Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/navraj007in/architecture-cowork-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/navraj007in/architecture-cowork-plugin/launch-check)<a href="https://agentmods.dev/commands/navraj007in/architecture-cowork-plugin/launch-check"><img src="https://agentmods.dev/badge/commands/navraj007in/architecture-cowork-plugin/launch-check/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/navraj007in/architecture-cowork-plugin/launch-check"><img src="https://agentmods.dev/badge/commands/navraj007in/architecture-cowork-plugin/launch-check.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00011 | $0.01342 |
| Opus 5 | $0.00005 | $0.00671 |
| Sonnet 5 | $0.00002 | $0.00268 |
| Haiku 4.5 | $0.00001 | $0.00134 |
Grade A, and why
launch-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 132 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/architect:launch-check
Trigger
/architect:launch-check
Purpose
Runs a 10-point file-system readiness checklist against the project to score it on launch-readiness. No AI calls — all checks are purely file-system based. Also runs a 9-point production hardening sub-check.
Checklist (10 points)
| # | Check | How it's verified |
|---|---|---|
| 1 | Tests present | tests/, __tests__/, or npm test script exists |
| 2 | Health check endpoint | Any file containing "health" in path or name |
| 3 | Environment variables complete | .env.example vars all set in .env |
| 4 | Monitoring / error tracking | Sentry, Datadog, or similar in package.json / requirements.txt |
| 5 | Security headers | helmet, cors, or security middleware in deps |
| 6 | README.md | README.md exists at project root |
| 7 | Dockerfile | Dockerfile exists at project root |
| 8 | CI/CD pipeline | .github/workflows/, .gitlab-ci.yml, or Jenkinsfile exists |
| 9 | Database migrations | migrations/ or prisma/migrations/ directory exists |
| 10 | API specification | openapi.yaml, swagger.yaml, or equivalent in architecture-output/ |
Production Hardening Sub-Check (9 patterns)
Run all 9 production hardening pattern checks against the project's backend entry point and source files:
| # | Pattern | How it's verified |
|---|---|---|
| 1 | Security headers (helmet/CORS) | helmet and cors middleware present in backend deps and applied in entry point |
| 2 | Health check endpoint | Route file or handler containing "health" exists in backend |
| 3 | Correlation ID propagation | x-correlation-id middleware exists in backend entry point and API client forwards the header |
| 4 | Graceful shutdown | SIGTERM/SIGINT handlers exist in backend entry point with server.close() |
| 5 | Structured logging | A logging library (pino, winston, serilog, zerolog) is present and console.log is absent from production code paths |
| 6 | Auth token interceptor | Frontend API client has Bearer token injection, 401 retry, and redirect on refresh failure |
| 7 | Rate limiting | Rate limiting middleware is applied to API routes |
| 8 | Input validation | Zod/Joi/FluentValidation schemas are applied to request body/params/query before handlers |
| 9 | Retry + timeout | Outbound HTTP calls use AbortController timeout and exponential backoff retry |
| 10 | Soft delete | ORM models have deletedAt field and transparent query filter middleware |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 132 lines · 11 tokens per session scan A f9f1bd3cb09d
launch-check is a command published in the GitHub repository navraj007in/architecture-cowork-plugin (2 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 11 tokens to every session and 1,342 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
nyann:retrofit
Audit an existing repo against a profile and fix what's drifted. Unlike doctor (read-only), retrofit detects missing hooks, misconfigured gitignore, documentation gaps, and non-compliant history, then offers to remediate via bootstrap. Idempotent — safe to re-run.
nyann:apply
Apply an Infrastructure-as-Code change — the highest-stakes mutator in nyann; it can change real cloud infrastructure. Re-runs the plan, shows it, confirms, then applies. Unmistakably opt-in: apply is never the default and destructive applies require a second explicit confirm. For IaC apply intent only (not "apply a…
nyann:hotfix
Create the branch topology for a patch release against a previously tagged version. Ensures release/ . exists from the source tag, then creates hotfix/ off it. After this, the user commits the fix and runs /nyann:release from the hotfix branch.
nyann:release
Cut a release: generate a CHANGELOG section from Conventional Commits, make a release commit, and create an annotated tag. Defaults to conventional-changelog strategy.
nyann:ship
Open a GitHub pull request AND merge it in one step. Default uses GitHub's native auto-merge (returns immediately with outcome:"queued"); --client-side polls for green CI in the foreground then runs gh pr merge. Requires gh installed + authed.
nyann:cleanup-branches
Prune local branches whose work is already merged into the base. Lists candidates first, then applies on --yes. Mirrors the safe-delete semantics of git branch -d (lowercase d): nothing unmerged is touched.