Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add ashlrai/ashlr-plugin/plugin install ashlrWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/ashlrai/ashlr-plugin/ashlr-genome-rewrap)<a href="https://agentmods.dev/commands/ashlrai/ashlr-plugin/ashlr-genome-rewrap"><img src="https://agentmods.dev/badge/commands/ashlrai/ashlr-plugin/ashlr-genome-rewrap.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00064 | $0.00504 |
| Opus 5 | $0.00032 | $0.00252 |
| Sonnet 5 | $0.00013 | $0.00101 |
| Haiku 4.5 | $0.00006 | $0.00050 |
Grade A, and why
ashlr-genome-rewrap scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Run the rewrap script and show the user its output verbatim.
Steps:
-
Run via Bash:
bun run ${CLAUDE_PLUGIN_ROOT}/scripts/genome-rewrap.ts $ARGUMENTS -
Print the script's stdout verbatim — the per-member wrap log is what the admin needs to confirm success.
-
If the script exits non-zero, surface its stderr:
- Exit 2: prereq missing — likely no Pro token, no local keypair, or
no
.cloud-idin this repo. Suggest the relevant skill:/ashlr-upgrade,/ashlr-genome-keygen, or/ashlr-genome-team-init. - Exit 3: network / server error. Suggest checking
$ASHLR_API_URLand the team's tier (rewrap requires Team tier).
- Exit 2: prereq missing — likely no Pro token, no local keypair, or
no
Flags (forwarded via $ARGUMENTS):
| Flag | Purpose |
|---|---|
--rotate-dek |
Generate a fresh team DEK before wrapping. Invalidates every existing envelope. Use after a suspected key compromise. |
--endpoint <url> |
Override the default https://api.ashlr.ai |
--cwd <dir> |
Repo to operate on (default cwd) |
When to use
- A teammate ran
/ashlr-genome-keygen --force(rotated their key); their previous envelope no longer decrypts. - A new teammate joined the team and ran
/ashlr-genome-keygen; they now have a pubkey on file but no envelope yet. - Suspected key compromise — run with
--rotate-dekto mint a fresh DEK and invalidate every prior envelope at once.
What it does
Re-wraps the existing team DEK for every member with a current pubkey on
file. With --rotate-dek, generates a fresh DEK first so every old
envelope is invalidated.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 49 lines · 64 tokens per session scan A 26d9219f29b3
ashlr-genome-rewrap is a command published in the GitHub repository ashlrai/ashlr-plugin (3 stars, last pushed yesterday), licensed MIT. It adds 64 tokens to every session and 504 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
familiar
Interact with your companion — show or change personality, mood, stats, and lore.
recall-save
Generate / overwrite .recall/context.md with Recall's local offline summarizer.
ccc-orchestrate
Sequential and tmux/worktree orchestration guidance for multi-agent workflows.
standup
Show a daily standup summary with completed, in-progress, and blocked tasks across all active epics.
complete
Signal that a skill's work is complete. Triggers downstream subscriptions with "when": "complete" timing. Automatically invoked — do not run manually.
setup
A setup command for configuring claude-mini-hud as Claude Code's terminal status line. It lets the user choose Chinese, English, minimal, or ultra-minimal display text and writes the setting to Claude Code's configuration.