setup

A first-run setup guide for MDDesign, a workflow for documenting and checking software designs. It detects missing dependencies, prints platform-specific installation commands, and verifies each installation.

In plain words
What is it for?
Use it to install or check Node.js tools, the DESIGN.md checker, planning and memory skills, and optional memory-search services.
Why use it?
It replaces guesswork about what must be installed and pauses after each missing dependency so you can complete setup safely. It can be run repeatedly without starting over.

Command for Codex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/othmanadi/mddesign/setup
Clone the repo
git clone --depth 1 https://github.com/OthmanAdi/MDDesign

Made for: Codex.

Per session 37 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,631 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 2 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00037 $0.01631
Opus 5 $0.00018 $0.00816
Sonnet 5 $0.00007 $0.00326
Haiku 4.5 $0.00004 $0.00163

Measured 2d ago against content hash 75896c902a90, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade C, and why

setup scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

grep -q '"mempalace"' "$HOME/.claude/settings.json" 2>/dev/null && echo "configured" || echo "MISSING"

Enumerates other installed skillsmediumAgent snooping

Other skills' SKILL.md files reveal prompts, capabilities and secrets that should be invisible to peers.

ls "$HOME/.claude/skills/planning-with-files/SKILL.md" 2>/dev/null \
.codex/commands/setup.md · 195 lines

How it starts

The opening of the file, as written. The whole thing — 195 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/mddesign:setup

First-run setup. Detects what is missing on this machine and walks the user through installing it. Idempotent — safe to run any time.

What I check, in order

Dependency Required What it gives you
node + npx required DESIGN.md linter (Google's @google/design.md)
@google/design.md required structural validation for harvest and critique
planning-with-files skill required task_plan.md / findings.md / progress.md
code-memory-router skill optional but recommended three-tier memory routing (scratch / WHERE / WHY)
MemPalace MCP optional persistent WHY-tier decisions
QMD MCP optional WHERE-tier code/doc search

Flow

For each dependency, run the detection probe. If missing, print a one-paragraph install block tailored to the user's platform (Windows / macOS / Linux). After printing the install block, stop and wait for the user to say "done" or "skip" before moving to the next dependency.

Step 1: Node + npx

command -v node && command -v npx

If absent:

Node is not on PATH.

Install Node.js LTS from https://nodejs.org. On Windows: download the Windows Installer (.msi). On macOS: brew install node. On Linux: use your distro's package manager or nvm.

After installing, restart your terminal and run /mddesign:setup again.

Step 2: @google/design.md

npx --yes @google/design.md lint --help 2>&1 | head -1

If empty or error: nothing to install per se (npx fetches on demand). Verify cache works by:

mkdir -p /tmp/mddesign-probe && cd /tmp/mddesign-probe && cat > DESIGN.md <<'EOF'
---
version: alpha
name: Probe
colors:
  primary: '#000000'
typography:
  body:
    fontFamily: Inter
    fontSize: 16px
    fontWeight: 400
    lineHeight: 1.5
rounded:
  md: 8px
spacing:
  md: 16px
components:
  button:
    backgroundColor: '{colors.primary}'
---
# Probe
## Overview
test
## Colors
test
## Typography
test
## Layout
test
## Elevation & Depth
test
## Shapes
test
## Components
test
## Do's and Don'ts
test
EOF
npx --yes @google/design.md lint DESIGN.md
echo "EXIT: $?"

Read the full file on GitHub · 195 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 195 lines · 37 tokens per session scan C 75896c902a90

Subscribe to this mod's changes

setup is a command published in the GitHub repository OthmanAdi/MDDesign (13 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 37 tokens to every session and 1,631 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it C with 2 findings (reads agent configuration directories, enumerates other installed skills). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.