Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/mendixlabs/mxcli/upstream-prgit clone --depth 1 https://github.com/mendixlabs/mxcliWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00017 | $0.00555 |
| Opus 5 | $0.00009 | $0.00278 |
| Sonnet 5 | $0.00003 | $0.00111 |
| Haiku 4.5 | $0.00002 | $0.00056 |
Grade A, and why
upstream-pr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/mxcli-dev:upstream-pr — Link to open a PR into upstream (mendixlabs/mxcli)
Generate a prefilled GitHub compare URL that opens a PR merging this fork
(ako/mxcli) into the upstream fork (mendixlabs/mxcli).
Why a link instead of opening the PR directly: mendixlabs/mxcli is not in
this session's tooling scope, so the PR can't be created via the GitHub API. The
compare URL prefills the title and body; the user opens it and clicks "Create
pull request".
Steps
- Confirm what's actually unmerged upstream. If you have (or can fetch) the
upstream base, build the range explicitly:
If the fetch is blocked or unnecessary, fall back to summarising the fork'sgit fetch https://github.com/mendixlabs/mxcli main git log --no-merges --oneline FETCH_HEAD..HEADmainsince the last sync. - Draft a concise title and a Markdown body grouping the changes by theme (one bullet per finding/fix). Reuse the structure from the last sync PR.
- Generate the link with the script — pass the body on stdin so multi-line
Markdown encodes cleanly:
Or let it auto-build the body from commits:scripts/upstream-pr-link.sh --title "<title>" --body-file - <<'BODY' <markdown body> BODYscripts/upstream-pr-link.sh --commits FETCH_HEAD..HEAD - Present to the user:
- the prefilled compare URL,
- the title and body as plain text (fallback if the browser trims a long prefilled body).
- Remind the user that
mendixlabs/mxcliisn't in scope, so this is a link — offer toadd_repoand open the PR via API if they'd rather.
Notes
- Defaults are
ako/mxcli:main → mendixlabs/mxcli:main. Override with--fork,--upstream,--base,--headfor other syncs. - Do not include the model identifier in the title or body.
- This is a link generator only — it does not push, commit, or open anything.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 52 lines · 17 tokens per session scan A b72fe9ea1561
upstream-pr is a command published in the GitHub repository mendixlabs/mxcli (115 stars, last pushed 2d ago), licensed Apache-2.0. It adds 17 tokens to every session and 555 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
MIGRATE_DESIGN
Design doc for the migration tool PR. Author: Sol ([email protected]). Co-authored-by: wakesync.
plan
Create a structured task-by-task implementation plan for a feature and write it to docs/superpowers/plans/.
toh-help
Display all Toh Framework commands and quick usage guide.
specsmd-construction-agent
Command "specsmd-construction-agent" from fabriqaai/specs.md, covering activate construction agent, activation, parameters, critical first steps and your skills.
fire
FIRE orchestrator - Fast Intent-Run Engineering main entry point.
issue-resolve
Drive an assessed gflow-cli issue (verdict CONFIRMED-BUG or LIKELY-BUG, with localized verifiable scope) to a fix: isolated worktree off develop, test-first fix, /gflow:check, then a DRAFT PR for human review. Mutating and gated — runs inside a strict action envelope (never merges, never spends credits, never marks a…