Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/jonase47/ccpr/gate-p2git clone --depth 1 https://github.com/jonase47/ccprWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.02014 |
| Opus 5 | $0.00000 | $0.01007 |
| Sonnet 5 | $0.00000 | $0.00403 |
| Haiku 4.5 | $0.00000 | $0.00201 |
Grade A, and why
gate-p2 scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 143 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/gate-p2 – Quality Gate 2: Validation → Architecture
Checks whether all critical Assumptions have been validated and a well-founded Go/No-Go/Pivot Decision can be made. This is the most important gate in the model – here it is decided whether to invest in the cost- and time-intensive architecture and implementation phase. No argument – this gate always checks the complete checklist.
No Argument ($ARGUMENTS not applicable)
Gate commands do not accept arguments. They always check the complete current project status.
Execution
1. Read Preflight Report
Read docs/.gate-preflight-p2.md as the primary source of information. This report contains:
- Artefact existence and mandatory sections (mechanically checked)
- Content check (regex-based: risk assessments, validation status, results, PoC)
- Document summaries (via Ollama, if available)
If the preflight report does not exist or is older than 10 minutes, read the validation documents directly instead — always start with the phase index:
docs/validation/VALIDATION.md(phase index) — gives you the detail-file table, key decisions, open risks.- From the index's detail-file table, load only the detail files you need:
docs/validation/ASSUMPTIONS.md(register with validation status)docs/validation/MARKET_VALIDATION.mddocs/validation/POC.md(pluspoc/code directory if relevant)docs/validation/REGULATORY_CHECK.md
- P1 reference (only when validation findings impact concept/financials):
docs/concept/CONCEPT.md(index), thenBUSINESS_MODEL.md/FINANCIAL_PLAN.md/DSGVO_INITIAL_ASSESSMENT.mdselectively.
1a. Constitution Inviolables (mandatory pre-gate)
If docs/CONSTITUTION.md exists, the preflight report (docs/.gate-preflight-p2.md) includes a section "Constitution Inviolables (Required Read)" with the project's non-negotiable rules.
These Inviolables are mandatory input for the gate:
- Include the Inviolable bullets verbatim in the agent prompt (Step 2 below).
- The agent must check each evaluated phase-decision against the Inviolables.
- Any violation is an "Inviolable breach" — surface it explicitly in the verdict and treat it as a No-Go signal (Conditional Go only if the user explicitly waives; document the waiver).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 143 lines · 0 tokens per session scan A 387e7ba0d096
gate-p2 is a command published in the GitHub repository jonase47/ccpr (1 stars, last pushed yesterday), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 2,014 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
drift
Post-implementation spec drift check — verify the implementation matches existing OpenSpec specifications.
feature
Orchestrate a complete feature through discovery, spec, implementation, and review.
research
Research a technical or product question.
tidy
Consistency check for non-code repos with INDEX.md hierarchy. Verifies INDEX.md accuracy, MEMORY.md references, orphaned files, stale dates, and WAITING markers.
clean-check
Analyze code for cleanliness issues (unused code, comment quality, formatting, naming, complexity). Delegates to the code-cleanliness agent.
build
Mini spec-first development workflow for well-scoped implementation tasks with human in the loop.