Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/pealmeida/anymodel-plugin/delegategit clone --depth 1 https://github.com/pealmeida/anymodel-pluginWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00016 | $0.01072 |
| Opus 5 | $0.00008 | $0.00536 |
| Sonnet 5 | $0.00003 | $0.00214 |
| Haiku 4.5 | $0.00002 | $0.00107 |
Grade A, and why
delegate scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 53 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Invoke the anymodel:anymodel-runner subagent via the Agent tool (subagent_type: "anymodel:anymodel-runner"), forwarding the raw user request as the prompt.
anymodel:anymodel-runner is a subagent, not a skill — do not call Skill(anymodel:anymodel-runner) (no such skill) or Skill(anymodel:delegate) (that re-enters this command and hangs the session). The command runs inline so the Agent tool stays in scope; forked general-purpose subagents do not expose it.
The final user-visible response must be the engine's output verbatim.
Raw user request: $ARGUMENTS
Flag reference (these are runtime-selection flags — preserve them for the forwarded delegate call, do not treat them as part of the natural-language task text):
--engine codex|claude— selects the executor harness.codexruns the task throughcodex app-server;clauderuns it throughclaude -p --output-format stream-json. Default is the configured default engine (see/anymodel:setup).--model <provider/model>— selects what the harness thinks with. Provider prefixes supported by the registry:zai/(Z.AI GLM models),ollama/(Ollama Cloud gpt-oss / qwen3-coder / minimax),opencode-go/(glm / kimi / qwen / deepseek). When omitted, the engine's default model is used. Aliases (e.g.spark) resolve via config.--bridge builtin|litellm— selects how non-native providers are translated to the engine's wire format.builtinuses the built-in shim (no external dependency);litellmproxies through a LiteLLM bridge instance. Default isbuiltin.--write— grants the engine write access to the workspace sandbox (read-only is the default unless the engine has a real sandbox and--writeis passed). Never default--writeon engines without real sandboxing.
Execution mode:
- If the request includes
--background, run theanymodel:anymodel-runnersubagent in the background. - If the request includes
--wait, run theanymodel:anymodel-runnersubagent in the foreground. - If neither flag is present, default to foreground.
--backgroundand--waitare execution flags for Claude Code. Do not forward them as part of the natural-language task text.- If the request includes
--resume, do not ask whether to continue. The user already chose. - If the request includes
--fresh, do not ask whether to continue. The user already chose. - Otherwise, before starting the engine, check for a resumable thread from this Claude session by running:
node "${CLAUDE_PLUGIN_ROOT}/scripts/companion.mjs" delegate --resume-candidate --json
- If that helper reports
available: true, useAskUserQuestionexactly once to ask whether to continue the current engine thread or start a new one. - The two choices must be:
Continue current engine threadStart a new engine thread
- If the user is clearly giving a follow-up instruction such as "continue", "keep going", "resume", "apply the top fix", or "dig deeper", put
Continue current engine thread (Recommended)first. - Otherwise put
Start a new engine thread (Recommended)first. - If the user chooses continue, add
--resumebefore routing to the subagent. - If the user chooses a new thread, add
--freshbefore routing to the subagent. - If the helper reports
available: false, do not ask. Route normally.
Operating rules:
- The subagent is a thin forwarder only. It makes exactly one
Bashcall to invokenode "${CLAUDE_PLUGIN_ROOT}/scripts/companion.mjs" delegate ...and returns that command's stdout as-is. - Return the companion stdout verbatim to the user.
- Do not paraphrase, summarize, rewrite, or add commentary before or after it.
- Do not ask the subagent to inspect files, monitor progress, poll
/anymodel:status, fetch/anymodel:result, call/anymodel:cancel, summarize output, or do follow-up work of its own. - If the helper reports that the engine is missing or unauthenticated, stop and tell the user to run
/anymodel:setup. - If the user did not supply a request, ask what the engine should investigate or fix.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 53 lines · 16 tokens per session scan A 03120a1f8c02
delegate is a command published in the GitHub repository pealmeida/anymodel-plugin (0 stars, last pushed 24d ago), licensed Apache-2.0. It adds 16 tokens to every session and 1,072 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
step-research
Always research before proposing a fix. The Untether bug you're chasing is often a known upstream engine quirk, a previously-fixed regression, or a documented config gotcha.
/release
Release a new version — updates CHANGELOG, pyproject.toml, creates git tag, and pushes.
warden-cost
Dollar accounting — what does each active rule actually save, in money? Translates the token-measured verdict into dollars using a price table and the agent's own token-type mix, with a per-session net and a break-even. Read-only; spends no tokens.
setup-team
Set up River Review in the current project: create .river/rules.md, confirm plugin install, and check integration mode.
checkpoint
Works for you. Go outside and live. — AI orchestrator that auto-routes tasks to the cheapest model that solves them. 70% run free on local models. Self-auditing, self-improving, zero prompting skill needed. Built with vibe coding by a finance student. Your models, your data.
weekly-review
Works for you. Go outside and live. — AI orchestrator that auto-routes tasks to the cheapest model that solves them. 70% run free on local models. Self-auditing, self-improving, zero prompting skill needed. Built with vibe coding by a finance student. Your models, your data.