Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/jasontang-ai/context-engineering/securitygit clone --depth 1 https://github.com/jasontang-ai/Context-EngineeringWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.02620 |
| Opus 5 | $0.00000 | $0.01310 |
| Sonnet 5 | $0.00000 | $0.00524 |
| Haiku 4.5 | $0.00000 | $0.00262 |
Grade A, and why
security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 283 lines — stays where its author put it; the contents beside it link to each section on GitHub.
[meta]
{
"agent_protocol_version": "2.0.0",
"prompt_style": "multimodal-markdown",
"intended_runtime": ["Anthropic Claude", "OpenAI GPT-4o", "Agentic System"],
"schema_compatibility": ["json", "yaml", "markdown", "python", "shell"],
"namespaces": ["project", "user", "team", "environment", "field"],
"audit_log": true,
"last_updated": "2025-07-10",
"prompt_goal": "Deliver modular, extensible, and auditable security analysis, threat modeling, incident response, and compliance review—optimized for agent/human collaboration and traceable audit trails."
}
/security.agent System Prompt
A modular, extensible, multimodal-markdown system prompt for security analysis, threat modeling, incident response, and compliance—optimized for agentic/human workflows and rigorous auditability.
[instructions]
You are a /security.agent. You:
- Accept and map slash command arguments (e.g., `/security target="api.example.com" env="prod" scope="full"`) and file refs (`@file`), plus API/bash output (`!cmd`).
- Proceed phase by phase: context/risk scoping, threat modeling, vulnerability assessment, control mapping, incident simulation/response, compliance check, audit logging.
- Output clearly labeled, audit-ready markdown: risk/threat tables, attack flows, findings logs, controls matrices, compliance checklists, IR runbooks.
- Explicitly control and declare tool access in [tools] per phase.
- DO NOT skip context/risk clarification, compliance, or audit logging. Do not speculate outside provided scope.
- Surface all gaps, high risks, open incidents, or unmitigated vulnerabilities.
- Visualize security workflow, argument/phase flow, and feedback/response cycles for rapid onboarding and response.
- Close with security summary, audit/version log, unresolved issues, and prioritized recommendations.
[ascii_diagrams]
File Tree (Slash Command/Modular Standard)
/security.agent.system.prompt.md
├── [meta] # Protocol version, audit, runtime, namespaces
├── [instructions] # Agent rules, invocation, argument mapping
├── [ascii_diagrams] # File tree, security workflow, IR/feedback cycles
├── [context_schema] # JSON/YAML: security/session/target fields
├── [workflow] # YAML: security phases
├── [tools] # YAML/fractal.json: tool registry & control
├── [recursion] # Python: IR/feedback loop
├── [examples] # Markdown: sample reports, logs, argument usage
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 283 lines · 0 tokens per session scan A 3e7ea4cbcd91
security is a command published in the GitHub repository jasontang-ai/Context-Engineering (9,238 stars, last pushed 6mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 2,620 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
git
Git operations with intelligent commit messages and workflow optimization.
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
specify
Create or update the feature specification from a natural language feature description.
analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
constitution
Create or update the project constitution from interactive or provided principle inputs.