Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/flagler-county-bocc/mcp-forge/http-apigit clone --depth 1 https://github.com/Flagler-County-BoCC/mcp-forgeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00958 |
| Opus 5 | $0.00000 | $0.00479 |
| Sonnet 5 | $0.00000 | $0.00192 |
| Haiku 4.5 | $0.00000 | $0.00096 |
Grade A, and why
http-api scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 124 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Entrypoint — http-api
This file is consumed by Step 8 of the rewrite process. Apply when
AUDIT_MANIFEST.projectType === "http-api".
Controller Convention
// src/modules/<domain>/<domain>.controller.ts
export class <Domain>Controller {
constructor(private readonly service: <Domain>Service) {}
async get<Domain>ById(req: Request, res: Response): Promise<void> {
const { id } = validate(IdParamSchema, req.params);
const result = await this.service.get<Domain>ById(id);
res.status(200).json(ok(result));
}
}
Rules:
- Validate all inputs with
validate()at the top of each method. - Use
ok(),created(), orpaginated()fromsrc/lib/response.tsfor all responses. - Wrap Express handlers with
asyncHandler(see below) during route registration. - Controllers only receive service instances via constructor.
src/lib/async-handler.ts (Express only)
import type { Request, Response, NextFunction, RequestHandler } from 'express';
type AsyncFn = (req: Request, res: Response, next: NextFunction) => Promise<void>;
export function asyncHandler(fn: AsyncFn): RequestHandler {
return (req, res, next) => void fn(req, res, next).catch(next);
}
Routes — src/routes/.routes.ts
Express:
import { Router } from 'express';
import { asyncHandler } from '../lib/async-handler.js';
import { <domain>Controller } from '../lib/container.js';
const router = Router();
router.get('/:id', asyncHandler((req, res) => <domain>Controller.get<Domain>ById(req, res)));
router.post('/', asyncHandler((req, res) => <domain>Controller.create<Domain>(req, res)));
export { router as <domain>Routes };
Fastify:
import type { FastifyPluginAsync } from 'fastify';
export const <domain>Routes: FastifyPluginAsync = async (fastify) => {
fastify.get('/:id', handler);
fastify.post('/', handler);
};
src/routes/index.ts
Register all domain routers under their base path:
// Express:
app.use('/api/v1/<domain>', <domain>Routes);
// Fastify:
app.register(<domain>Routes, { prefix: '/api/v1/<domain>' });
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 124 lines · 0 tokens per session scan A e5f3bec3e8ca
http-api is a command published in the GitHub repository Flagler-County-BoCC/mcp-forge (1 stars, last pushed 2mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 958 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
build-fix
빌드 에러를 자동으로 분석하고 수정합니다.
test-ts
Run TypeScript tests for Solana frontends and Anchor programs.
types
Debug and fix TypeScript type errors with systematic analysis and expert guidance.
setup-project
Initialize a new Bun + TypeScript backend project with best practices setup (Hono, Prisma, Biome, testing, Docker).
sdk
Create or extract TypeScript SDK.
scaffold-react
Quickly scaffold a new React + TypeScript project with Claude Code configuration.