Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/ANcpLua/ancplua-claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/ancplua/ancplua-claude-plugins/derot)<a href="https://agentmods.dev/commands/ancplua/ancplua-claude-plugins/derot"><img src="https://agentmods.dev/badge/commands/ancplua/ancplua-claude-plugins/derot.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00052 | $0.00537 |
| Opus 5 | $0.00026 | $0.00269 |
| Sonnet 5 | $0.00010 | $0.00107 |
| Haiku 4.5 | $0.00005 | $0.00054 |
Grade A, and why
derot scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Run a derot pass: find and fix rot — every place this repo's stated intent (comments, docs, CI infra, versions, dependency choices) has drifted from what the code/build actually is — without deleting knowledge that still holds.
Scope: $ARGUMENTS (empty → the whole repo; prioritise src/, .github/, *.md, build/config files).
Use the derot skill for the full methodology and the five rot dimensions. The pass:
- Plan. Decide the scope; split it into areas (by directory / file-type).
- Scout — parallel, read-only. For a non-trivial repo, fan out one
rot-scoutper area (Agent tool, or a Workflow when there are many areas — scouts are independent and read-only, so they parallelise cleanly). Each scout VERIFIES every candidate against ground truth before reporting it (open the referenced code; checkVersion.props/Directory.Packages.props/global.jsonfor version claims; grep for symbol/ID/file existence; read the code under the comment). For dimension 5, dispatch thedep-analyst. - Synthesize. Collect findings into one ordered apply-list. Drop
unverified; keepconfirmed-rot,correct-keep-explanation,obsolete-delete. Sanity-check each against its stated evidence. - Apply. YOU — not the scouts — apply the verified edits. Correct beats delete: keep a useful why, fix only the wrong facts.
- Verify. Build + test; for YAML/props-only changes, validate the file. Never claim done without running it.
- Report + commit. Summarize each change with its one-line root-cause justification, plus a separate flagged, not changed list (secrets to delete, unverified candidates, dependency calls needing a human). Commit + push per the repo's hygiene conventions.
The discipline is non-negotiable (see the skill): never "fix" a comment to match a wrong assumption — fix whichever of {comment, code} is actually wrong, and chase it through every caller. Never assert a dependency succession from memory — cite the source or report it as unverified.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 19 lines · 52 tokens per session scan A e8861ecce44e
derot is a command published in the GitHub repository ANcpLua/ancplua-claude-plugins (5 stars, last pushed 20d ago), licensed MIT. It adds 52 tokens to every session and 537 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
sdd-init
Initialize SDD context — detects project stack and bootstraps persistence backend.
review-branch
Review the current branch's diff against base by dispatching atomic-reviewer. No orchestration loop, no spec required — pre-flight before /commit pr or /commit merge.
init
Install the formatters this repository needs, with every command visible before it runs.
merge-conflict-analysis
You are analyzing merge conflicts for PR #${{ pr-number }}.
review-sdk-app
Review and validate a Claude Agent SDK application against best practices.
repo-audit
Audit a codebase (local or remote GitHub/GitLab) against architecture principles and requirements, surfacing drift, risk, and missing decisions.