Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add assafkip/kipi-system/plugin install kipi-dsseWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/assafkip/kipi-system/issue-closeout)<a href="https://agentmods.dev/commands/assafkip/kipi-system/issue-closeout"><img src="https://agentmods.dev/badge/commands/assafkip/kipi-system/issue-closeout.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00020 | $0.01464 |
| Opus 5 | $0.00010 | $0.00732 |
| Sonnet 5 | $0.00004 | $0.00293 |
| Haiku 4.5 | $0.00002 | $0.00146 |
Grade A, and why
issue-closeout scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 84 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Autonomy contract. This step is agent-handled, not founder-gated. Once every pending in-scope finding has a non-pending disposition (accepted/rejected/deferred) AND every accepted patch has been applied with required_checks green, close the issue automatically without founder confirmation. The founder is notified post-closeout via the final report (step 6). Founder-gated steps remain: /issue-approve, /prd-approve, /prd-split commit, and any mid-issue scope amendment. Disposition rationale text and patch correctness still need to meet the merge-blocker rules in step 3. Autonomy is about removing the gate prompt, not lowering the bar.
Close the active DSSE issue. Execute in order:
-
Run
python3 "${CLAUDE_PLUGIN_ROOT}/scripts/issue_runner.py" status. Confirmreceipts.verifiedandreceipts.reviewedare both set. If either is null, stop and tell the founder which step is missing. Do not relaunch/issue-reviewon your own initiative; that command has its own iteration cap. -
Pull the snapshotted scope and the pending findings:
ALLOWED=$(python3 "${CLAUDE_PLUGIN_ROOT}/scripts/issue_runner.py" allowed-files) ISSUE_ID=$(python3 "${CLAUDE_PLUGIN_ROOT}/scripts/issue_runner.py" status | python3 -c "import sys,json; print(json.load(sys.stdin).get('issue_id',''))") python3 "${CLAUDE_PLUGIN_ROOT}/scripts/issue_findings.py" list "$ISSUE_ID" --only-pendingThe list output is JSON: each finding has
id,source,severity,body,affected_path,out_of_scope. Show them to the founder one by one. Out-of-scope findings are already filtered from the gate but are still in the list for visibility. -
Triage each pending in-scope finding using these merge-blocker rules. The disposition is the verb. Use the writer; do NOT hand-edit the JSONL:
-
accepted -> correctness bug introduced by this issue's diff. Patch it now in
allowed_files. After the patch lands, mark accepted (theresolved_atstamp is the receipt that the patch happened):python3 "${CLAUDE_PLUGIN_ROOT}/scripts/issue_findings.py" set-disposition "$ISSUE_ID" <finding-id> acceptedIf the patch requires re-running checks, re-run
/issue-verify. Do NOT auto-relaunch/issue-review. The runner's review-rounds cap exists to break loops; you must respect it. The founder opts in if they want another adversarial pass. -
deferred -> valid finding but out of contract for this issue (architectural debt, unchanged-code patterns, follow-up work). Rationale REQUIRED. Optional
--followup-issue-idif a tracking issue exists:python3 "${CLAUDE_PLUGIN_ROOT}/scripts/issue_findings.py" set-disposition "$ISSUE_ID" <finding-id> deferred \ --rationale "tracked for follow-up: applies to all 09 agents, not just this slice" -
rejected -> Codex misread scope or hallucinated the issue. Rationale REQUIRED:
python3 "${CLAUDE_PLUGIN_ROOT}/scripts/issue_findings.py" set-disposition "$ISSUE_ID" <finding-id> rejected \ --rationale "codex flagged a config value that is intentionally null; design doc says null disables the feature"
-
-
After every pending in-scope finding has a non-pending disposition (the runner's gate counts these), check the count:
python3 "${CLAUDE_PLUGIN_ROOT}/scripts/issue_findings.py" count "$ISSUE_ID" --in-scope-pendingMust print
0. If non-zero, the gate will block close. Re-triage the remaining findings. -
Record triage, then close. Run these as two separate steps and STOP if the first one exits non-zero -- there is no
set -ehere, so a failedtriagewould otherwise fall through intocloseand produce a confusing second failure at the receipt gate:python3 "${CLAUDE_PLUGIN_ROOT}/scripts/issue_runner.py" triage python3 "${CLAUDE_PLUGIN_ROOT}/scripts/issue_runner.py" closetriagerecomputes the pending/invalid counts from the findings ledger and writes thefindings_triagedreceipt only when both are zero. It replacesmark findings_triaged, which refuses by design (ASK-402): the count was always computed, while the receipt was hand-stamped, so the two could disagree. Iftriageexits 2 it names what is still pending -- go back to step 3 and disposition those findings.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 84 lines · 20 tokens per session scan A 2625ff2da3db
issue-closeout is a command published in the GitHub repository assafkip/kipi-system (109 stars, last pushed today), licensed MIT. It adds 20 tokens to every session and 1,464 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
today
Your AI Chief of Staff's morning briefing — the main product deliverable of Data.
tomorrow
End-of-day review and AI delegation — queue overnight nightshift work.
diagnostic
Command "diagnostic" from datacore-one/datacore, covering diagnostic, command context, when to reference dip-0002, quick reference and agents this command invokes.
sprint-start
You are the Sprint-Start Facilitator — you run the Monday kickoff ceremony.
sync
Command "sync" from datacore-one/datacore, covering sync, command context, when to reference dip-0010, quick reference and agents this command invokes.
recall
Recall memories with filtering and search.