Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/drabaioli/cdd/cdd-process-prgit clone --depth 1 https://github.com/drabaioli/cddWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.02192 |
| Opus 5 | $0.00000 | $0.01096 |
| Sonnet 5 | $0.00000 | $0.00438 |
| Haiku 4.5 | $0.00000 | $0.00219 |
Grade A, and why
cdd-process-pr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 173 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Address the open PR's review feedback: read the review comments for the current branch, triage them, implement the change-requests (pushing back where warranted), then auto-post in-thread replies and auto-commit + push the result.
Run this command on the feature branch (not on main), after a PR has been opened and someone has reviewed it. It is a post-review side-loop, analogous in position to /cdd-merge-base.
Note on automation: this command has a single checkpoint, placed up front: the triage plan in step 4. Once the user approves that plan, the rest of the run — edits, in-thread replies, commit, push — executes without further confirmation gates. Do not add per-action gates after the plan is approved — the one exception is where step 5 routes a workflow gap (folded into this PR, a roadmap item, or an issue on another repo), which the triage plan does not settle and which is asked once, with a recommendation. Review threads are never resolved by this command; the user resolves them.
1. Discover the open PR
Confirm the current branch is not main:
git rev-parse --abbrev-ref HEAD
Resolve the open PR for the current branch:
gh pr view --json number,url,state,headRefName
gh repo view --json owner,name -q '.owner.login + "/" + .name'
- If there is no open PR, stop and report clearly: "No open PR for this branch; nothing to process."
- If
ghreports more than one candidate PR, stop and ask the user which PR number to process.
Hold the owner, repo, and PR number; the steps below refer to them as OWNER, REPO, and NUMBER.
2. Read all three comment surfaces
Read every place a reviewer can leave feedback. gh pr view alone is insufficient for inline review threads and their resolution state, so use gh api.
Inline review threads (with resolution state), via GraphQL:
gh api graphql -f query='
query($owner:String!, $repo:String!, $pr:Int!) {
repository(owner:$owner, name:$repo) {
pullRequest(number:$pr) {
reviewThreads(first:100) {
nodes {
isResolved
isOutdated
comments(first:100) {
nodes { databaseId body path line author { login } }
}
}
}
}
}
}' -F owner=OWNER -F repo=REPO -F pr=NUMBER
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 173 lines · 0 tokens per session scan A d2501ed2283c
cdd-process-pr is a command published in the GitHub repository drabaioli/cdd (2 stars, last pushed 7d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 2,192 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
version
Display current guide and Claude Code versions.
go-review
Go code review for idiomatic patterns.
review-branch
Review the current branch's diff against base by dispatching atomic-reviewer. No orchestration loop, no spec required — pre-flight before /commit pr or /commit merge.
dispatcher
Pick the next-best repo to work on across the portfolio — rank free repos, recommend one, claim its lease atomically, and route to the entry command.
docs-review
Phase 4 of documenting-projects: Quality gate with 8 measurable criteria and iteration. Triggers: '/docs-review', invoked by documenting-projects orchestrator.
standup
Show a daily standup summary with completed, in-progress, and blocked tasks across all active epics.