init

A command for creating or reviewing Claude Code configuration in a repository. It uses the project's detected technology stack to guide repository-specific rules and skills.

In plain words
What is it for?
Initializing missing .claude configuration, auditing existing setup, and force-updating generated repository rules when explicitly requested.
Why use it?
It helps keep coding-agent instructions organized and suited to the project. Audit mode can identify improvements without replacing existing configuration.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/rileyhilliard/agentrc/init
Clone the repo
git clone --depth 1 https://github.com/rileyhilliard/agentrc
Per session 9 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 3,643 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00009 $0.03643
Opus 5 $0.00005 $0.01821
Sonnet 5 $0.00002 $0.00729
Haiku 4.5 $0.00001 $0.00364

Measured yesterday against content hash 513f6dfa9512, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

init scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Recursive force deletemediumDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

"Bash(rm -rf /)",

Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.

.agentrc/commands/init.md · 612 lines

How it starts

The opening of the file, as written. The whole thing — 612 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Initialize or audit .claude/ configuration for this repository based on detected stack.

Arguments:

  • $ARGUMENTS: Optional flags
    • --audit: Only analyze existing config, report improvements
    • --force: Overwrite existing files without confirmation

Mode Detection

  1. Check if .claude/ directory exists
  2. If exists AND no --force: Run Audit Mode
  3. If not exists OR --force: Run Fresh Init Mode

Progressive Disclosure Principles

Generated rules and skills follow progressive disclosure to minimize token usage while maintaining depth:

Three-layer approach:

  1. Metadata (scanned first) - Name and description only
  2. Main file (loaded if selected) - Concise patterns, under 500 lines
  3. Reference files (loaded on-demand) - Deep details in references/ subdirectory

Key rules:

  • Main files point to reference files, never duplicate content
  • References are always one level deep (no nested references)
  • Reference files include a table of contents for partial reads
  • Rules reference ce:* skills rather than duplicating skill content

When to use references/:

  • Domain-specific schemas or configurations
  • Extensive code examples for different scenarios
  • API documentation that varies by context
  • Style guides with multiple personas

Example structure:

rules/
├── testing.md                    # Points to ce:writing-tests skill
└── api/
    ├── conventions.md            # Main file, ~100 lines
    └── references/
        ├── error-codes.md        # Loaded when handling errors
        └── pagination.md         # Loaded when implementing pagination

skills/
└── my-project-connector/
    ├── SKILL.md                  # Main instructions, <500 lines
    └── references/
        ├── auth-flows.md         # OAuth, API key, etc.
        └── rate-limiting.md      # Retry strategies

Fresh Init Mode

Step 1: Detect Stack

Check for manifest files in the repository root:

File Stack Test Framework
pyproject.toml or requirements.txt Python pytest
package.json Node.js/TypeScript vitest, jest
Cargo.toml Rust cargo test
go.mod Go go test
pom.xml or build.gradle Java/Kotlin JUnit
Gemfile Ruby RSpec

Read the full file on GitHub · 612 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 612 lines · 9 tokens per session scan B 513f6dfa9512

Subscribe to this mod's changes

init is a command published in the GitHub repository rileyhilliard/agentrc (3 stars, last pushed 6mo ago), licensed MIT. It adds 9 tokens to every session and 3,643 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it B with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.