Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/jonase47/ccpr/gate-p6-securitygit clone --depth 1 https://github.com/jonase47/ccprWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01005 |
| Opus 5 | $0.00000 | $0.00502 |
| Sonnet 5 | $0.00000 | $0.00201 |
| Haiku 4.5 | $0.00000 | $0.00101 |
Grade A, and why
gate-p6-security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 79 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/gate-p6-security – Security Approval Evaluation
Evaluates all security-relevant points of the Gate-P6 checklist and grants Security approval.
Argument: $ARGUMENTS = not applicable
Gate commands accept no arguments.
Prerequisites
docs/quality/QA.md(phase index) existsdocs/quality/AUDIT.md(sub-index) and its detail files (audit_auth.md,audit_config.md,audit_deps.md,audit_dsgvo.md,audit_sast.md)docs/quality/PENTEST.md(sub-index) and its detail files (pentest_recon.md,pentest_auth.md,pentest_authz.md,pentest_injection.md,pentest_logic.md)docs/architecture/SECURITY.md(P3 sub-index) as reference for the security architecturedocs/concept/DSGVO_INITIAL_ASSESSMENT.md(P1 detail file) as compliance benchmark
Agent
- Type: security-master
- Model: opus
Pre-Flight
If docs/.gate-preflight-p6.md exists and is less than 10 minutes old, read it as a starting point. Mechanical checks (file existence, sections) are already done – focus on content evaluation.
Context (Orchestrator prepares)
Read the phase and sub-indexes first, then load detail files only when their status row signals an open issue:
- From
docs/quality/QA.md: status, key decisions, open risks (entry point) - From
docs/quality/AUDIT.md(sub-index): row status of eachaudit_*.md - From
docs/quality/PENTEST.md(sub-index): row status of eachpentest_*.md - From
docs/architecture/SECURITY.md: P3 threat model summary (key decisions, open risks) - From
docs/concept/DSGVO_INITIAL_ASSESSMENT.md: DSGVO requirements (short list) - Detail files (
audit_dsgvo.md,pentest_authz.md, ...) only when a sub-index row isneeds-reworkor has an open Critical risk
Prompt Template
Goal: Security approval evaluation for Gate P6.
Security Reports: [inline summaries]
Output Format:
Checklist (max. 6 points): | # | Check Point | Status | Justification | Status: Met / Partial / Not Met
Security Approval:
- Approved / Conditional Approval / Not Approved
- Justification (2–3 sentences)
- Conditions (if conditional, as numbered list)
Constraints:
- Security evaluation ONLY, NO QA evaluation
- Evaluation based exclusively on available reports
- No approval if critical or high security findings are open
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 79 lines · 0 tokens per session scan A 591fdd11ee44
gate-p6-security is a command published in the GitHub repository jonase47/ccpr (1 stars, last pushed yesterday), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,005 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
drift
Post-implementation spec drift check — verify the implementation matches existing OpenSpec specifications.
feature
Orchestrate a complete feature through discovery, spec, implementation, and review.
research
Research a technical or product question.
tidy
Consistency check for non-code repos with INDEX.md hierarchy. Verifies INDEX.md accuracy, MEMORY.md references, orphaned files, stale dates, and WAITING markers.
clean-check
Analyze code for cleanliness issues (unused code, comment quality, formatting, naming, complexity). Delegates to the code-cleanliness agent.
build
Mini spec-first development workflow for well-scoped implementation tasks with human in the loop.