Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/baek-labs/hames/gogit clone --depth 1 https://github.com/baek-labs/hamesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00015 | $0.00272 |
| Opus 5 | $0.00008 | $0.00136 |
| Sonnet 5 | $0.00003 | $0.00054 |
| Haiku 4.5 | $0.00002 | $0.00027 |
Grade A, and why
go scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/go
사용법: /go <task-id>
이 커맨드 호출 자체를 현재 사용자의 go 요청으로 기록한다. 모델이 자율적으로 호출하거나 예전 승인을 재사용하면 안 된다.
node arsenal/task_contract.js activate --workspace "<workspace-path>" --task-id "<task-id>" --session "<current-session-id>" --approval "current-user:/go <task-id>"
helper가 READY 상태, contract.json 명세 해시, 기록된 승인 출처 구조를 검증해 ACTIVE로 전환한 경우에만 실행한다. --approval은 현재 /go의 감사 기록이지 인증 수단이 아니다. 실행 중에는:
contract.json의 파일 범위와 불변 조건을 지킨다.plan.md를 실행 안내로만 사용한다.- 정의된 검증을 실행하고 성공한 경우에만 helper의 review 전환을 수행한다.
node arsenal/task_contract.js review --session "<current-session-id>"
REVIEW는 검토 대기이며 사용자 인수가 아니다. /go는 Git 작업이나 중요 행동 승인을 포함하지 않는다.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 26 lines · 15 tokens per session scan A af5d852ee63f
go is a command published in the GitHub repository baek-labs/hames (5 stars, last pushed 1mo ago), licensed MIT. It adds 15 tokens to every session and 272 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
ox-session-review
Command "ox-session-review" from sageox/ox, covering failure-mode watch-list (read first), from the ledger root. should print 0, phase 1 — scan & score (read-only), quality buckets (first match wins) and removal candidates.
al
Run AgentLint diagnostic across all projects. Use when: user says /al, 'check all projects', 'agent lint', or '体检'.
dispatcher
Pick the next-best repo to work on across the portfolio — rank free repos, recommend one, claim its lease atomically, and route to the entry command.
audit-plugin
Audit plugin skills, commands, and agents for structure, size, and naming issues.
iterate
自主迭代循环,自动完成任务序列.
harness-upgrade
Discover and adopt new template content after a plugin upgrade — diffs your HARNESS.md against the current template and presents new items for review.