Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/aphrody-code/bxc/bxc-verifygit clone --depth 1 https://github.com/aphrody-code/bxcWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00037 | $0.00347 |
| Opus 5 | $0.00018 | $0.00173 |
| Sonnet 5 | $0.00007 | $0.00069 |
| Haiku 4.5 | $0.00004 | $0.00035 |
Grade A, and why
bxc-verify scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Run the safe, scoped verification for bxc-style projects.
# Basic
/bxc-verify
# With lint fix on our code only
/bxc-verify --fix
Implementation:
- Always run
BXC_TEST_LIVE_GROK=0 HOME=/tmp/nonexistent bun test test/ packages/ src/ --timeout 30000 - Run per-package tsc with --skipLibCheck on packages/x/tsconfig.json and packages/xai (and any other workspace packages that have one).
- Run direct oxlint only on feature-relevant paths (packages/, src/cli/ relevant, src/mcp, rust-bridge/src if applicable). Never the broad root lint that walks everything.
- If in a plugin context, also run any validate-*.sh from the plugin-dev or bxc skills.
- Append a short "feature OK" or detailed status line to the project autopilot log if present (
/tmp/bxc-autopilot.logor similar). - Report the "30 pass / 2 skip / 0 fail" style summary when possible.
Never suggest or execute bare bun test, bun run lint without paths, or global tsc without --skipLibCheck on the right packages.
Use the bxc-verify-enforcer agent if the output looks suspicious.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 28 lines · 37 tokens per session scan A c83513ce23eb
bxc-verify is a command published in the GitHub repository aphrody-code/bxc (2 stars, last pushed 2d ago), licensed Apache-2.0. It adds 37 tokens to every session and 347 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
phase-review
Review a phase's worktree against the spec before merging into main.
release
Cut a Uni-CLI release from a clean main.
verify
Run the full Uni-CLI verification gate and report the outcome.
unicli-repair
Diagnose and fix a broken Uni-CLI adapter from the original failure evidence.
unicli-search
Search any supported website or platform using Uni-CLI.
feature
End-to-end feature/bug-sweep workflow for ui-debugger-mcp — understand, reproduce against a real target, explore in parallel, split into path-disjoint slices, build with a hive of agents in this ONE checkout (never worktrees), gate green, PR, merge, release to npm. Tracks in GitHub issues. Reads intent from the prompt.