Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/punt-labs/z-spec/audit-devgit clone --depth 1 https://github.com/punt-labs/z-specWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00007 | $0.02511 |
| Opus 5 | $0.00003 | $0.01256 |
| Sonnet 5 | $0.00001 | $0.00502 |
| Haiku 4.5 | $0.00001 | $0.00251 |
Grade A, and why
audit-dev scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- audit — 89% identical, 12 lines differ
How it starts
The opening of the file, as written. The whole thing — 285 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/z-spec-dev:audit-dev - Test Coverage Audit
Audit unit test coverage against constraints defined in a Z specification. Extracts invariants, preconditions, effects, and bounds from the spec, then searches the test suite for coverage.
Input
Arguments: $ARGUMENTS
Parse arguments:
- First positional argument: Z specification file (default: search
docs/*.tex) --json: Output JSON instead of markdown table--test-dir=DIR: Override test directory detection
Process
0. Prerequisites
This command does not require fuzz or probcli. It reads existing Z specifications and searches test files using pattern matching. The specification should already exist (created via /z-spec-dev:code2model-dev).
1. Locate the Specification
If a file path is provided, use it directly.
If no file specified:
- Look in
docs/for.texfiles containing Z specifications - If multiple found, ask user to specify
Read the specification file.
2. Detect Language and Test Directory
If --test-dir specified, use it.
Otherwise, auto-detect from project files:
| Indicator | Language | Test Directory Pattern |
|---|---|---|
Package.swift, *.xcodeproj, project.yml |
Swift | *Tests/ |
package.json, tsconfig.json |
TypeScript | __tests__/, *.test.ts, *.spec.ts |
pyproject.toml, setup.py, requirements.txt |
Python | tests/, test_*.py, *_test.py |
build.gradle.kts, pom.xml |
Kotlin | src/test/ |
Use Glob to find test files matching the detected pattern.
3. Extract Constraints from Z Specification
Parse the specification and extract constraints into 4 categories:
Category 1: Schema Invariants
Location: \where clauses in state schemas (non-operation schemas without \Delta or \Xi)
Examples:
\begin{schema}{State}
level : \nat
\where
level \geq 1 \\
level \leq 26
\end{schema}
Extracts: level >= 1, level <= 26
Category 2: Operation Preconditions
Location: Predicates in operation schemas (\Delta or \Xi) that reference only unprimed state variables and inputs.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 285 lines · 7 tokens per session scan A ee4bc93aef85
audit-dev is a command published in the GitHub repository punt-labs/z-spec (5 stars, last pushed 3d ago), licensed MIT. It adds 7 tokens to every session and 2,511 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
meeting-listen
Play back a completed meeting summary as a voiced debate between personas.
meeting-hive
Run an autonomous PR/FAQ review meeting where four personas debate and reach consensus without user intervention.
vote
Assess whether a PR/FAQ should move forward with a structured go/no-go decision.
feedback
Incorporate feedback into PR/FAQ and redraft affected sections.
feedback-to-us
Tell us how the prfaq plugin is working for you (anonymous 1-5 feedback).
badge
Generate a stage-colored badge and embed it in your README.