Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/dheerg/swarms/update-workflowgit clone --depth 1 https://github.com/DheerG/swarmsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00015 | $0.02327 |
| Opus 5 | $0.00008 | $0.01163 |
| Sonnet 5 | $0.00003 | $0.00465 |
| Haiku 4.5 | $0.00002 | $0.00233 |
Grade A, and why
update-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 119 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/swarm:update-workflow
You are updating an existing custom workflow's shortcut command to match the current swarm template. This command regenerates only the plugin-owned wiring of .claude/commands/<name>.md — the ## Workflow section and default wiring that comes from swarm. It never touches the mode skill at .claude/skills/<name>-mode/SKILL.md — that file is consumer-owned.
Step 0: Parse argument
$ARGUMENTS
The argument is the workflow name (kebab-case, matching the existing file name without .md). If $ARGUMENTS is empty, ask the user (plain text, not AskUserQuestion): "Which workflow should I update? (Pass the name — e.g., triage-gh-issue.)" Wait for their response.
Step 1: Locate and read the existing file
The target file is .claude/commands/<name>.md in the current working directory.
- If the file does not exist: tell the user "No workflow found at
.claude/commands/<name>.md. This command updates existing workflows — use/swarm:create-workflowto create a new one." Stop. - If the file exists: use the Read tool to read it.
Do not read or modify .claude/skills/<name>-mode/SKILL.md. That file is consumer-owned.
Step 2: Extract consumer-owned sections
From the existing shortcut command, extract these consumer-owned values and blocks verbatim. These will be preserved:
- Frontmatter fields:
description,argument-hint,disable-model-invocation, and any other fields present. Preserve all of them. ## Settingssection — the entire block under the## Settingsheading, including Mode, Outcomes question, Defaults, and any other settings the consumer has added.## User-Provided Contextsection — the block under that heading (typically$ARGUMENTS).## Pre-flightsection if present — the block under that heading (intake-specific actions, bash commands, arg parsing). This is consumer-owned.- Any section not recognized as plugin-owned — preserve as-is.
Consumer ownership rule: anything that is not the plugin-owned wiring (the template preamble and the ## Workflow section) belongs to the consumer.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 119 lines · 15 tokens per session scan A 5da735fdcb7e
update-workflow is a command published in the GitHub repository DheerG/swarms (86 stars, last pushed 1mo ago), licensed MIT. It adds 15 tokens to every session and 2,327 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
prompt
System instructions for writing effective prompts. Apply when generating commands, skills, agents, or any LLM instructions.
full
Run the full hope pipeline — intent, shape, target, freeze as needed — then execute.
token-review
Analyze SDLC token usage from .claude/sdlc/token-log.json (last run) and token-history.jsonl (rolling). Surfaces the biggest cost centers and concrete optimization candidates. Read-only.
start
Activate the SDLC workflow (opt-in), re-enable after suspension, or start a new task when already enabled. On fresh install — auto-detects repo/CI/stack/tracker (≤3 prompts), creates .enabled, takes a one-sentence task description, and auto-generates scope.md and a draft plan. On re-enable — verifies the suspension…
build
Start Phase 4 — implement the approved design with surgical-edit discipline and work-item traceability.
configure
Guided setup for config/tools.json and config/tools.local.json. Replaces manual file editing for first-time setup and common reconfigurations. Auto-invoked on fresh install (Layer 0) and when a command finds its required config missing (Layer 2). Safe to run anytime for proactive changes.