Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/niels-emmer/myace/verifygit clone --depth 1 https://github.com/niels-emmer/myaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/niels-emmer/myace/verify)<a href="https://agentmods.dev/commands/niels-emmer/myace/verify"><img src="https://agentmods.dev/badge/commands/niels-emmer/myace/verify.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00040 | $0.00439 |
| Opus 5 | $0.00020 | $0.00219 |
| Sonnet 5 | $0.00008 | $0.00088 |
| Haiku 4.5 | $0.00004 | $0.00044 |
Grade A, and why
verify scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
- Run
plan/validate, format/lint, and policy-as-code checks and confirm an actual pass — quote the real output, don't summarize a run you didn't just do. - Read the plan output and confirm it matches the intended change — no resources created or destroyed that the task didn't ask for.
- Confirm the change added or updated tests that cover it (pipeline unit tests, deployment integration/smoke tests), checked against the
test-patternsskill's checklist — not just that some test somewhere still passes. - Run the linter and type checker; both must be clean. A warning that's routinely ignored project-wide is a judgment call to note explicitly, not to silently pass over.
- If the change touches identity, secrets, network exposure, data, images, or dependencies, run it through the
devsecops-checklistskill and resolve every FAIL before continuing — don't defer a blocking finding to "a follow-up." - If the change includes a state migration or a change to a shared/critical path, confirm the rollback path has actually been exercised, not just written.
- Confirm documentation and runbooks — README, AGENTS.md-style rule files, inline comments describing now-stale behavior — have been updated to match the change, in this same change set.
- Append the decision-log entry per the
memory-systemskill: what was decided, how it was tested (point at the specific runs from steps 1-4), and which docs were touched. - Only report the change as done once every applicable step above is actually true — not once the code compiles, and not once "most of it" is finished.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 15 lines · 40 tokens per session scan A 653e6b999063
verify is a command published in the GitHub repository niels-emmer/myace (1 stars, last pushed 4d ago), licensed MIT. It adds 40 tokens to every session and 439 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other commands, from other repositories
brainstorm
已弃用 - 请改用 superpowers:brainstorming 技能.
arckit.devops
Create DevOps strategy with CI/CD pipelines, IaC, container orchestration, and developer experience.
fix
Apply a single safe quick win from DESIGN.md.critique.md. HITL gated. Re-lints DESIGN.md after every edit; reverts if lint regresses.
compose
One-shot wiring check for MDDesign. Verifies planning-with-files, DESIGN.md, code-memory-router, and Google linter are all reachable. Surfaces any missing piece with a one-line fix-it. Read-only.
gha
Analyze GitHub Actions CI failures.
zeus-install-traefik
Zeus: GitOps-flavored Traefik install/upgrade — edits common.traefik/ Kustomize; never runs helm directly.