Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/kastalien-research/thoughtbox/indexgit clone --depth 1 https://github.com/Kastalien-Research/thoughtboxWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/kastalien-research/thoughtbox/index)<a href="https://agentmods.dev/commands/kastalien-research/thoughtbox/index"><img src="https://agentmods.dev/badge/commands/kastalien-research/thoughtbox/index.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01202 |
| Opus 5 | $0.00000 | $0.00601 |
| Sonnet 5 | $0.00000 | $0.00240 |
| Haiku 4.5 | $0.00000 | $0.00120 |
Grade A, and why
index scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 159 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Hypothesis-Driven Development (HDD)
Commands for working with the hypothesis-driven development workflow where ADRs are the source of truth, not code.
Core Principle
Code is an implementation artifact. ADRs (Architecture Decision Records) are the source of truth.
Available Commands
Core Workflow
overview
Complete explanation of the hypothesis-driven development approach, workflow phases, and philosophy.
quick-reference
Quick command reference and cheat sheet for the HDD workflow.
Session Management
init
Initialize a new HDD session by creating local workflow state and linking the user-selected tracker only when one is explicitly in scope.
state
State management, checkpoints, and phase transitions.
Phase Commands
research
Phase 1: Research existing ADRs, rejected approaches, and form hypotheses.
stage-adr
Phase 2: Create staging ADR with context, decision, hypotheses, and validation criteria.
validate
Phase 4: Validate hypotheses through automated testing and required manual user testing.
decide
Phase 5: Make accept/reject decision based on validation results and migrate ADRs.
Router + Modules
hddis a thin orchestrator router.- Focused phase modules live in
./modules/. - State contract:
./state.md
Workflow Summary
Research → 🚦 → Stage ADR → 🚦 → Implement → Validate+Manual → 🚦 → Accept/Reject
↓ User ↓ User ↓ Testing User ↓
docs/adr Approve staging/ Approve Code + Confirm docs/adr
rejected docs/adr Tests or rejected/
🚦 = Required User Approval Checkpoint
User interaction is required at EVERY phase:
- After Research - Approve hypotheses
- After Staging ADR - Approve implementation plan
- During Validation - Perform manual testing
- Before Decision - Confirm accept/reject
- Before Rejection - Approve rejection (if applicable)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 159 lines · 0 tokens per session scan A 57aa900d6242
index is a command published in the GitHub repository Kastalien-Research/thoughtbox (64 stars, last pushed 1mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,202 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other commands, from other repositories
validate-prd
Validate an existing PRD against BMAD standards - comprehensive review for completeness, clarity, and quality.
editorial-review-structure
Structural editor that proposes cuts, reorganization, and simplification while preserving comprehension.
add-tool
Scaffold a new FreeAgent MCP tool (handler + registration + test) following the repo pattern.
OPSX: Archive
Archive a completed change in the experimental workflow.
audit-web
请使用 anjian MCP 工具处理这个网站安全评估请求:$ARGUMENTS.
data-mesh-contract
Create federated data product contracts for mesh architectures with SLAs, governance, and interoperability guarantees (project).