Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/bybren-llc/safe-agentic-workflow/local-syncgit clone --depth 1 https://github.com/bybren-llc/safe-agentic-workflowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/bybren-llc/safe-agentic-workflow/local-sync)<a href="https://agentmods.dev/commands/bybren-llc/safe-agentic-workflow/local-sync"><img src="https://agentmods.dev/badge/commands/bybren-llc/safe-agentic-workflow/local-sync.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00007 | $0.02155 |
| Opus 5 | $0.00003 | $0.01077 |
| Sonnet 5 | $0.00001 | $0.00431 |
| Haiku 4.5 | $0.00001 | $0.00215 |
Grade C, and why
local-sync scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
rm -rf node_modules How it starts
The opening of the file, as written. The whole thing — 378 lines — stays where its author put it; the contents beside it link to each section on GitHub.
📋 TEMPLATE: This command is a template. See "Customization Guide" below to adapt for your infrastructure.
Perform complete local development environment sync after pulling from dev branch. This ensures dependencies, database, and validation are all up-to-date.
Workflow
1. Git Branch Cleanup (Best Practice)
Check current branch and switch to dev if needed:
CURRENT_BRANCH=$(git branch --show-current)
echo "Current branch: $CURRENT_BRANCH"
If on feature branch:
- Check for uncommitted changes
- If clean, switch to dev:
git checkout dev - If dirty, offer to stash:
git stash && git checkout dev - Save feature branch name for cleanup
Switch to dev branch:
git checkout dev
2. Git Pull
Pull latest changes from origin/dev:
git pull origin dev
If pull fails due to uncommitted changes:
- Stash changes:
git stash - Pull again
- Reapply stash:
git stash pop
3. Branch Cleanup (Git Best Practice)
After pulling latest dev, clean up merged branches:
Check if previous feature branch is merged:
# If we switched from a feature branch, check if it's merged
git branch --merged dev | grep -v "^\*" | grep -v "dev" | grep -v "master"
Offer to delete merged feature branch:
# Example: {{TICKET_PREFIX}}-381-rename-slash-commands-remote-prefix
git branch -d {{TICKET_PREFIX}}-381-rename-slash-commands-remote-prefix
Prune remote tracking branches:
# Remove stale remote tracking branches
git fetch --prune origin
List stale local branches:
# Show branches not updated in 30+ days
git for-each-ref --sort=-committerdate refs/heads/ --format='%(refname:short) | %(committerdate:relative)' | grep -E 'weeks|months|years' ago
Offer to delete stale branches (interactive)
4. Smart Change Detection
Detect what changed to determine necessary steps:
# Check if package.json changed
DEPS_CHANGED=$(git diff HEAD@{1} HEAD -- package.json yarn.lock)
# Check if prisma schema changed
SCHEMA_CHANGED=$(git diff HEAD@{1} HEAD -- prisma/schema.prisma prisma/migrations/)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 378 lines · 7 tokens per session scan C 0cbd2300c267
local-sync is a command published in the GitHub repository bybren-llc/safe-agentic-workflow (406 stars, last pushed 1mo ago), licensed MIT. It adds 7 tokens to every session and 2,155 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
help
Category: System Syntax: /help [command|topic].
translate-docs
翻译项目文档到指定语言.
review-tasks
审查任务的忠实度、可执行性、依赖关系与验证.
clarify
Reduce spec ambiguity via targeted questions with adaptive auto-invocation (planning is 80% of success).
tasks-to-issues
将现有任务转换为该功能的可操作 GitHub Issues.
ultrathink
Enter deep craftsman mode - question everything, plan like Da Vinci, craft insanely great solutions, then materialize to roadmap.