Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/medadembha/docflow/scangit clone --depth 1 https://github.com/MedAdemBHA/docflowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00016 | $0.00466 |
| Opus 5 | $0.00008 | $0.00233 |
| Sonnet 5 | $0.00003 | $0.00093 |
| Haiku 4.5 | $0.00002 | $0.00047 |
Grade A, and why
scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Turn the actual codebase into doc drafts (not blank templates). Two generators; the draft is then verified + trimmed by you.
Spec from a module
bash "${CLAUDE_PLUGIN_ROOT}/scripts/docflow-spec.sh" <code-path> --target "$CLAUDE_PROJECT_DIR" --docs-root <DOCS_ROOT>
Scans the path → writes <DOCS_ROOT>/specs/(mmm-yy)-<name>.md pre-filled with: source file list, exported symbols (Architecture), interfaces/types/enums (Data), string paths + HTTP verbs (API), hooks/state (Flow). Add --stdout to preview without writing. Won't overwrite an existing spec.
After generating: verify the auto lists, group exports into the real component/service map, confirm which paths are real endpoints, and fill the Risks section (heuristics can't infer it).
Plan candidates from repo signal
bash "${CLAUDE_PLUGIN_ROOT}/scripts/docflow-plan.sh" --target "$CLAUDE_PROJECT_DIR" --docs-root <DOCS_ROOT> --days 30
Scans TODO/FIXME/HACK/XXX markers + git churn (last N days) → writes <DOCS_ROOT>/plans/upcoming/(mmm-yy)-candidates.md. It will not overwrite an existing candidates file unless --force is passed. Set SCAN_DIR=src to limit scope.
After generating: triage each candidate into critical/now/next/later.md, then delete the candidates file. Markers in high-churn areas → likely critical/now.
Rules
- These produce drafts. Never ship an unverified auto-spec — the agent/dev curates first.
- Re-run after big code changes to refresh the discovered surface.
- Regenerate
INDEX.mdafterward:bash "${CLAUDE_PLUGIN_ROOT}/scripts/docflow-map.sh" "$CLAUDE_PROJECT_DIR/<DOCS_ROOT>". - Validate before reporting completion:
bash "${CLAUDE_PLUGIN_ROOT}/scripts/docflow-validate.sh" --target "$CLAUDE_PROJECT_DIR".
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 28 lines · 16 tokens per session scan A 7ce3a6c6e06b
scan is a command published in the GitHub repository MedAdemBHA/docflow (41 stars, last pushed 17d ago), licensed MIT. It adds 16 tokens to every session and 466 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
search
Search OpenDocu local versioned official docs using explicit library keywords.
review-renovate
Review and merge renovate PRs with automerge configuration updates.
monitor-ci
Monitors pull request CI checks until they are resolved (pass or fail).
/add-claude-rule
Appends the rule from $ARGUMENTS to CLAUDE.md.
implement-regression-tests
Implement regression tests marked with it.skip.
plan-regression-tests
Plan regression tests for existing code with it.skip statements.