Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/davidmatousek/tachi/executegit clone --depth 1 https://github.com/davidmatousek/tachiWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00020 | $0.00650 |
| Opus 5 | $0.00010 | $0.00325 |
| Sonnet 5 | $0.00004 | $0.00130 |
| Haiku 4.5 | $0.00002 | $0.00065 |
Grade A, and why
execute scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- execute — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 94 lines — stays where its author put it; the contents beside it link to each section on GitHub.
User Input
$ARGUMENTS
You MUST consider the user input before proceeding (if not empty).
Overview
Execute ad-hoc tasks with automatic agent assignment and parallel orchestration. Use for quick fixes, updates, and multi-file changes without the full triad workflow.
Input: Natural language task description (e.g., "Fix the OAuth bug and update docs")
Output: Completed tasks + Architect review (if code changes) + Execution summary
Agent Assignment
See Agent Registry for task-to-agent mapping.
| Pattern | Agent |
|---|---|
| api, endpoint, backend, database | senior-backend-engineer |
| component, ui, react, frontend | frontend-developer |
| test, validation, e2e | tester |
| deploy, docker, ci/cd, infrastructure | devops |
| debug, investigate, root cause | debugger |
| security, vulnerability, auth | security-analyst |
| design, mockup, ux | ux-ui-designer |
| research, evaluate, best practice | web-researcher |
| docs/architecture/ | architect |
| docs/devops/ | devops |
Workflow
Step 1: Parse Tasks
Split user input by "and", ",", "then", ";" into discrete tasks. Classify each by keywords from the Agent Registry.
Step 2: Assign Agents
Map each task to primary agent using the Agent Registry table.
Step 3: Compute Waves
- Wave 1: Tasks with no dependencies (can run in parallel)
- Wave 2+: Tasks that depend on previous waves
- Sequential keywords ("then", "after") create dependencies
Step 4: Execute
Launch agents in parallel within each wave using Task tool. Wait for wave completion before starting next wave.
Step 5: Architect Review
If any code was changed, invoke architect agent to review technical decisions.
Step 6: Summary
Report completed tasks, files modified, wave timings, and any issues.
Examples
Quick fix:
/execute Fix the login redirect bug and add a test for it
→ Wave 1: debugger (fix) → Wave 2: tester (test)
Parallel work:
/execute Add logging to the API, update the README
→ Wave 1: senior-backend-engineer + product-manager (parallel)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 94 lines · 20 tokens per session scan A 71be2f015d33
execute is a command published in the GitHub repository davidmatousek/tachi (90 stars, last pushed 20d ago), licensed Apache-2.0. It adds 20 tokens to every session and 650 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
fortigate
Run cs-security-analyst (AT + CA workflows) against the Fintech FortiGate zero-day scenario and produce a 7-task scorecard.
orchestrate
Run the full 4-agent USAP orchestration chain (cs-security-analyst → cs-incident-responder → cs-ciso-advisor → cs-security-program-manager) against the Perfect Storm scenario. Shows inter-agent handoffs and per-agent mock comparison.
README
Claude Code slash commands for the Unified Security Agent Platform (USAP). These commands let you load any USAP skill as a live LLM persona and run structured compliance tests — all inside a Claude Code session.
challenge
Run cs-security-analyst (AT workflow) against the Perfect Storm 8-vector crisis scenario and produce a 12-check mock comparison scorecard.
compare
Before/after comparison of zero-day-response SKILL.md v1 (broken) vs v2 (fixed) against the FortiGate zero-day scenario. Outputs a scored table.
test
Run a USAP skill against the FortiGate zero-day test scenario and produce a 6-problem compliance scorecard.