Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/iliaal/codesage/codesage-revalidategit clone --depth 1 https://github.com/iliaal/codesageWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00017 | $0.01392 |
| Opus 5 | $0.00009 | $0.00696 |
| Sonnet 5 | $0.00003 | $0.00278 |
| Haiku 4.5 | $0.00002 | $0.00139 |
Grade A, and why
codesage-revalidate scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 82 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Revalidate CodeSage findings
Review the owning feature again, apply the same evidence and identity gates as /codesage-review, and reconcile through codesage-review-state.
Parse and resolve
Require an absolute onboarded project path and exactly one selector:
--finding <id>: locate one finding under$PROJECT/.codesage/findings/*.json.
Every .codesage/... path below lives under the project, not the session's working directory — always write it as $PROJECT/.codesage/....
--feature <id>: select findings in one feature.--all: select across the project, grouped by feature.
--status defaults to open. --max-verify-findings defaults to 5 and caps new regression candidates sent to each feature verifier.
If no findings match, print the selector and available status counts, then stop. Warn before dispatch when the selection spans more than 50 findings or 20 features.
Prepare feature-local inputs
Use rev_$(date -u +%Y%m%dT%H%M%SZ) as RUN_ID. For each feature:
- Read
entry_path,title,kind, andfeature_filesfrom the findings document. For legacy documents missing metadata, callmcp__codesage__list_features(project, limit=200)once and join byfeature_id. - Write the feature record under
$PROJECT/.codesage/reviews/<RUN_ID>/features/. - Project only the targeted findings. Include ID, location, severity, category, title, summary, evidence, suggested fix, and status. Strip
history. Write their ID array to$PROJECT/.codesage/reviews/<RUN_ID>/targets/<feature_id>.json. - Call
mcp__codesage__assess_risk_batchonce for the feature's entry and owned paths. Write the batch-shaped result to$PROJECT/.codesage/reviews/<RUN_ID>/risk/<feature_id>.json. - Compute changed slice paths since
reviewed_at_sha, when present, and union them with the targeted findings' paths. Write the array to$PROJECT/.codesage/reviews/<RUN_ID>/changed/<feature_id>.json. - Run
codesage-review-state plan-featurewith the feature, risk, and changed/target path files, passing--project "$PROJECT"so deleted files drop out of the plan instead of deadlocking coverage. Write$PROJECT/.codesage/reviews/<RUN_ID>/plans/<feature_id>.jsonand pass it to the reviewer asmust_read.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 82 lines · 17 tokens per session scan A 802f1b13a7c8
codesage-revalidate is a command published in the GitHub repository iliaal/codesage (20 stars, last pushed 3d ago), licensed MIT. It adds 17 tokens to every session and 1,392 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
rb-setup
First-time setup. Configure the LLM API key, or a no-API-key local host runner (Codex / Trae / Claude / any headless CLI) that RepoBrain uses for codebase Q&A and refresh. / 首次 setup,配置 RepoBrain 代码问答与 refresh 所需的 LLM API key,或无需 API key 的本地 host runner(Codex / Trae / Claude / 任意无头 CLI)。.
rb-ask
Ask a question about the current project's codebase via the repobrain knowledge hub. / 通过 repobrain 知识库询问当前项目代码。.
rb-refresh
Rebuild the repobrain project knowledge base after significant changes. / 在重要改动后重建 repobrain 项目知识库。.
rb-init
Scaffold a new multi-agent repository from the RepoBrain template (invokes agent-repo-init skill). / 基于 RepoBrain 模板创建新的多智能体仓库。.
rp-build-cli
Build with rp-cli context builder → chat → implement.
rp-investigate-cli
Deep codebase investigation and architecture research with rp-cli commands.