Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/deepfusionlabs/deep-init/versiongit clone --depth 1 https://github.com/deepfusionlabs/deep-initWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00037 | $0.00580 |
| Opus 5 | $0.00018 | $0.00290 |
| Sonnet 5 | $0.00007 | $0.00116 |
| Haiku 4.5 | $0.00004 | $0.00058 |
Grade A, and why
version scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Report the running DeepInit version — fast, no analysis. Do exactly this, then stop:
-
State the loaded version verbatim. This line ships inside the plugin markdown that is actually loaded in your session, so it is the source of truth for "what is running right now":
DeepInit v0.7.2
-
Read the on-disk version (best-effort — skip gracefully if a path isn't present):
- a local clone of this repo →
.claude-plugin/plugin.json(the"version"field) - the marketplace-installed copy → the newest
plugin.jsonunder~/.claude/plugins/(the active pin is recorded in~/.claude/plugins/installed_plugins.json; a newer copy in the cache that the pin hasn't moved to means the update was fetched but not yet applied)
- a local clone of this repo →
-
Compare and advise:
-
loaded == on-disk → "You're running the latest version — you're all set."
-
loaded is behind on-disk → "The running plugin is STALE: a newer version is on disk but not live. Claude Code loads plugin markdown ONCE per session and does not re-read it mid-session, so one activation step remains — and it depends on your host. Detect your host first (from your system context), then do only the matching one:
- Plain terminal / CLI → run
/reload-plugins, or (more reliable for a version/command flip) start a new session. A reload picks up skills and hooks but doesn't rebuild the slash-command index, so this canary may not flip from/reload-pluginsalone — a new session is the sure path. - VS Code / JetBrains extension → restart the IDE itself (a full quit + reopen).
Developer: Reload Windowdoes not reload the plugin host, so the loaded number won't flip from a window reload (or a new chat in the same window). - Desktop app / web → fully restart the app (or reload the session) — a window reload alone is not enough.
Then run
/deep-init:versionagain to confirm the LOADED number flipped (it reports what's actually running, so it's the honest check that activation worked)." - Plain terminal / CLI → run
-
on-disk not found → just report the loaded version.
-
For a full active-vs-installed-vs-newest diagnosis across every plugin (and duplicate-shadow detection), run /oss-kit:oss-plugin-doctor.
$ARGUMENTS
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 28 lines · 37 tokens per session scan A c11c543db66d
version is a command published in the GitHub repository deepfusionlabs/deep-init (6 stars, last pushed 12d ago), licensed MIT. It adds 37 tokens to every session and 580 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
fleet-conformance
Scan every repo on the machine for guardrails, testing, and observability conformance; audit the deltas semantically; produce a fleet report; and propose canary-first remediation.
claude-md-migrate
Rewrite a bloated or stale CLAUDE.md into a lean, verified "map, not wishes" file — nothing invented, hard rules preserved verbatim.
claude-md-new
Scaffold a CLAUDE.md for this repo from battle-tested templates, filled in with the project's real commands.
implement-review
One agent implements a task, then reviews its own work behind a hard verification gate before finalizing.
project-init
Stand up the context layers for a project — a thin pointer-style AGENTS.md plus seed compass maps — without touching the memory layer.
claude-md-audit
Grade this repo's CLAUDE.md / AGENTS.md (0–100) and return a worst-first fix list.