Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/dupe-com/standdown/showcasegit clone --depth 1 https://github.com/dupe-com/standdownWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00025 | $0.00342 |
| Opus 5 | $0.00013 | $0.00171 |
| Sonnet 5 | $0.00005 | $0.00068 |
| Haiku 4.5 | $0.00003 | $0.00034 |
Grade A, and why
showcase scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Publish this extension's standdown grade to the "Graded with standdown" showcase.
It must already grade A or A+ on conformanceGrade (if it hasn't been graded,
run /standdown:setup first).
Follow ${CLAUDE_PLUGIN_ROOT}/showcase/README.md — or, if unavailable,
https://github.com/dupe-com/standdown/blob/main/showcase/README.md. Derive the
submission details from this extension's standdown integration (name, policy set,
disabled hosts, and — if published — its Chrome Web Store id), generate the
submission with the submit tool, build the CI-authoritative card, and open a PR to
dupe-com/standdown. Ask me only for my GitHub handle and today's date.
Before opening the PR, tell me exactly what the submission will disclose — for a
custom policy set that's my resolved policies + disabled hosts, published to a
public Dupe-owned repo — and what it will not send (no self-click ids, keys,
user data, or source). Then ask whether to proceed, submit as allPolicies
to disclose less, or stop; don't publish without my explicit yes.
If my extension is published, also run the Tier 2 live-verify for an A+. Never
hand-edit the generated grade, SHA, card, or SHOWCASE.md — CI re-checks all of
it, so a hand-edit just fails the build.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 25 lines · 25 tokens per session scan A c7bed9c135c2
showcase is a command published in the GitHub repository dupe-com/standdown (5 stars, last pushed 20d ago), licensed MIT. It adds 25 tokens to every session and 342 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
extension-add
Add a feature surface (sidebar, popup, content script, etc.) to an existing extension.
extension-publish
Prepare an extension for store submission (Chrome Web Store, Firefox Add-ons).
interactive-dev
Start a persistent interactive development session with natural language browser control, auto-error monitoring, and full dev tool access.
seo-audit
Run a comprehensive SEO, accessibility, performance, and security audit on a URL, producing a scored report with prioritized recommendations.
record-workflow
Record browser interactions and generate a Playwright test with assertions and best-practice selectors.
kaboom/audit
Run the Kaboom Phase 1 audit for the current tracked site and return a six-lane local report.