Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/kumaran-is/claude-code-onboardingWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/kumaran-is/claude-code-onboarding/validate-changes)<a href="https://agentmods.dev/commands/kumaran-is/claude-code-onboarding/validate-changes"><img src="https://agentmods.dev/badge/commands/kumaran-is/claude-code-onboarding/validate-changes.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00042 | $0.00551 |
| Opus 5 | $0.00021 | $0.00275 |
| Sonnet 5 | $0.00008 | $0.00110 |
| Haiku 4.5 | $0.00004 | $0.00055 |
Grade A, and why
validate-changes scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Validate Changes Before Commit
Step 1 — Check staged changes
Run git diff --cached --stat. If nothing is staged, tell the user and stop.
Step 2 — Get the full diff
Run git diff --cached to get the complete diff of all staged changes.
Step 3 — Invoke the evaluator
Use the Agent tool to launch the output-evaluator agent with this prompt:
Evaluate these staged changes for correctness, completeness, and safety.
Return a JSON verdict with scores and issues.
Changes:
[paste the full git diff here]
Step 4 — Parse verdict and act
APPROVE — scores >= 7, no high issues:
- Show scores and summary
- Ask: "Proceed with commit?"
NEEDS_REVIEW — score 5–6 or medium issues:
- Show all issues grouped by severity
- Offer three options:
- Fix issues and re-evaluate
- Commit anyway (acknowledge risks)
- Abort
REJECT — score < 5 or any high-severity issue:
- State the rejection clearly
- Show critical issues
- Do NOT offer to commit anyway
- Suggest specific fixes
Step 5 — Commit (if approved)
If user confirms, create the commit using the conventional commit flow (feat:, fix:, etc.).
Output example
Evaluating 3 staged files...
VERDICT: NEEDS_REVIEW
Scores:
Correctness: 8/10
Completeness: 6/10
Safety: 9/10
Issues:
[MEDIUM] src/api/handler.ts:45
Missing error handling for network failures
[LOW] src/utils/format.ts:12
Consider adding input validation
Suggestion: Add try-catch around the fetch call in handler.ts
How to proceed?
1. Fix and re-evaluate
2. Commit anyway (1 medium issue)
3. Abort
When to use
- After significant code changes before committing
- Changes touching security-sensitive code (auth, tokens, DB)
- Before pushing to a shared branch
When to skip
- Trivial changes: typos, formatting, docs only
- Already manually reviewed thoroughly
- Rapid iteration on a local feature branch
$ARGUMENTS
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 91 lines · 42 tokens per session scan A 2594aeab2776
validate-changes is a command published in the GitHub repository kumaran-is/claude-code-onboarding (35 stars, last pushed 2mo ago), licensed MIT. It adds 42 tokens to every session and 551 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other commands, from other repositories
review-diff
Review the current working diff for correctness, security, and reuse.
elegant-code-review
Review the current working diff against the elegant-code decision ladder and propose deletions, honoring the negligence floor.
git
The pre-finish status: branch, hygiene findings, message checks, workflow lint, template state.
prp-commit
Quick commit with natural language file targeting: describe what to commit in plain English.
fix-comments
Address PR review comments by implementing requested changes automatically.
validate-pr-description
Use when validating a PR title and description for conventional commit format, issue linking keywords, and template compliance before submission.