Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/goldziher/poly/poly-checkgit clone --depth 1 https://github.com/Goldziher/polyWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00015 | $0.00460 |
| Opus 5 | $0.00008 | $0.00230 |
| Sonnet 5 | $0.00003 | $0.00092 |
| Haiku 4.5 | $0.00002 | $0.00046 |
Grade A, and why
poly-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
poly Check
Run poly as a checking gate over ${1:-.}. Apply no fixes.
poly fmt --check ${1:-.} --format json— capture formatting drift.poly lint ${1:-.} --format json— capture lint findings (remember the whole-project section is on stderr under--format json; check the exit code).
Step 2 applies no fixes, but it is not read-only: poly lint's whole-project phase executes
the configured whole-project tools (cargo clippy and friends) against the live worktree, and
their own side effects — a refreshed lock file, a populated build or type-checker cache — are
not poly's to control. Add --no-workspace when the tree must be left untouched; that drops
the whole-project tools from the check, so say so in the report.
That phase only runs when the argument is the repository root (the . default) or no path at
all. Naming narrower paths makes the run path-scoped — the per-file tier only, with a note
on stderr — so poly lint src/ is already free of those side effects. Pass --workspace to
opt back in; the phase then covers the whole repository regardless of the paths named.
Report:
- Which files have formatting drift.
- Lint findings grouped by rule and severity (error vs warning).
- The overall pass/fail from the exit codes:
0clean;1findings or drift — forlintonly error-severity findings (or a failing whole-project tool) reach1, warnings still exit0;2the run did not verify what it was asked to (a missing path, a file an engine failed on, a--deny-skips/--max-skipsbreach, or the whole-project phase itself erroring).
Do not apply fixes here — if the user wants them applied, run /poly-fix.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 37 lines · 15 tokens per session scan A bc822803e987
poly-check is a command published in the GitHub repository Goldziher/poly (10 stars, last pushed 3d ago), licensed MIT. It adds 15 tokens to every session and 460 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
brooks-audit
Run a Brooks-Lint architecture audit.
todo
The quality-gated task list: tasks with real descriptions, testable acceptance criteria, and evidence — a task only closes when the controller agrees it is done.
release
The pre-tag controller: version sync, changelog, clean tree, gate, and suite — every failure listed, the tag printed, never run.
security
The security pass: secrets (blocking), SAST, dependency vulns — plus the index's entry points to review from.
git
The pre-finish status: branch, hygiene findings, message checks, workflow lint, template state.
init
Install the formatters this repository needs, with every command visible before it runs.