Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/kota1026/quantum-shield/codespace-verifygit clone --depth 1 https://github.com/kota1026/quantum-shieldWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00474 |
| Opus 5 | $0.00000 | $0.00237 |
| Sonnet 5 | $0.00000 | $0.00095 |
| Haiku 4.5 | $0.00000 | $0.00047 |
Grade A, and why
codespace-verify scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Codespaces UI確認コマンド
Codespacesで$ARGUMENTSシステムのUIを確認します。
1. Codespaces起動確認
ターミナルで以下を実行:
# サービス起動状態確認
docker ps
# PostgreSQL, Redis, RabbitMQが起動していない場合
cd /workspaces/quantum-shield
docker compose -f docker/docker-compose.dev.yml up -d
# フロントエンド起動
cd /workspaces/quantum-shield/apps/web
pnpm install
pnpm dev
2. ポート確認
Codespaces の「ポート」タブで以下を確認:
- 3000: Next.js フロントエンド ← ここでUI確認
- 5432: PostgreSQL
- 6379: Redis
- 15672: RabbitMQ管理画面
3. UI確認URL
ポート3000を「公開」に設定後、以下のURLでアクセス:
https://{codespace-name}-3000.app.github.dev/ja/consumer/landing
https://{codespace-name}-3000.app.github.dev/ja/consumer/dashboard
https://{codespace-name}-3000.app.github.dev/en/consumer/landing
4. 確認チェックリスト
- ページが404にならない
- Tailwindスタイルが適用されている(背景色、ボタン色)
- 日本語/英語切り替えが動作する
- hinomaru(赤), gold(金)の色が表示される
5. トラブルシューティング
502エラーの場合:
cd /workspaces/quantum-shield/apps/web && pnpm dev
スタイルが適用されない場合:
ls apps/web/postcss.config.js # 存在確認
cat apps/web/postcss.config.js # 内容確認
ポートが表示されない場合:
- Codespaces「ポート」タブ → 「ポートの追加」→ 3000
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 63 lines · 0 tokens per session scan A b34ebd61239d
codespace-verify is a command published in the GitHub repository kota1026/quantum-shield (0 stars, last pushed 4d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 474 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
audit
Full security audit of a Solidity/Vyper/Rust contract or directory. Runs the entire vuln-skills library and dispatches DeFi specialist subagents based on detected protocol type.
audit-deps
Audit third-party dependencies — resolve installed versions, cross-reference known-vulnerable releases, and flag vendored code that has diverged from upstream.
pre-deploy
Interactive pre-launch security checklist — walk the operational and code-safety gates and produce a final GO / NO-GO with each item PASS / FAIL / N-A.
audit-live
Audit a deployed contract on a live chain. Pulls verified source from the block explorer, optionally forks the chain for live-state simulation.
audit-multi-chain
Diff the on-chain configuration of one contract deployed across multiple chains — owner, oracle, fees, timelock, pause state, proxy impl — and flag the chain that drifted.
audit-strict
Multi-pass consensus audit — runs the audit twice with different prompts, only reports consensus findings. Aggressively cuts false positives.