Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/omermaksutii/rugproof/provergit clone --depth 1 https://github.com/omermaksutii/RugProofWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/omermaksutii/rugproof/prover)<a href="https://agentmods.dev/commands/omermaksutii/rugproof/prover"><img src="https://agentmods.dev/badge/commands/omermaksutii/rugproof/prover.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00034 | $0.00952 |
| Opus 5 | $0.00017 | $0.00476 |
| Sonnet 5 | $0.00007 | $0.00190 |
| Haiku 4.5 | $0.00003 | $0.00095 |
Grade A, and why
prover scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 86 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/prover — prove it, don't just fuzz it
Fuzzing samples inputs; formal verification proves a property over all inputs (or returns a concrete counter-example). This command defaults to Halmos — symbolic execution that runs offline against your existing Foundry tests — and falls back to Certora (CVL spec) when configured.
Procedure
Step 1 — Pick the property
$ARGUMENTS is [contract] [property]. If no property is named, propose from the templates by protocol type below. Each maps to a check_ test function.
ERC-20 — supply conservation / no inflation
function check_transfer_preservesSupply(address to, uint256 amt) public {
uint256 pre = token.totalSupply();
token.transfer(to, amt);
assert(token.totalSupply() == pre); // no mint/burn on transfer
}
AMM — constant-product K monotonicity
reserve0 * reserve1after a fee-paying swap is>=before. [[flash-loan-attacks]].
Access control — only-owner can call X
function check_setFee_onlyOwner(address caller, uint16 bps) public {
vm.assume(caller != owner);
vm.prank(caller);
try vault.setFee(bps) { assert(false); } catch { } // must revert
}
No-reentrancy invariant — a guarded function cannot be re-entered (assert the guard slot is set during the external call).
Solvency — sum(balances) <= totalAssets holds after any single state transition.
Step 2 — Run Halmos
halmos --function check_transfer_preservesSupply --solver-timeout-assertion 0
Or via the runner MCP so it shares the Foundry build:
mcp__forge-runner__symbolic(tool="halmos", function="check_setFee_onlyOwner")
Step 3 — Interpret the result
- PASS = a proof. The property holds for every input within the explored bounds. State the bounds explicitly (e.g. "all
uint256 amt, loop unrolled to 3"). - COUNTEREXAMPLE = a concrete input that violates the property → this is a finding. Minimize it and write a
/exploitPoC. - TIMEOUT / path explosion = inconclusive, not a pass. Narrow scope (bound array lengths,
--loopunroll limit, constrain inputs withvm.assume) and re-run.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 86 lines · 34 tokens per session scan A 54fa844a2186
prover is a command published in the GitHub repository omermaksutii/RugProof (9 stars, last pushed 1mo ago), licensed MIT. It adds 34 tokens to every session and 952 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
phase6-start
Command "phase6-start" from kota1026/quantum-shield, covering phase 6 $arguments 開始, step 1: 進捗状況を確認, step 2: 未完了画面を特定, step 3: 必須ファイルを読み込む and step 4: インフラ確認.
codespace-verify
Command "codespace-verify" from kota1026/quantum-shield, covering codespaces ui確認コマンド, 1. codespaces起動確認, サービス起動状態確認, postgresql, redis, rabbitmqが起動していない場合 and フロントエンド起動.
pr-merge
Command "pr-merge" from kota1026/quantum-shield, covering pr作成・マージコマンド, 1. 変更確認, 2. コミット(未コミットがある場合), 3. pr作成 and 4. マージ.
krait
Run a complete multi-phase security audit on the target codebase.
krait-fuzz
Run an invariant-based fuzzing campaign: Understand → Extract Invariants → Generate Foundry Tests → Run & Fix Iteratively → Report.
dashboard
Open the ChainGPT marketplace dashboard (localhost web UI — Overview, Skills, Activity, Health, About).