Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/jcarlosrodicio/opencode-agent-orchestration-kit/autonomousgit clone --depth 1 https://github.com/jcarlosrodicio/opencode-agent-orchestration-kitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/jcarlosrodicio/opencode-agent-orchestration-kit/autonomous)<a href="https://agentmods.dev/commands/jcarlosrodicio/opencode-agent-orchestration-kit/autonomous"><img src="https://agentmods.dev/badge/commands/jcarlosrodicio/opencode-agent-orchestration-kit/autonomous.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00011 | $0.00723 |
| Opus 5 | $0.00005 | $0.00362 |
| Sonnet 5 | $0.00002 | $0.00145 |
| Haiku 4.5 | $0.00001 | $0.00072 |
Grade A, and why
autonomous scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 76 lines — stays where its author put it; the contents beside it link to each section on GitHub.
authorization: explicit_command_invocation execution_scope: local_checkout_only max_iterations_per_invocation: 6 planned_iteration_budget: task_specific_1_to_6 hard_safety_ceiling: 6 completion_authority: reviewer_only canonical_review_policy: code-review-and-quality/references/review-policy.md final_review_authority: reviewer validation_gate: deterministic_per_iteration canonical_state_path: .opencode/loops/.json history_path: .opencode/loops/.history.jsonl lock_path: .opencode/loops/.lock human_view_path: .opencode/loops/.md worktree_mode: prohibited scheduling: prohibited parallelism: prohibited external_writes: prohibited auto_commit_push_merge_deploy: prohibited reviewer_execution: task_subagent_only reviewer_evidence: required_subagent_attestation final_review_attestation: review_stage_verdict_causality_evidence
/autonomous
Use only for one explicitly requested local objective. Read the local rules, Git state, and minimum validation guidance. Stop before writing if protected changes overlap or the task reaches secrets, authorization, payments, PII, migrations, infrastructure, production, or another material decision outside the contract.
Write the Task Contract to .opencode/loops/<slug>.md. Before starting, lead
sets a task-specific planned iteration budget from 1 to 6; six remains a hard
safety ceiling, not a consumption target. If state does not exist, initialize
it with oak state init --root . --planned-iterations <1-6>; otherwise inspect
and resume it. Never delete or reinitialize existing state. An explicit schema
migration requires renewed human approval before oak state resume; do not
reuse earlier approval.
Cycle
developer -> reviewer -> developer (state sync)
For at most the planned iteration budget, developer makes one focused change and runs at
least one relevant deterministic validation. lead invokes reviewer only as
a subagent with task reviewer; never run opencode run --agent reviewer.
Only that child session's final pass or pass_with_observations may complete
the objective. Preserve stage, verdict, causality, and evidence. The state-sync
step translates either successful canonical verdict to the historical runtime
APPROVE attestation through oak state attest-review --root .; oak state record cannot set completed without that
attestation bound to the approved contract.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 76 lines · 11 tokens per session scan A 70663b7d36e3
autonomous is a command published in the GitHub repository jcarlosrodicio/opencode-agent-orchestration-kit (105 stars, last pushed 5d ago), licensed Apache-2.0. It adds 11 tokens to every session and 723 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
prime-pm-role
Prime the PM (project manager) persona for the headless session runner. Receives the user message as $ARGUMENTS.
_prime-rails
These rails apply to every session-runner session (PM, Dev, and Teammate roles). Each role prime instructs you to read and apply this file before acting.
prime-dev-role
Prime the Dev (developer) persona for the headless session runner. No task is present in $ARGUMENTS — the runner will relay the PM's first instruction separately.
prime-teammate-role
Prime the Teammate persona for the headless session runner. Receives the user message as $ARGUMENTS.
update
Bring this machine to latest main — sync deps, verify environment, restart services. Runs deterministically via inline bash execution, not model discretion.
fd-verify
Verify the implementation — run tests, check regression on affect.md files, review and scan; blocks /fd-done on failure.