked on…
sm-scour
Run slop-mop's comprehensive pre-PR sweep for this repository.
review-pr
A command for reviewing a GitHub pull request against its issue contract and design documents. A pull request is a proposed code change submitted for review; gh is GitHub's command-line tool.
servo-gate
Verify the current spec / plan / diff against a named oracle from the manifest (GO / FIX / STOP).
review
Run full AI code review cycle on current PR branch.
review-status
Check Rami review status without triggering new review.