Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/olo-dot-io/uni-cli/phase-reviewgit clone --depth 1 https://github.com/olo-dot-io/Uni-CLIWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00466 |
| Opus 5 | $0.00000 | $0.00233 |
| Sonnet 5 | $0.00000 | $0.00093 |
| Haiku 4.5 | $0.00000 | $0.00047 |
Grade A, and why
phase-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/phase-review — cross-phase review before merge
Review a phase's worktree against the spec before merging into main.
Usage
/phase-review <phase-number>
Example: /phase-review 8 reviews Phase 8 output.
What it does
- Locates the phase's branch/worktree from
.claude/plans/sessions/. - Reads the spec section from
FINAL.md. - Runs
git log --oneline main..HEADto see all commits on the branch. - Runs
git diff main...HEAD --statfor a file-level summary. - For each deliverable in the spec, checks whether a matching commit exists and whether the expected files are present.
- Runs
npm run verifyone last time. - Returns one of:
DONE— every deliverable present, verify green.DONE_WITH_CONCERNS— all deliverables present, but something non-blocking is off (test count lower than promised, skipped tests without comments, etc.).NEEDS_CONTEXT— cannot verify against spec (missing FINAL.md, ambiguous deliverable).BLOCKED— a deliverable is missing or verify fails.
Ground rules
- Never approve a phase that claims files exist when they do not.
- Never approve a phase where
npm run verifyfailed locally. - Trust the spec, not the implementer's summary.
- Show evidence: commit SHAs, file paths, test count deltas.
Output shape
Phase N review: <DONE | DONE_WITH_CONCERNS | NEEDS_CONTEXT | BLOCKED>
Commits: <count> (SHAs: abc1234, def5678, ...)
Files touched: <count> (<adds> additions, <dels> deletions)
Test delta: +<n> new tests
Verify: <green | red with first error>
Deliverables:
8.1 [✓] Changesets + verify-changesets gate
8.2 [✓] OIDC npm publish + --provenance
...
Concerns: <none | bulleted list>
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 56 lines · 0 tokens per session scan A 089408ebea50
phase-review is a command published in the GitHub repository olo-dot-io/Uni-CLI (270 stars, last pushed 12d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 466 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
toon
A lightweight data format designed to minimize token usage when passing structured data to LLMs.
qa
Dispatch a verifiable browser task to the qa-tester subagent. Use for regression checks, smoke tests, and any task with a clean pass/fail outcome. Supports an EXHAUSTIVE mode that verifies every control behind an honesty gate.
feedback
File a plugin-capability-gap note, or flush queued notes to GitHub issues.
telemetry
Inspect, opt in/out of, and audit mochi's anonymous usage telemetry.
insights
Owner-only — fetch and print the mochi-insight server's aggregate summary.
render
Inspect an archived transcript (gzipped) — show counts, tool calls, errors. Useful after a PreCompact or SessionEnd, before deciding to write a retroactive /continuum:checkpoint.