Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/randomittin/heimdall/report-buggit clone --depth 1 https://github.com/randomittin/heimdallWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00084 | $0.00961 |
| Opus 5 | $0.00042 | $0.00481 |
| Sonnet 5 | $0.00017 | $0.00192 |
| Haiku 4.5 | $0.00008 | $0.00096 |
Grade A, and why
report-bug scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 96 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/hmd:report-bug — File an Issue Against the Heimdall Plugin
Use when the user wants to report a bug, request a feature, or flag a docs problem in the Heimdall plugin itself (NOT in the project they're working on).
Process
-
Classify the report from the user's description:
bug— something in Heimdall is broken or behaves wrongfeature— a new capability they wantdocs— wrong/missing/confusing docs or help textquestion— they want clarification (last resort — try answering first)enhancement— improvement to existing behavior
If unclear, ask one clarifying question. Do NOT spam questions.
-
Gather details — pull from the conversation and (if relevant) recent tool output:
- What were they trying to do?
- What did Heimdall do instead?
- Reproduction steps (concrete commands or actions)
- Stack trace / error output (verbatim, in a fenced code block)
- Expected behavior
-
Compose the body as Markdown. Use this template:
## Summary <one or two sentences> ## Steps to reproduce 1. ... 2. ... ## Expected behavior <what should have happened> ## Actual behavior <what did happen, with error output verbatim> ## Additional context <any relevant details — only include if non-trivial>Write the body to a temp file (e.g.
/tmp/heimdall-issue-body-$$.md). -
Compose a tight title — under 70 chars, imperative or descriptive. Examples:
bug: parallelism-tracker fails on linux-musl (no fcntl.h)feature: add /hmd:rollback to revert last wavedocs: agents/coder.md doesn't mention isolation: worktree
-
Invoke the helper:
"${CLAUDE_PLUGIN_ROOT}/bin/report-issue" \ --title "<title>" \ --body-file "/tmp/heimdall-issue-body-$$.md" \ --kind <bug|feature|docs|question|enhancement>The helper auto-prepends an
## Environmentblock with plugin SHA, OS, kernel, recent commits, and dirty cwd files. Do NOT duplicate that in your body — keep your body focused on the user's report.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 96 lines · 84 tokens per session scan A 1e34d9650393
report-bug is a command published in the GitHub repository randomittin/heimdall (5 stars, last pushed 11d ago), licensed MIT. It adds 84 tokens to every session and 961 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
autocode
Fully autonomous development pipeline. Give it a feature description or PRD file and it will plan, write tests, implement code, run tests, and verify — all automatically with zero human intervention.
autocode-new
Scan current project and generate a project-specific autocode development pipeline (agents, commands, rules, hooks). Interactive setup wizard.
dispatcher
Pick the next-best repo to work on across the portfolio — rank free repos, recommend one, claim its lease atomically, and route to the entry command.
standup
Show a daily standup summary with completed, in-progress, and blocked tasks across all active epics.
dev-planner
Generate or update DEV-PLAN.md with phased development plan from Product-Spec.md.
iterate
Iteration delivery — delivery check + archive + commit & tag + bump version.