hep-connect

hep-connect is a command for Claude Code from agentlas-ai/Agentlas-OS. It costs 9 tokens per session (822 once invoked), scanned A, original, Apache-2.0.

A command that connects an Agentlas agent, team, group, or organisation chart to Telegram, a messaging app. It guides setup through a Telegram bot and a paired chat.

In plain words
What is it for?
Use it to choose an Agentlas target, save its Telegram bot token securely, pair chats, and send a test message.
Why use it?
It gives people a way to communicate with an Agentlas target through Telegram without manually managing chat-session details.

Command for Claude Code

Written for Claude Code: allowed-tools in frontmatter.

Good fit Use it to choose an Agentlas target, save its Telegram bot token securely, pair chats, and send a test message.

Compare 6 commands from other repositories ↓
Install with agentmods
npx agentmods add commands/agentlas-ai/agentlas-os/hep-connect
About the project

Agentlas OS is a local-first system for creating, storing, borrowing, and running specialist AI agents and temporary agent teams through supported hosts and models. It serves people who want reusable agents that remain available across computers and model workspaces, and the catalogue contains its skills, commands, hooks, agents, instructions, plugin, and rule.

agentlas-ai/Agentlas-OS · 1,105 stars · on GitHub · agentlas.cloud

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/agentlas-ai/Agentlas-OS

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for hep-connect

README.md
[![agentmods](https://agentmods.dev/badge/commands/agentlas-ai/agentlas-os/hep-connect/github.svg)](https://agentmods.dev/commands/agentlas-ai/agentlas-os/hep-connect)
Your own site
<a href="https://agentmods.dev/commands/agentlas-ai/agentlas-os/hep-connect"><img src="https://agentmods.dev/badge/commands/agentlas-ai/agentlas-os/hep-connect/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for hep-connect

Your own site · 80×15
<a href="https://agentmods.dev/commands/agentlas-ai/agentlas-os/hep-connect"><img src="https://agentmods.dev/badge/commands/agentlas-ai/agentlas-os/hep-connect.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 9 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 822 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00009 $0.00822
Opus 5 $0.00005 $0.00411
Sonnet 5 $0.00002 $0.00164
Haiku 4.5 $0.00001 $0.00082

Measured 6d ago against content hash 4ebd6fd770a6, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

hep-connect scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

.claude/commands/hep-connect.md · 68 lines

How it starts

The opening of the file, as written. The whole thing — 68 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Update fallback: 자동 업데이트가 안 되면 hephaestus update를 한 번 실행하세요. 업데이트하지 않아도 현재 버전 명령은 그대로 동작합니다.

Hephaestus Connect

Raw arguments: $ARGUMENTS

Use this prompt when the operator wants Telegram to talk to one Agentlas target: a single agent, a saved group, a local team, or a .agentlas org chart.

Current product contract:

  1. Start with Telegram only.
  2. Do not ask for a BotFather token in chat. Save it only through a runtime-owned secret store.
  3. Prefer the Agentlas Desktop Connect surface at /connect; it lists saved groups, .agentlas org charts, local teams, team agents, and single agents.
  4. Explain the setup in simple words:
    • choose who should answer;
    • make a Telegram bot in BotFather;
    • save the token in the local secret store;
    • pair one Telegram chat;
    • send one test message;
    • keep adding more chats as needed.
  5. Session state belongs to the Telegram chat binding. Team, org, and saved group bindings use one session per chat. Single-agent direct chats can keep one session per user.

If running inside Agentlas Desktop development, report that the Desktop route is /connect and use the real local Connect UI as the source of truth. Do not pretend that Telegram delivery is live until token validation, chat pairing, and a test message pass.

Rules carried from the other runtime copies

These lines existed in one runtime's hand-maintained copy and not in the longest one. They are kept verbatim rather than dropped — a rule that only one runtime enforced was still a rule someone wrote on purpose.

  • /hep-connect Use this command when the user wants Telegram to talk to one Agentlas target:

  • a single agent, a saved agent group, a local team, or a .agentlas org chart.
  • Telegram is the only channel for this flow.
  • The easiest path is Agentlas Desktop -> Connect (/connect).
  • The Connect screen must list real local targets, not placeholder cards:
  • saved groups, .agentlas org charts, local teams, team agents, and single agents.
  • Never collect or echo a BotFather token in chat.
  • A valid connection is not just a saved token.
  • Draft -> Token checked -> Chat paired -> Test passed -> Running.
  • Each binding picks one target and owns its own session state.
  • If the user only asks to start, tell them to open Desktop Connect and choose the target.
  • If they ask for implementation work, attach to the actual Desktop and Hephaestus codebase before editing.
  • Do not claim live Telegram delivery until token validation, chat pairing, and a test message are implemented and verified.
  • /hep-connect Telegram Connect is a guided setup flow for one job:

  • choose who should answer in Telegram, connect a bot, pair a chat, send a test message, and keep the receipt.
    • Telegram only until this channel is reliable.
    • Show real local targets, not mock cards.
    • Token handling must go through a runtime-owned secret store.
  • Do not ask the user to paste a BotFather token into ordinary chat.
    • A user can add unlimited chat bindings.
  • Session memory belongs to the binding, not to the global bot.
    • Team, org, and saved-group bindings use one session per Telegram chat.
  • When the Desktop app is available, use the /connect surface as the operator home.
  • When implementation is requested, edit the real Agentlas Desktop and Hephaestus codebase and verify token check, chat pairing, test send, and delivery receipt before claiming live Telegram delivery.

Read the full file on GitHub · 68 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 68 lines · 9 tokens per session scan A 4ebd6fd770a6

Subscribe to this mod's changes

hep-connect is a command published in the GitHub repository agentlas-ai/Agentlas-OS (1,105 stars, last pushed 3d ago), licensed Apache-2.0. It adds 9 tokens to every session and 822 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.