Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/frankxai/agentic-creator-os/command_compliance_reportgit clone --depth 1 https://github.com/frankxai/agentic-creator-osWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/frankxai/agentic-creator-os/command_compliance_report)<a href="https://agentmods.dev/commands/frankxai/agentic-creator-os/command_compliance_report"><img src="https://agentmods.dev/badge/commands/frankxai/agentic-creator-os/command_compliance_report.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00420 |
| Opus 5 | $0.00000 | $0.00210 |
| Sonnet 5 | $0.00000 | $0.00084 |
| Haiku 4.5 | $0.00000 | $0.00042 |
Grade A, and why
COMMAND_COMPLIANCE_REPORT scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to COMMAND_COMPLIANCE_REPORT — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
Analysis Commands Compliance Report
Overview
Reviewed all command files in .claude/commands/analysis/ directory to ensure proper usage of:
mcp__claude-flow__*tools (preferred)npx claude-flowcommands (as fallback)- No direct implementation calls
Files Reviewed
1. token-efficiency.md
Status: ✅ Updated Changes Made:
- Replaced
npx ruv-swarm hook session-end --export-metricswith proper MCP tool call - Updated to:
Tool: mcp__claude-flow__token_usagewith appropriate parameters - Maintained result format and context
Before:
npx ruv-swarm hook session-end --export-metrics
After:
Tool: mcp__claude-flow__token_usage
Parameters: {"operation": "session", "timeframe": "24h"}
2. performance-bottlenecks.md
Status: ✅ Compliant (No changes needed)
Reason: Already uses proper mcp__claude-flow__task_results tool format
Summary
- Total files reviewed: 2
- Files updated: 1
- Files already compliant: 1
- Compliance rate after updates: 100%
Compliance Patterns Enforced
- MCP Tool Usage: All direct tool calls now use
mcp__claude-flow__*format - Parameter Format: JSON parameters properly structured
- Command Context: Preserved original functionality and expected results
- Documentation: Maintained clarity and examples
Recommendations
- All analysis commands now follow the proper pattern
- No direct bash commands or implementation calls remain
- Token usage analysis properly integrated with MCP tools
- Performance analysis already using correct tool format
The analysis directory is now fully compliant with the Claude Flow command standards.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 54 lines · 0 tokens per session scan A 8e72f8fedc88
COMMAND_COMPLIANCE_REPORT is a command published in the GitHub repository frankxai/agentic-creator-os (10 stars, last pushed 2d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 420 tokens. A static security scan graded it A with 0 findings. It is 100% identical to COMMAND_COMPLIANCE_REPORT, differing in 0 lines, and is treated as a copy.
Other commands, from other repositories
security-audit-static
Static security audit of AI-built code — map trust boundaries, cross-reference documented intent, self-refute every finding, and report only evidence-backed risks.
sprint
Sprint lifecycle — plan a sprint, run a retrospective, or generate release notes.
performance-audit-static
Static performance audit of AI-built code — find N+1 queries and request waterfalls, over-fetching, missing indexes, and caching opportunities, ranked by effort and impact.
analyze-test
Analyze A/B test results — statistical significance, sample size validation, and ship/extend/stop recommendations.
document-app
Reverse-engineer an AI-built codebase into the system documents reviewers and auditors need — a core set (architecture, flows, permissions, variables) plus conditional docs (emails, cron, SEO, automation) when they apply.
meeting-notes
Summarize a meeting transcript into structured notes with decisions, action items, and follow-ups.