Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/nel-neru/libraium/refresh-metadatagit clone --depth 1 https://github.com/nel-neru/LibrAIumWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00021 | $0.00379 |
| Opus 5 | $0.00010 | $0.00189 |
| Sonnet 5 | $0.00004 | $0.00076 |
| Haiku 4.5 | $0.00002 | $0.00038 |
Grade A, and why
refresh-metadata scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Refresh the library's GitHub metadata for: $ARGUMENTS (empty = the whole library).
-
Token first — 43+ API calls must not run anonymously (60 req/h limit):
export GITHUB_TOKEN=$(gh auth token) -
Dry-run and review (never start with
--write):node scripts/refresh-metadata.mjs $ARGUMENTSWalk the user through the digest: star drift,
STATUStransitions (active -> stale= candidate for succession via suggest alternatives), upstream renames (manual: follow the rename rules in/add-entry— the file must move because slug = slugify(full_name)), and fetch errors. -
Demo-stale seed note.
ai-agent/openai-swarmis seeded stale to showcase the GUI's stale badge and alternative suggestions. The test suite does NOT depend on it (stale scenarios run on the checked-in fixture inmcp-server/test/fixtures/stale-lib/), so writing the flip is safe — just tell the user the GUI showcase loses its stale example until some entry goes stale for real. -
Apply only what the user approves:
node scripts/refresh-metadata.mjs $ARGUMENTS --writeThe script re-runs validate-data itself. Show
git diff --stat data/— only scalar frontmatter lines may change (flow-styletags: [...]lines must be untouched). Leave the commit to the user unless they ask.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 31 lines · 21 tokens per session scan A e7fc7ebff2f4
refresh-metadata is a command published in the GitHub repository nel-neru/LibrAIum (0 stars, last pushed 5d ago), licensed MIT. It adds 21 tokens to every session and 379 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
implement-issue
Command "implement-issue" from outfitter-dev/blz, covering implement linear issue, context, important, preparation and workflow sequence.
review
Comprehensive code review for blz changes.
blz
Search, retrieve, and manage documentation with BLZ.
cli
Instructions: $ARGUMENTS.
docs
Instructions: $ARGUMENTS.
reset_project
Wipe the per-project memory cache for the active project when it was re-cloned from the same path.