Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/john-farina/claude-plugins/conjure-hookgit clone --depth 1 https://github.com/john-farina/claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/john-farina/claude-plugins/conjure-hook)<a href="https://agentmods.dev/commands/john-farina/claude-plugins/conjure-hook"><img src="https://agentmods.dev/badge/commands/john-farina/claude-plugins/conjure-hook.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00032 | $0.03864 |
| Opus 5 | $0.00016 | $0.01932 |
| Sonnet 5 | $0.00006 | $0.00773 |
| Haiku 4.5 | $0.00003 | $0.00386 |
Grade B, and why
conjure-hook scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
cat ~/.claude/conjure-config.md 2>/dev/null How it starts
The opening of the file, as written. The whole thing — 375 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Phase 0: Route the Request
Before building anything, verify a hook is the right artifact.
| Question | If YES → use instead |
|---|---|
Does the user trigger this explicitly via /command? |
Skill → run /conjure-skill <name> |
| Does Claude spawn this with isolated context or a different model? | Agent → run /conjure-agent <description> |
| Should this fire automatically on an event without the user asking? | Hook → continue ✅ |
Common mislabels:
| Request sounds like… | Actually is… |
|---|---|
| "hook to commit my changes" | Skill — user-triggered |
| "hook to search the codebase" | Agent — isolated, spawned by Claude |
| "hook that fires whenever I edit a file" | Hook ✅ |
| "hook that runs on session start" | Hook ✅ |
| "hook to review my PR" | Skill — user-triggered workflow |
If it's clearly a skill or agent, stop and say: "This is better as a [skill/agent] — run /conjure-skill or /conjure-agent instead."
Phase 0.5: Load User Preferences
Before doing anything else, read both conjure config files if they exist:
cat ~/.claude/conjure-config.md 2>/dev/null
cat .claude/conjure-config.md 2>/dev/null
Follow all instructions found in ## hooks and ## global sections throughout every phase of this command. Project-local instructions (.claude/conjure-config.md) take precedence over global ones when they conflict. If neither file exists, proceed with defaults.
Phase 1: Parse Arguments + Detect Mode
Parse $ARGUMENTS:
| Pattern | Mode |
|---|---|
| empty | Create — ask what the hook should do |
| description only (no slug) | Create — use description as intent |
<slug> only, found in settings.json |
Update — read entry + script, refine |
<slug> only, not found |
Create — use slug as intended name |
<slug> review |
Review — audit script + settings entry, report issues |
<slug> add-event |
Extend — add a new event to an existing hook's script |
help |
Stop and print the Phase 1 argument table above, then stop |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 375 lines · 32 tokens per session scan B 68eec6a9c194
conjure-hook is a command published in the GitHub repository john-farina/claude-plugins (1 stars, last pushed 3mo ago), licensed MIT. It adds 32 tokens to every session and 3,864 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
sm-sail
Command "sm-sail" from ScienceIsNeato/slop-mop, covering /sm-sail — drive a pr to green, autonomously, the loop, when sail parks on review threads, when to stop before "pr ready" — only two reasons and expect convergence, not one pass.
sm-buff
You usually don't run buff directly — run sm sail. sm sail drives the whole PR to green and calls buff watch / triage for you, stopping only when it needs you to act (see /sm-sail). Reach for sm buff here only for surgical work: inspecting a specific failure, or resolving a single review thread when sail has parked on…
sm-wake-angry-drunk-captain
The last-resort verb. Use it ONLY when the loop is genuinely exhausted: barnacles filed, gates green or truly unfixable, and the single remaining move is a human judgment call no sm verb can make for you.
sm-barnacle
Use when sm itself gives invalid guidance, blocks valid work, produces confusing output, or breaks install/upgrade/refit flow. Do not use this for real target-repo failures; fix those through the normal rail.
sm-init
Run when you find a repo with sm installed but no .sbconfig.json — or after upgrading slopmop to pick up new gates.
sm-refit
Run slop-mop's one-time onboarding remediation rail for this repository.