dedupe-report

dedupe-report is a command for coding agents from axiomantic/spellbook. It costs 38 tokens per session (1,840 once invoked), scanned A, original, MIT.

A read-only report command for reviewing possible duplicate Markdown content. It combines analysis verdicts into a human-readable report and asks for a decision on each extract candidate.

In plain words
What is it for?
Run it after duplicate analysis to inspect findings and choose which repeated blocks may be extracted.
Why use it?
It keeps review separate from editing, exposes disagreements for inspection, and prevents approved changes from being applied automatically.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/axiomantic/spellbook/dedupe-report
Clone the repo
git clone --depth 1 https://github.com/axiomantic/spellbook

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for dedupe-report

README.md
[![agentmods](https://agentmods.dev/badge/commands/axiomantic/spellbook/dedupe-report.svg)](https://agentmods.dev/commands/axiomantic/spellbook/dedupe-report)
Your own site
<a href="https://agentmods.dev/commands/axiomantic/spellbook/dedupe-report"><img src="https://agentmods.dev/badge/commands/axiomantic/spellbook/dedupe-report.svg" alt="Measured on agentmods" height="20"></a>
Per session 38 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,840 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00038 $0.01840
Opus 5 $0.00019 $0.00920
Sonnet 5 $0.00008 $0.00368
Haiku 4.5 $0.00004 $0.00184

Measured 5d ago against content hash cf9661fedc77, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

dedupe-report scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commands/dedupe-report.md · 211 lines

How it starts

The opening of the file, as written. The whole thing — 211 lines — stays where its author put it; the contents beside it link to each section on GitHub.

MISSION

Phase 3 of the dedupe skill: consume the verdicts artifact produced by /dedupe-analyze, render a human-readable markdown report, and drive per-finding disposition approval via AskUserQuestion.

This command is read-only with respect to the source markdown tree. The only file it writes is the report artifact itself. It NEVER edits skill or command files. It NEVER auto-chains to /dedupe-apply.

Part of the dedupe- command family.* Run after /dedupe-analyze. Run before /dedupe-apply.

Invariant Principles

  1. Read-only with respect to source files — this phase produces a report; the apply phase produces edits. They are separate, gated by explicit operator invocation.
  2. No auto-chain to apply/dedupe-apply is invoked explicitly by the operator after they review the report. This command never triggers it.
  3. Per-finding disposition is gated — EXTRACT candidates each receive one AskUserQuestion prompt. There is no "apply all" affordance at this phase.
  4. Drift is surfaced, never auto-resolved — RECONCILE-drifted findings appear in their own section with no apply option.

No-auto-chain invariant: This command never auto-chains to /dedupe-apply. The operator explicitly invokes apply only after reviewing the report and its recorded dispositions. Auto-chaining would bypass the report-review gate that exists for safety.


Invocation

/dedupe-report <verdicts-path>
  • <verdicts-path> — the artifact produced by /dedupe-analyze. Required.

Inputs

  • The verdicts artifact at <verdicts-path>. Read it to recover the per-pair findings, the reproducibility footnote, and the resolved seed paths.

If the verdicts artifact records analyze_halted=true, this command renders only the halt summary section and exits. No EXTRACT candidates are surfaced; the operator must rerun /dedupe-analyze after addressing the halt cause.


Phase 3.1 — Aggregate verdicts

Parse the verdicts artifact and group findings by verdict family:

Read the full file on GitHub · 211 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 211 lines · 38 tokens per session scan A cf9661fedc77

Subscribe to this mod's changes

dedupe-report is a command published in the GitHub repository axiomantic/spellbook (10 stars, last pushed yesterday), licensed MIT. It adds 38 tokens to every session and 1,840 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.