Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/alinaqi/maggy/initialize-projectgit clone --depth 1 https://github.com/alinaqi/maggyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/alinaqi/maggy/initialize-project)<a href="https://agentmods.dev/commands/alinaqi/maggy/initialize-project"><img src="https://agentmods.dev/badge/commands/alinaqi/maggy/initialize-project.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.14177 |
| Opus 5 | $0.00000 | $0.07089 |
| Sonnet 5 | $0.00000 | $0.02835 |
| Haiku 4.5 | $0.00000 | $0.01418 |
Grade D, and why
initialize-project scanned grade D with 4 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
BOOTSTRAP_DIR=$(cat ~/.claude/.bootstrap-dir 2>/dev/null) Enumerates other installed skillsmediumAgent snooping
Other skills' SKILL.md files reveal prompts, capabilities and secrets that should be invisible to peers.
ls -la .claude/skills/ 2>/dev/null Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
rm -rf "$TEMP_DIR" Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
if curl -fsSL "$DOWNLOAD_URL" -o "$TEMP_DIR/codebase-memory-mcp.tar.gz"; then How it starts
The opening of the file, as written. The whole thing — 1,849 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Initialize Project
Full project setup with Claude coding guardrails. Works for both new and existing projects.
This command is idempotent - run it anytime to update skills, add missing structure, or reconfigure.
Phase 0: Validate Bootstrap Installation
FIRST, verify Maggy is properly installed:
# Read bootstrap directory (saved during install)
BOOTSTRAP_DIR=$(cat ~/.claude/.bootstrap-dir 2>/dev/null)
# Run quick validation
"$BOOTSTRAP_DIR/tests/validate-structure.sh" --quick
This checks:
- Skills are installed with correct structure (folder/SKILL.md)
- Commands are installed (~/.claude/commands/)
- Hooks are installed (~/.claude/hooks/)
If validation fails:
- Show the error to user
- Suggest running:
cd "$BOOTSTRAP_DIR" && git pull && ./install.sh - Offer to continue anyway or abort
If validation passes:
- Continue to Phase 1
Phase 1: Detect Project State
First, check what already exists:
# Check for existing Claude setup
ls -la .claude/skills/ 2>/dev/null
ls -la CLAUDE.md 2>/dev/null
ls -la _project_specs/ 2>/dev/null
# Check for cross-tool setup (Kimi CLI, Codex CLI)
ls -la .kimi/skills/ 2>/dev/null
ls -la .codex/skills/ 2>/dev/null
ls -la .agents/skills/ 2>/dev/null
ls -la AGENTS.md 2>/dev/null
# Detect installed AI CLI tools
BOOTSTRAP_DIR=$(cat ~/.claude/.bootstrap-dir 2>/dev/null)
DETECTED_AGENTS=$("$BOOTSTRAP_DIR/scripts/detect-agents.sh" 2>/dev/null || echo "claude")
echo "Detected AI CLI tools: $DETECTED_AGENTS"
# Check for existing git repo
git remote -v 2>/dev/null
# Check for existing package files
ls package.json pyproject.toml 2>/dev/null
# Check for Flutter project
ls pubspec.yaml 2>/dev/null
# Check for Android project
ls android/build.gradle android/app/build.gradle 2>/dev/null
# Check for native language in Android projects
find android -name "*.java" -type f 2>/dev/null | head -1
find android -name "*.kt" -type f 2>/dev/null | head -1
Based on findings, determine:
- New project: No CLAUDE.md, no .claude/skills/, no code files
- Existing project with skills: Has .claude/skills/ - offer to UPDATE
- Existing codebase without skills: Has code but no Claude setup - AUTO-RUN ANALYSIS
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 1,849 lines · 0 tokens per session scan D 3c7106ff54ae
initialize-project is a command published in the GitHub repository alinaqi/maggy (705 stars, last pushed 16d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 14,177 tokens. A static security scan graded it D with 4 findings (reads agent configuration directories, enumerates other installed skills, recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
frappe-backend
Treat the task as Frappe backend work.
py-harden
Scan Python backend code for anti-patterns and fix them. Runs the full anti-pattern catalog (AP-01 through AP-22) against the codebase.
py-structure
Analyze and recommend project structure improvements. Checks file sizes, layer organization, module splitting, and hexagonal architecture compliance.
git
Git operations with intelligent commit messages and workflow optimization.
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.