Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/flaviozanoni/minos/configuregit clone --depth 1 https://github.com/FlavioZanoni/minosWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/flaviozanoni/minos/configure)<a href="https://agentmods.dev/commands/flaviozanoni/minos/configure"><img src="https://agentmods.dev/badge/commands/flaviozanoni/minos/configure.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00011 | $0.01030 |
| Opus 5 | $0.00005 | $0.00515 |
| Sonnet 5 | $0.00002 | $0.00206 |
| Haiku 4.5 | $0.00001 | $0.00103 |
Grade A, and why
configure scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- minos-configure — 91% identical, 9 lines differ
How it starts
The opening of the file, as written. The whole thing — 70 lines — stays where its author put it; the contents beside it link to each section on GitHub.
The user wants minos configured as follows: $ARGUMENTS
Translate that into config changes and apply them. Everything you need is below - do not guess fields.
Files
- Global (applies everywhere):
~/.config/minos/rules.jsonc - Project (this repo only):
.minos/rules.jsonc
Pick the scope the user implied ("everywhere/always" → global; otherwise default to project). Read the target file first (it may not exist - then create it). Files are JSONC: // comments and trailing commas are allowed; when editing, preserve existing entries and comments.
Schema
{
"rules": [
{
"id": "kebab-case-unique-id", // required
"summary": "one-line description", // optional, shown in the config UI
"enabled": false, // optional: keep the rule in config but skip it; omit = active
"appliesTo": {
"tools": ["Bash"], // which agent tools: Bash for commands, Edit/Write for file changes; omit = all
"pathGlob": ["src/**/*.ts"], // content rules only; ** = any depth, * = within segment; omit = all files
"commandMatch": ["git commit"] // command rules only; case-insensitive substrings; omit = all commands
},
"trigger": {
// exactly one of these three shapes:
// { "type": "contains", "patterns": ["push --force"] } // case-insensitive literal, any match fires
// { "type": "regex", "patterns": ["rm\\s+-[a-z]*r[a-z]*f"] } // JS regex, case-SENSITIVE, any match fires
// { "type": "llm-judge", "promptText": "yes/no question", "context": "tooling", "model": "..." }
// promptText = inline judge prompt (preferred); "prompt": "path.md" = prompt file relative to the
// config dir; "context": "tooling" additionally sends the project's discovered scripts/CLIs to the judge;
// "model" = per-rule judge model override, omit to inherit the config-level default
},
"action": "block", // "block" denies the action; "warn" lets it through with a notice
"message": "shown to the agent when the rule fires - say what to do instead"
}
],
"disable": ["global-rule-id", { "id": "other-id", "reason": "why" }], // project file only: turn off global rules here
"judge": { "model": "claude-haiku-4-5-20251001", "timeoutMs": 30000 } // default model for llm-judge rules
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 70 lines · 11 tokens per session scan A d31cb6afa9f1
configure is a command published in the GitHub repository FlavioZanoni/minos (5 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 11 tokens to every session and 1,030 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
composite-actions
Generate, review, secure, and test composite GitHub Actions following best practices — full repo scaffold, interview-driven generation, PR creation on existing repos, SHA pinning, secrets-as-inputs, job summaries, and actionlint validation.
github-actions
Design, review, secure, and debug GitHub Actions workflows — reusable workflows, OIDC federation, SHA pinning, token scoping, promotion orchestration, and CI failure diagnosis.
datadog
Set up and troubleshoot Datadog — Agent deployment on Kubernetes, APM instrumentation, Log Management, Monitors, Dashboards, SLOs, Synthetic tests, and live incident investigation using the Datadog MCP server. Covers Terraform-managed Datadog resources.
fluxcd
FluxCD entry point — routes to the right workflow based on what you need. Live cluster issue → structured 5-workflow debug trace. Repo health check → 6-phase audit (discovery, validation, API compliance, best practices, security). Helm chart review → helmchart. Starts by asking one question to confirm the right mode.
linkerd
Linkerd-specific diagnostics — mTLS verification, proxy injection issues, authorization policy debugging, traffic management, and multi-cluster connectivity problems.
announce
Draft X/Twitter announcement post (or thread) for the latest plugin release.