bob-new

bob-new is a command for coding agents from PounceAI/bob-control. It costs 14 tokens per session (700 once invoked), scanned A, original, Apache-2.0.

A command that turns a rough work request into one structured task for IBM Bob, a task board and worker system.

In plain words
What is it for?
It checks pending tasks for duplicates, then creates a task with a clear description of what must be done and how it should be routed.
Why use it?
It removes the need to manually decide the task title, acceptance conditions, priority, tags, and execution mode.

Command

Part of the bob-companion plugin — 4 skills, 8 commands, 1 agent, 1 MCP server shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/pounceai/bob-control/bob-new
Clone the repo
git clone --depth 1 https://github.com/PounceAI/bob-control

Or install bob-companion, the plugin that ships this one along with the rest of its 4 skills, 8 commands, 1 agent, 1 MCP server.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for bob-new

README.md
[![agentmods](https://agentmods.dev/badge/commands/pounceai/bob-control/bob-new.svg)](https://agentmods.dev/commands/pounceai/bob-control/bob-new)
Your own site
<a href="https://agentmods.dev/commands/pounceai/bob-control/bob-new"><img src="https://agentmods.dev/badge/commands/pounceai/bob-control/bob-new.svg" alt="Measured on agentmods" height="20"></a>
Per session 14 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 700 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00014 $0.00700
Opus 5 $0.00007 $0.00350
Sonnet 5 $0.00003 $0.00140
Haiku 4.5 $0.00001 $0.00070

Measured 5d ago against content hash df886b1466d8, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

bob-new scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

claude-plugin/commands/bob-new.md · 40 lines

What it actually says

You are the foreman for IBM Bob. The user has handed you a rough piece of work; turn it into one clean, well-formed task on the board so Bob can pull and run it.

Rough request:

$ARGUMENTS

Do this:

  1. Check for duplicates first. Call list_tasks (status pending) and skip creating anything that already exists; tell the user if you find a near-match.
  2. Shape the task, then call create_task once with:
    • title — short, action-oriented, imperative (e.g. "Refactor src/db.ts to drop the global handle"). Not a sentence.
    • description — context + concrete acceptance criteria. State what "done" means and any constraints. If the work is read-only, say "Do NOT modify files."
    • prioritylow | medium | high | urgent. Infer from the request; default medium. Use high/urgent only when the user signals it.
    • tags — short labels for filtering, e.g. ['rpg','refactor']. Include a domain tag when obvious (rpg, sql, db, docs).
    • mode — usually omit it and let the dispatcher auto-route. Set it explicitly only when the user is specific. Valid modes and what they mean:
      • ask — read-only (explain / research / review / document). Safe; no writes or commands.
      • code — normal edit + build + run. The default.
      • advanced — adds Browser + MCP power. Use for anything touching a website/URL/scrape/screenshot.
      • orchestrator — coordinating a multi-step epic with sub-tasks.
      • plan / review — read-only: produce a design/plan, or review-findings on a diff. No writes.
      • devsecops — security work (scan + remediate). Standard risk, write-capable.

How routing works (so you can pick tags/wording that route well): the dispatcher resolves the mode as explicit mode › a tag naming a mode › a keyword auto-router over title + description + tags › code. Read-only modes (review/plan/ask) are suppressed when the task carries an implementation verb, so build work is never stranded in a no-write mode. You don't need to reproduce the keyword table — file the task, then read the exact routed mode back from the connector's router with predict_mode.

After creating it, call predict_mode { id: <new id> } and report the new task id, the title, and the routed mode + source (with a one-line "why"). If the request is genuinely several independent pieces of work, say so and suggest delegating to the bob-foreman subagent to split it.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 40 lines · 14 tokens per session scan A df886b1466d8

Subscribe to this mod's changes

bob-new is a command published in the GitHub repository PounceAI/bob-control (1 stars, last pushed 21d ago), licensed Apache-2.0. It adds 14 tokens to every session and 700 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.