Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/cognitx-leyton/codegraph/create-prgit clone --depth 1 https://github.com/cognitx-leyton/codegraphWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00013 | $0.00713 |
| Opus 5 | $0.00006 | $0.00357 |
| Sonnet 5 | $0.00003 | $0.00143 |
| Haiku 4.5 | $0.00001 | $0.00071 |
Grade C, and why
create-pr scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
PYPI_VERSION=$(curl -s https://pypi.org/pypi/cognitx-codegraph/json 2>/dev/null | python3 -c "import sys,json; print(json.load(sys.stdin)['info']['version'])" 2>/dev/null || echo "not published") Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
allowed-tools: Bash(git:*), Bash(gh:*), Bash(grep:*), Bash(curl:*) How it starts
The opening of the file, as written. The whole thing — 105 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Create PR (Step 12 — final workflow step)
Create a pull request from the current feature branch to hotfix with a full description of what was implemented.
Process
1. Verify state
git branch --show-current # must be a feature branch (feat/, fix/, chore/)
git status -s # should be clean
git log --oneline hotfix..HEAD # commits to include
If uncommitted changes exist: STOP, run /commit first.
If on a protected branch (main/release/hotfix): STOP, wrong branch.
2. Push the feature branch
BRANCH=$(git branch --show-current)
git push origin "$BRANCH"
3. Get PyPI version (if packaged)
PYPI_VERSION=$(curl -s https://pypi.org/pypi/cognitx-codegraph/json 2>/dev/null | python3 -c "import sys,json; print(json.load(sys.stdin)['info']['version'])" 2>/dev/null || echo "not published")
4. Analyze commits
Review ALL commits between hotfix and the feature branch:
BRANCH=$(git branch --show-current)
git log --oneline hotfix.."$BRANCH"
git diff --stat hotfix.."$BRANCH"
Identify: type of change (feat/fix/refactor), scope, key changes.
5. Comment on the source issue (if applicable)
If an issue number was mentioned, add an implementation summary:
gh issue comment <N> --body "## Implementation Complete
**Package:** cognitx-codegraph=={version}
### What was done
- <summary>
### Tests
- {N} tests passing
This issue will be automatically closed when the PR is merged."
6. Create PR
Include Closes #N in the body so GitHub auto-closes the issue on merge.
Do NOT manually close the issue.
BRANCH=$(git branch --show-current)
gh pr create --base hotfix --head "$BRANCH" --title "<type>: <concise description>" --body "$(cat <<'EOF'
Closes #<N>
## Summary
- <bullet 1: what changed>
- <bullet 2: what changed>
## Test plan
- [x] Unit tests: {N} passed
- [x] Byte-compile clean
- [x] Code review: clean
- [x] Critique: PASS
- [x] Self-index verified
- [ ] Leytongo real-world test
## Package
PyPI: `cognitx-codegraph=={version}`
Install: `pip install cognitx-codegraph=={version}`
Generated with [Claude Code](https://claude.com/claude-code)
EOF
)"
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 105 lines · 13 tokens per session scan C 25607f2d8ab5
create-pr is a command published in the GitHub repository cognitx-leyton/codegraph (11 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 13 tokens to every session and 713 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
feedback
Security Design Review — PRD/기획서 기반 보안 의견서·검토 의견서 생성.
compliance
이전 보안 진단 보고서의 Finding들이 패치되었는지 확인하고, 변경된 코드에서 신규 취약점을 탐색합니다.
va
Vulnerability Assessment — 8차원 아키텍처 진단 + Self-Verify + Evidence Verification.
pentest
Penetration Testing — 시나리오 기반 모의해킹 + POC + 라이브 검증 (State Delta 기반).
redteam
Red Team Operations — 인프라 설정 보안 리뷰 + MITRE ATT&CK + Detection Engineering.
verify
Adversarial Verification — 보안 진단 보고서 독립 검증 (Autonomous First).