Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/ogrodev/fsociety/ty-forumsgit clone --depth 1 https://github.com/ogrodev/fsocietyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/ogrodev/fsociety/ty-forums)<a href="https://agentmods.dev/commands/ogrodev/fsociety/ty-forums"><img src="https://agentmods.dev/badge/commands/ogrodev/fsociety/ty-forums.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00009 | $0.00744 |
| Opus 5 | $0.00005 | $0.00372 |
| Sonnet 5 | $0.00002 | $0.00149 |
| Haiku 4.5 | $0.00001 | $0.00074 |
Grade A, and why
ty-forums scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -s -A "Mozilla/5.0" -H "Cookie: ${FORUM_SESSION_COOKIE}" \ How it starts
The opening of the file, as written. The whole thing — 85 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are executing a breach forum search for the tyrell data exfiltration plugin.
Step 1 — Profile Gate Check
Before proceeding, verify that the active operational profile meets the minimum access tier:
node "${CLAUDE_PLUGIN_ROOT}/scripts/hunt-engine.js" forum --check-profile $ARGUMENTS
If the profile is surface or light, stop immediately and inform the operator:
Forum hunting requires a deep or higher operational profile. Switch profiles before continuing.
Proceed only if the profile is deep, dark, or ghost.
Step 2 — Generate Forum Search Queries
Run the hunt engine to produce optimized forum search queries:
node "${CLAUDE_PLUGIN_ROOT}/scripts/hunt-engine.js" forum $ARGUMENTS
The script returns a list of query objects with fields: forum, query, keywords, and thread_patterns. Common forums include RaidForums archives, BreachForums, Exploit.in, XSS.is, and dedicated leak channels.
Step 3 — Execute Forum Searches
For each forum and query combination, search via available tooling:
- Via MCP web search: Submit targeted queries with site-specific operators (e.g.,
site:forum-url "<keyword>"). - Via direct HTTP (if forum is accessible on clearnet):
curl -s -A "Mozilla/5.0" -H "Cookie: ${FORUM_SESSION_COOKIE}" \ "https://<forum>/search?q=<query>" | grep -oP '(?<=href=")[^"]+thread[^"]+' - Record thread URLs, post dates, post authors, and any attached sample files or torrent links.
Step 4 — Extract Leak Metadata
For each promising thread or post found, extract structured metadata:
- Target organization: Which entity's data is being sold or shared
- Record count: How many records (if stated)
- Data fields: What columns are included (emails, passwords, PII, financial)
- Date of breach: When the breach occurred (vs. when it was posted)
- Price or access requirement: Free, paid, traded, or escrow
- Sample availability: Whether a sample is posted for verification
- Seller reputation: Forum post count, vouches, verified tags
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 85 lines · 9 tokens per session scan A 5576636f02bd
ty-forums is a command published in the GitHub repository ogrodev/fsociety (20 stars, last pushed 5mo ago), licensed MIT. It adds 9 tokens to every session and 744 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other commands, from other repositories
better-auth:setup
Interactive setup wizard for better-auth authentication. Guides through database, framework, OAuth providers, and plugin configuration.
v-memory-refresh
(Re)index docs/superpowers prose into the local V-memory cache so recall is current. Incremental by file hash; runs fully offline (FTS5, pure stdlib). Optionally enable the semantic lane with a one-time bootstrap. Run it after pulling new docs, or when /v:remember looks stale.
symfony-migrations
Create and manage Doctrine migrations for database schema changes.
pentest
Activate pentest mode — displays ASCII art, configures session isolation, collects engagement scope, then OWNS the engagement: pre-flight, recon, planning (via the pentester-orchestrator planner), executor dispatch, a time-budget quota loop, aggregation, and report generation.
pentest-attacks
Define the attack profile for an engagement — select which attack categories and skills to use. Saves to .pentest-attacks.json. If run before /pentest:pentest, the orchestrator will respect the selection. If run standalone, does not launch a pentest.
pentest-scope
Define or update engagement scope — saves scope to disk without launching a pentest. Can be run before or during an engagement. If a pentest is active and the target changes drastically, warns the operator and suggests a new engagement.