dedupe-apply

dedupe-apply is a command for coding agents from axiomantic/spellbook. It costs 41 tokens per session (2,823 once invoked), scanned A, original, MIT.

A command that applies approved duplicate-content extractions and records each edit for rollback. Rollback means restoring the previous file contents if needed.

In plain words
What is it for?
Run it after reviewing the duplicate report to apply selected extractions and maintain a recovery journal.
Why use it?
It requires a clean Git working tree, asks for approval before each change, and preserves exact information needed to reverse edits safely.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/axiomantic/spellbook/dedupe-apply
Clone the repo
git clone --depth 1 https://github.com/axiomantic/spellbook

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for dedupe-apply

README.md
[![agentmods](https://agentmods.dev/badge/commands/axiomantic/spellbook/dedupe-apply.svg)](https://agentmods.dev/commands/axiomantic/spellbook/dedupe-apply)
Your own site
<a href="https://agentmods.dev/commands/axiomantic/spellbook/dedupe-apply"><img src="https://agentmods.dev/badge/commands/axiomantic/spellbook/dedupe-apply.svg" alt="Measured on agentmods" height="20"></a>
Per session 41 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,823 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00041 $0.02823
Opus 5 $0.00020 $0.01411
Sonnet 5 $0.00008 $0.00565
Haiku 4.5 $0.00004 $0.00282

Measured 4d ago against content hash 1996f8fa8818, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

dedupe-apply scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commands/dedupe-apply.md · 326 lines

How it starts

The opening of the file, as written. The whole thing — 326 lines — stays where its author put it; the contents beside it link to each section on GitHub.

MISSION

Phase 4 of the dedupe skill: consume the report artifact produced by /dedupe-report, apply every EXTRACT finding marked apply after one final pre-edit checkpoint, and journal each edit in a deterministic, rollback-ready format.

Part of the dedupe- command family.* Run after /dedupe-report.

Invariant Principles

  1. Clean working tree is a hard gategit status --porcelain must be empty. There is no override flag. The operator commits / stashes / discards before this command will touch the filesystem.
  2. Every edit is journaled — the journal is the rollback source of truth. If an edit is not journaled, it did not happen.
  3. Per-finding final checkpoint — every EXTRACT finding marked apply in the report receives one AskUserQuestion prompt immediately before its edit. There is no "apply all" affordance.
  4. Rollback is byte-exact — restoring an original block requires the new_path content to match what the journal recorded as the post-apply state. Mismatch means the canonical home was edited externally; warn and skip rather than overwrite the operator's work.
  5. No Python, no shell scripts — base64 encode/decode runs via the base64 CLI through the harness Bash tool. Journal parsing uses POSIX text utilities plus jq (preinstalled via brew on the dev machine).

Clean-tree-gate invariant: The clean-tree gate has no override. Every applied edit is journaled; the only way rollback remains trustworthy is if the working tree before apply is a known git state. Suppressing the gate would silently break rollback's correctness invariant.

Prohibited operations:

  • Editing any file before the clean-tree gate passes.
  • Editing any file before the per-finding AskUserQuestion checkpoint for that finding has returned apply.
  • Writing a journal entry whose original_text_*_b64 field does not round-trip back to the exact bytes read from the source file.
  • Rolling back a finding whose new_path content does not match the recorded new_text_b64 (warn and skip instead).
  • Implementing base64 encode/decode in Python.

Read the full file on GitHub · 326 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 326 lines · 41 tokens per session scan A 1996f8fa8818

Subscribe to this mod's changes

dedupe-apply is a command published in the GitHub repository axiomantic/spellbook (10 stars, last pushed yesterday), licensed MIT. It adds 41 tokens to every session and 2,823 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.