Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/naimkatiman/continuous-improvement/verify-installgit clone --depth 1 https://github.com/naimkatiman/continuous-improvementWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/naimkatiman/continuous-improvement/verify-install)<a href="https://agentmods.dev/commands/naimkatiman/continuous-improvement/verify-install"><img src="https://agentmods.dev/badge/commands/naimkatiman/continuous-improvement/verify-install.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00044 | $0.00627 |
| Opus 5 | $0.00022 | $0.00313 |
| Sonnet 5 | $0.00009 | $0.00125 |
| Haiku 4.5 | $0.00004 | $0.00063 |
Grade A, and why
verify-install scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 56 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/verify-install
Replaces the manual post-install dance (restart, run /discipline, hand-write a
hostile prompt, eyeball /dashboard) with one command that runs all three
checks and reports a single line.
Run the three checks in order. Do not skip a check because an earlier one passed — each proves a different layer.
Check 1 — slash commands loaded
If this command is executing, the marketplace did pick the plugin up and the
command registry loaded it. Record commands: ✓.
If you are reading this file directly rather than running it as /verify-install,
stop — the command is not registered. The fix is a Claude Code session restart
(slash commands load on session start). Record commands: ✗ (restart the session).
Check 2 — gateguard runtime hook fires
The runtime gate ships as a PreToolUse hook (hooks/gateguard.mjs). Probe it:
attempt to Write a throwaway file at a sandbox path (./.ci-verify-install-probe.txt
with the text probe) without presenting any research first.
- If the hook blocks the write with a fact-list reason — the runtime layer is
wired. Record
gateguard: ✓. Do not retry the write; the block is the pass. - If the write goes through with no pause — the hook did not load. Record
gateguard: ✗ (hooks/gateguard.mjs not wired — see README → Troubleshooting install). Delete the probe file if it was created.
Check 3 — observation capture recording
The observation hook appends one row per tool call to
~/.claude/instincts/<project-hash>/observations.jsonl. Read that file (resolve
<project-hash> from the current repo, or check ~/.claude/instincts/global/).
- If it exists and has at least one row — capture is recording. Record
observe: ✓. - If it is missing or empty, record
observe: ✗ (observation hook not recording; re-run the installer to migrate legacy Bash hook rows to the Node observer).
Report
Emit exactly one summary line, nothing else after it:
- All three passed:
✓ wired — commands, gateguard, observe all confirmed. - Any failed:
✗ <comma-separated failing checks with their fix hints>.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 56 lines · 44 tokens per session scan A de2b672fc611
verify-install is a command published in the GitHub repository naimkatiman/continuous-improvement (7 stars, last pushed 8d ago), licensed MIT. It adds 44 tokens to every session and 627 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
battlecard
Create a sales-ready competitive battlecard — positioning, feature comparison, objection handling, and win strategies.
release
Generate changelog, bump version, and create git tag.
generate-report
Generate a professional HTML report from assessment results in the conversation.
analyze-and-create-issue
Analyze codebase and create GitHub/GitLab/Forgejo issues per finding.
review
Cold re-quiz on code that already shipped — your own session commits, not the change in front of you.
privacy
Draft a jurisdiction-aware privacy policy for a digital product.