Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/atuljha23/holocron/sec-scangit clone --depth 1 https://github.com/atuljha23/holocronWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/atuljha23/holocron/sec-scan)<a href="https://agentmods.dev/commands/atuljha23/holocron/sec-scan"><img src="https://agentmods.dev/badge/commands/atuljha23/holocron/sec-scan.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00027 | $0.00443 |
| Opus 5 | $0.00014 | $0.00221 |
| Sonnet 5 | $0.00005 | $0.00089 |
| Haiku 4.5 | $0.00003 | $0.00044 |
Grade A, and why
sec-scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/holocron:sec-scan
Target: $ARGUMENTS — or working-tree diff if no arg.
1. Secret sweep
Run the regex gauntlet across the diff:
git diff $ARGUMENTS | grep -E 'AKIA[0-9A-Z]{16}|ghp_[A-Za-z0-9]{36,}|xox[baprs]-|AIza[0-9A-Za-z_-]{35}|sk_live_|sk-ant-|-----BEGIN .*PRIVATE KEY-----'
If anything matches, stop and report. Do not echo the matched secret in your output — redact.
2. Dependency advisories
Detect ecosystem and run the native auditor. Skip if the tool isn't installed.
- Node:
npm audit --audit-level=high(or pnpm/yarn equivalent) - Python:
pip-auditif present - Ruby:
bundler-audit check --updateif present - Rust:
cargo auditif present - Go:
govulncheck ./...if present
Summarize high/critical advisories. Ignore dev-only nuisance advisories unless severe.
3. SAST pass
Delegate to @security-reviewer with the diff and ask for:
- Authn/authz gaps
- Injection surfaces (SQL, shell, template, path, deserializer)
- Session / cookie attribute issues
- Unsafe crypto (MD5/SHA1 for security, ECB mode, custom crypto)
- Over-returning in response objects
Output
Severity-ordered findings (Critical / High / Medium / Low), each with file:line, impact, trigger, fix. Redact any actual secrets found.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 46 lines · 27 tokens per session scan A ce11e7d483af
sec-scan is a command published in the GitHub repository atuljha23/holocron (2 stars, last pushed 4mo ago), licensed MIT. It adds 27 tokens to every session and 443 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
learn
Learn Claude Code best practices and capture lessons into persistent memory.
insights
Surface patterns from your pro-workflow learnings and session history.
wiki
Build, query, and maintain long-lived knowledge bases. Each wiki = markdown folder + SQLite FTS5 shadow index. Survives sessions, indexes auto-load on SessionStart.
commit
Create a well-crafted commit after running pro-workflow quality checks.
handoff
Generate a structured handoff document that another Claude session (or your future self) can consume immediately to continue where you left off.
context-optimizer
Diagnose and fix context window problems.