Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/bybren-llc/safe-agentic-workflow/releasegit clone --depth 1 https://github.com/bybren-llc/safe-agentic-workflowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/bybren-llc/safe-agentic-workflow/release)<a href="https://agentmods.dev/commands/bybren-llc/safe-agentic-workflow/release"><img src="https://agentmods.dev/badge/commands/bybren-llc/safe-agentic-workflow/release.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00022 | $0.01898 |
| Opus 5 | $0.00011 | $0.00949 |
| Sonnet 5 | $0.00004 | $0.00380 |
| Haiku 4.5 | $0.00002 | $0.00190 |
Grade A, and why
release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 277 lines — stays where its author put it; the contents beside it link to each section on GitHub.
📋 TEMPLATE: This command uses
{{MAIN_BRANCH}},{{TICKET_PREFIX}}, and{{GITHUB_ORG}}/{{GITHUB_REPO}}placeholders. Replace with your project values.
You are executing a full version release. Follow each phase in order. Do not skip phases. Report status after each.
Input
The user provides a version number (e.g., v2.7.0). If not provided, determine the next version by:
git tag -l 'v*' | sort -V | tail -1
Then bump the minor version (or ask the user for major/minor/patch).
Phase 1: Pre-Release Validation
1.1 Verify Clean State
git status # Must be clean
git branch --show-current # Must be on {{MAIN_BRANCH}}
git fetch origin
git log --oneline origin/{{MAIN_BRANCH}}..HEAD # Must be empty (in sync)
BLOCKER: Working tree must be clean and branch must be current with remote.
1.2 Check Open PRs
gh pr list --state open
Decision point: If there are open PRs intended for this release, merge them first (Phase 2). If none, skip to Phase 3.
1.3 Verify CI Status
For each open PR to merge:
gh pr view <NUMBER> --json mergeStateStatus,statusCheckRollup \
--jq '{state: .mergeStateStatus, checks: [.statusCheckRollup[] | "\(.name): \(.conclusion // .status)"]}'
BLOCKER: All checks must pass. Do not merge PRs with failing required checks.
Phase 2: Merge Open PRs (if any)
2.1 Merge in Dependency Order
For each PR (merge in order — base dependencies first):
# Squash merge with proper commit message
gh pr merge <NUMBER> --squash --subject "type(scope): description [{{TICKET_PREFIX}}-XXX]"
2.2 Rebase Dependent PRs
After each merge, rebase any remaining PRs that target the same base:
git fetch origin
git checkout <dependent-branch>
git rebase origin/{{MAIN_BRANCH}}
git push --force-with-lease origin <dependent-branch>
Wait for CI to re-run before merging the next PR.
2.3 Sync Local After All Merges
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 277 lines · 22 tokens per session scan A 5f32d7bb305d
release is a command published in the GitHub repository bybren-llc/safe-agentic-workflow (406 stars, last pushed 1mo ago), licensed MIT. It adds 22 tokens to every session and 1,898 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
help
Category: System Syntax: /help [command|topic].
translate-docs
翻译项目文档到指定语言.
review-tasks
审查任务的忠实度、可执行性、依赖关系与验证.
clarify
Reduce spec ambiguity via targeted questions with adaptive auto-invocation (planning is 80% of success).
tasks-to-issues
将现有任务转换为该功能的可操作 GitHub Issues.
ultrathink
Enter deep craftsman mode - question everything, plan like Da Vinci, craft insanely great solutions, then materialize to roadmap.