Borrowing it
Nothing to install: this file belongs to Contoso-State/red-team-agent-orchestration. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Contoso-State/red-team-agent-orchestration/main/.claude/commands/report.mdgit clone --depth 1 https://github.com/Contoso-State/red-team-agent-orchestrationWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/contoso-state/red-team-agent-orchestration/report)<a href="https://agentmods.dev/commands/contoso-state/red-team-agent-orchestration/report"><img src="https://agentmods.dev/badge/commands/contoso-state/red-team-agent-orchestration/report/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/contoso-state/red-team-agent-orchestration/report"><img src="https://agentmods.dev/badge/commands/contoso-state/red-team-agent-orchestration/report.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00014 | $0.01139 |
| Opus 5 | $0.00007 | $0.00570 |
| Sonnet 5 | $0.00003 | $0.00228 |
| Haiku 4.5 | $0.00001 | $0.00114 |
Grade A, and why
report scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 65 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/report — Generate Assessment Report
You are acting as the Reporting Agent (agents/reporting/system-prompt.md). Turn raw findings into the final deliverables.
Preconditions
engagements/<session>/findings/raw/*.jsonlis populated (run/assessand ideally/attack-pathsfirst).engagements/<session>/engagement.dbexists with findings ingested (the canonical, deduplicated source).
Steps
- Refresh findings from current raw inputs, then export canonical artifacts. Always run findings ingest in replace mode first so stale DB rows from prior passes cannot leak into this report:
node tools/datastore/ingest.mjs --db engagements/<session>/engagement.db --session engagements/<session> --findings engagements/<session>/findings/raw --replace-findingsnode tools/datastore/export.mjs --db engagements/<session>/engagement.db --session engagements/<session> --what allThis writesfindings/normalized/findings.json,reports/findings.json,coverage.json,inventory/resources.jsonl, andinventory/summary.json.
- Validate the exported
engagements/<session>/reports/findings.jsonagainstschemas/finding.schema.json(node tools/validate-findings.mjs); fix or drop malformed entries at the source and re-export. - Confirm deduplication. The DB already deduplicates by
dedupe_key(falling back toid) and unionsaffected_resources[]; spot-check that the same misconfiguration across resources collapsed into one aggregated finding. - Reconcile severity using
knowledge/severity-model.md. You set the final severity consistently. - Promote attack paths from the Authorization & Attack Path Agent to the top.
- Map controls (CIS Azure, MITRE) from
controls/. - Surface coverage limitations from
engagements/<session>/inventory/coverage-limitations.json. - Promote the run into history and surface deltas.
node tools/datastore/promote.mjs --db engagements/<session>/engagement.db --history engagements/_history/<engagement.id>.db --out engagements/<session>/reports/delta.json. Lead the executive summary's "What changed" with the resulting new / persisting / resolved / regressed counts (the first run has no prior, so everything is new). - Render:
engagements/<session>/reports/executive-summary.md(fromreports/templates/executive-summary.md)engagements/<session>/reports/technical-report.md(fromreports/templates/technical-report.md)engagements/<session>/reports/assessment-deck.md(fromreports/templates/assessment-deck.md) — the PowerPoint-convertible slide deck. Follow the slide rules in that template (##titles,---separators, one idea per slide). See/deckfor the standalone flow and conversion commands.engagements/<session>/reports/findings.json(normalized canonical set)engagements/<session>/reports/report.html— the interactive HTML report, generated fromfindings.json(a print-first consulting deliverable: cover, contents, executive summary, attack paths, findings, prioritized recommendations, asset/scope inventory, a consolidated pan/zoom attack graph, and appendices):
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 65 lines · 14 tokens per session scan A a86f9789b01c
report is a command published in the GitHub repository Contoso-State/red-team-agent-orchestration (6 stars, last pushed 5d ago), licensed MIT. It adds 14 tokens to every session and 1,139 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
brand-generate
Generate an on-brand document from a saved Brand Profile.
cti-report
Render case deliverables — relationship graph (PNG/SVG/Mermaid) and a polished PDF/DOCX assessment. Usage: /cti-report [--graph|--pdf].
prose-review-docs
Reviews markdown documentation files or directories against the active prose style rules — the plugin's vendor-neutral baseline plus your organization's overlay when one is configured. Accepts a file path or directory (recursive). Runs prose-style-checker and optionally Vale. Supports --fix to auto-apply safe…
ppt-image2-editable-rebuild
Rebuild image2 or imagegen reference slides as editable PowerPoint decks.
render-figures
Compile all .tex and .typ figure files in a directory.
harness-onboarding
Generate a human-readable onboarding document from HARNESS.md, AGENTS.md, and REFLECTIONLOG.md — a friendly guide for new team members.