Getting it into your agent
There is no command for this one: it runs only inside a plugin, and the catalogue could not identify which plugin ships it. The source is linked below.
Wrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/marcosd4h/deepextractruntime/ai-logical-bug-scan)<a href="https://agentmods.dev/commands/marcosd4h/deepextractruntime/ai-logical-bug-scan"><img src="https://agentmods.dev/badge/commands/marcosd4h/deepextractruntime/ai-logical-bug-scan.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.04491 |
| Opus 5 | $0.00000 | $0.02246 |
| Sonnet 5 | $0.00000 | $0.00898 |
| Haiku 4.5 | $0.00000 | $0.00449 |
Grade A, and why
ai-logical-bug-scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- memory-scan — 86% identical, 123 lines differ
How it starts
The opening of the file, as written. The whole thing — 436 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AI Logical Bug Scan
Overview
AI-driven scan for logic vulnerabilities: authentication/authorization bypass, state machine errors, confused deputy, privilege escalation, missing impersonation revert, and sensitive API parameter injection.
Uses LLM agents that navigate cross-module callgraphs, read decompiled code on demand, and verify findings against assembly ground truth. All vulnerability detection decisions are made by LLM agents, not pattern matching.
Usage:
/ai-logical-bug-scan <module>-- scan top entry points for the module/ai-logical-bug-scan <module> <function>-- scan from a specific function/ai-logical-bug-scan <module> <function> --depth 3-- limit callgraph depth
IMPORTANT: Execution Model
This command executes immediately. Run the full pipeline and deliver the completed report without pausing for confirmation. Use the workspace handoff pattern for all phases.
Status Messaging (MANDATORY)
Keep the user informed at every phase boundary. Output a plain-text status message before each phase starts and after it completes. Messages are 1-2 lines summarizing what is happening and what the phase produced. Do NOT suppress status messages to "save time."
Execution Context
IMPORTANT: Script invocations like
python .claude/skills/.../script.pyrun from the workspace root. The scripts manage their own path setup.
Step 0: Preflight Validation
from helpers.command_validation import validate_command_args
result = validate_command_args("ai-logical-bug-scan", {
"module": "<user_module>",
"function": "<user_function_or_None>",
})
if not result.ok:
# report errors and stop
db_path = result.resolved["db_path"]
Workspace Protocol
Create .claude/workspace/<module>_logicscan_<function_or_all>_<timestamp>/ and
pass --workspace-dir and --workspace-step to all skill scripts.
Subagent Compliance Checklist (MANDATORY)
Before proceeding past each phase, verify the following. Violations invalidate the scan.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 436 lines · 0 tokens per session scan A 08a8d3c10c5e
ai-logical-bug-scan is a command published in the GitHub repository marcosd4h/DeepExtractRuntime (19 stars, last pushed 4mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 4,491 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
step-research
Always research before proposing a fix. The Untether bug you're chasing is often a known upstream engine quirk, a previously-fixed regression, or a documented config gotcha.
iterate-feature
Iterate on the feature "$ARGUMENTS" to fix issues and address feedback.
qa-changes
This skill should be used when the user asks to "QA a pull request", "test PR changes", "verify a PR works", "functionally test changes", or when an automated workflow triggers QA validation of code changes. Provides a structured methodology for setting up the environment, exercising changed behavior, and reporting…
doctor
Diagnosticar y reparar problemas del framework Don Cheli, git y entorno. Usa cuando el usuario dice "doctor", "problemas del framework", "don cheli no funciona", "repair Don Cheli", "debug setup", "setup broken", "framework broken", "reparar entorno". Detecta y repara issues de configuración, git y dependencias…
fix
Universal debugging and fix application with semantic code analysis.
doctor.es
Diagnostica problemas de inferencia LLM en Mac: asiai doctor verifica el estado de los motores, conflictos de puertos, carga de modelos y estado de la GPU.