Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/anilcancakir/claude-code-plugin/init-rulesgit clone --depth 1 https://github.com/anilcancakir/claude-code-pluginWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00034 | $0.01704 |
| Opus 5 | $0.00017 | $0.00852 |
| Sonnet 5 | $0.00007 | $0.00341 |
| Haiku 4.5 | $0.00003 | $0.00170 |
Grade B, and why
init-rules scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
cat .claude/rules/*.md 2>/dev/null How it starts
The opening of the file, as written. The whole thing — 146 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Init Project Rules
Generate .claude/rules/*.md files for the active codebase — path-scoped instructions auto-injected when matching files are touched.
Authoring knowledge: Rule format, frontmatter, two-tier system, context layer stack, dedup checks, and anti-slop rules live in the rule-creator skill. Read it before writing any rule content. The claude-md-writer skill's dedup guide covers the project→rules boundary.
Phase 1: Discovery
Detect tech stacks, score directories, extract conventions. Use Glob, Grep, and Read directly in the main context — no subagents. Source code always takes priority over docs.
-
Tech Stack Detection — Glob for
package.json,composer.json,pubspec.yaml,Cargo.toml,go.mod,pyproject.toml,Gemfile. Read each to extract framework, version, key dependencies. Detect monorepo roots (workspacesfields,packages/,apps/). Assemble: stack | framework | version | root path. -
Directory Scoring — Run
lsat depth 2-3, skippingvendor/,node_modules/,dist/,build/,.git/. For each significant directory: count files and subdirs (via Glob), detect own entry point (index.*,__init__.py, service providers, barrel exports), detect distinct patterns (contracts/,drivers/,concerns/,middleware/,migrations/). Assemble: directory | file count | subdir count | has entry | has patterns | total score. -
Convention Extraction — For each major directory, Read 3-5 source files and extract: import style, naming pattern, architectural pattern (facades, repos, controllers, middleware), API usage patterns, anti-patterns. Grep for
DO NOT|NEVER|DEPRECATEDcomments. Read linter configs (.eslintrc*,phpstan.neon,analysis_options.yaml). Priority: source code over docs. Assemble: directory | conventions list | gotchas. -
Gather dedup context via Bash:
ls -la .claude/rules/ 2>/dev/null cat .claude/rules/*.md 2>/dev/null cat CLAUDE.md 2>/dev/null | head -80 cat ~/.claude/CLAUDE.md 2>/dev/null | head -80 find . -maxdepth 3 -type f \( -name "*.dart" -o -name "*.php" -o -name "*.ts" -o -name "*.vue" -o -name "*.py" -o -name "*.go" -o -name "*.rs" \) | sed 's|/[^/]*$||' | sort | uniq -c | sort -rn | head -20
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 146 lines · 34 tokens per session scan B fbbe7ed0bdff
init-rules is a command published in the GitHub repository anilcancakir/claude-code-plugin (2 stars, last pushed 4mo ago), licensed MIT. It adds 34 tokens to every session and 1,704 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
cc-council
Comprehensive multi-agent council review with 6 protocols, 10 specialists, scoped scoring (per-scope thresholds and weights), state machine orchestration, auto-fix, and 50+ configuration flags.
perf-coaching-protocol
Generate a 60-minute solution-focused + CBT-grounded coaching session script for a manager-as-coach engagement. Coaches use questions, not advice. Produces session structure (check-in → focus → scaling → exception-finding → small-step → close), follow-up prompts, and the manager-as-coach training notes that name the…
perf-difficult-conversation
Three-conversations framework rehearsal (Stone/Patton/Heen — Harvard Negotiation Project) for high-stakes conversations — termination, demotion, hard feedback, conflict surfacing. Produces three-conversations breakdown (what-happened / feelings / identity), conversation script with multiple opening choices, SCARF…
perf-feedback-rehearsal
Rehearse a high-stakes feedback conversation before delivery. Takes an SBI sketch + recipient context, produces multiple openings, anticipated reactions with responses, SCARF-aware adjustments, and three branching paths the conversation could take with the manager's response to each. Saves to…
architect-entity
Produce an Entity Architecture Plan — current structure (if any), target structure, jurisdiction considerations, multi-entity question, holding-company question, and checklist for the lawyer conversation. Not legal advice; thinking architecture to bring into the room.
culture-onboarding-90
Design a 90-day onboarding architecture for a role. First day (psychological safety + belonging activation), first week (relationship + role context + early wins), first month (skill ramp + integration + baseline), first quarter (autonomous performance + cultural integration check). Written-first elements for…