Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/mmyslin/sideboard/roadmapgit clone --depth 1 https://github.com/mmyslin/sideboardWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00010 | $0.00293 |
| Opus 5 | $0.00005 | $0.00147 |
| Sonnet 5 | $0.00002 | $0.00059 |
| Haiku 4.5 | $0.00001 | $0.00029 |
Grade B, and why
roadmap scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
1. Run `cat ~/.claude/sideboard-token 2>/dev/null` (Bash) to read the board's What it actually says
Open my Sideboard roadmap board. The router is already running on :7777.
-
Run
cat ~/.claude/sideboard-token 2>/dev/null(Bash) to read the board's auth token. Build the board url: if you got a token, usehttp://127.0.0.1:7777/roadmap-board.html?token=<TOKEN>(substituting the value); if the file was empty or missing, use the url without?token=. -
Call navigate with that url to reuse the existing pane tab. ONLY if navigate errors that no preview/pane is open, call preview_start once with that same url.
-
Take ONE screenshot to confirm the board rendered — you should see the PROJECT header and the Backlog / In Progress / Done columns. If the pane is blank, or the board is collapsed into a short strip at the top with empty space below it, call navigate to the same url once more so the pane re-measures, then take one more screenshot.
-
Reply with ONE short line (e.g. "Board's up.") and STOP. Do nothing beyond steps 1-3 — no page reading, no further navigation.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 24 lines · 10 tokens per session scan B 97b2bb091402
roadmap is a command published in the GitHub repository mmyslin/sideboard (2 stars, last pushed 13d ago), licensed MIT. It adds 10 tokens to every session and 293 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
pm-all
Full technical governance scan; rebuild .pm/dashboard. Default does not wait on draft PRD. Use --compare-baseline only after a confirmed PRD/charter.
pm-outline
Generate detailed project outline and draft charter from user intent (empty/new projects).
pm-charter
Create, import, discover, approve, or skip project charter. No-arg form is an interactive wizard.
pm-docs
Detect missing/stale core docs; dual-mode fill (user upload or AI draft under .pm/docs/drafts). Confirm before writing official paths.
pm-next
Claim the single next governance todo (marks inprogress).
_closing
会改 .pm/ 的 /pm- 回复必须有一句中文摘要。链接只列已经存在的文件,不要指向还没生成的路径。.