Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/gotalab/cc-sdd/validate-implgit clone --depth 1 https://github.com/gotalab/cc-sddWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00009 | $0.00462 |
| Opus 5 | $0.00005 | $0.00231 |
| Sonnet 5 | $0.00002 | $0.00092 |
| Haiku 4.5 | $0.00001 | $0.00046 |
Grade A, and why
validate-impl scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- validate-impl — 94% identical, 8 lines differ
What it actually says
Implementation Validation
Parse Arguments
- Feature name:
$1(optional) - Task numbers:
$2(optional)
Auto-Detection Logic
Perform detection before invoking Subagent:
If no arguments ($1 empty):
- Parse conversation history for
/kiro:spec-impl <feature> [tasks]patterns - OR scan
{{KIRO_DIR}}/specs/*/tasks.mdfor[x]checkboxes - Pass detected features and tasks to Subagent
If feature only ($1 present, $2 empty):
- Read
{{KIRO_DIR}}/specs/$1/tasks.mdand find all[x]checkboxes - Pass feature and detected tasks to Subagent
If both provided ($1 and $2 present):
- Pass directly to Subagent without detection
Invoke Subagent
Delegate validation to validate-impl-agent:
Use the Task tool to invoke the Subagent with file path patterns:
Task(
subagent_type="validate-impl-agent",
description="Validate implementation",
prompt="""
Feature: {$1 or auto-detected}
Target tasks: {$2 or auto-detected}
Mode: {auto-detect, feature-all, or explicit}
File patterns to read:
- {{KIRO_DIR}}/specs/{feature}/*.{json,md}
- {{KIRO_DIR}}/steering/*.md
Validation scope: {based on detection results}
"""
)
Display Result
Show Subagent summary to user, then provide next step guidance:
Next Steps Guidance
If GO Decision:
- Implementation validated and ready
- Proceed to deployment or next feature
If NO-GO Decision:
- Address critical issues listed
- Re-run
/kiro:spec-impl <feature> [tasks]for fixes - Re-validate with
/kiro:validate-impl [feature] [tasks]
Note: Validation is recommended after implementation to ensure spec alignment and quality.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 69 lines · 0 tokens per session scan A 6df4e0ebcd9d
validate-impl is a command published in the GitHub repository gotalab/cc-sdd (3,646 stars, last pushed 3mo ago), licensed MIT. It adds 9 tokens to every session and 462 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
evaluate
Evaluate a skill across model tiers using blind testing.
cost-tracker
Track session costs, understand token spend, and get optimization tips.
t800-onboard
Для чата с новичками. Показывает, что настроено в Cursor (global + local), и что умеет отдел T-800.
verify
Perform a non-destructive post-implementation verification gate validating the implementation against spec.md, plan.md, tasks.md, and constitution.md.
prompt-create
Create a new prompt following ground rules.
make-this
Install the Multi-Agent Loop Kit into the current repo and run the setup interview.