Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/shuxueshuxue/gugu-docsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/shuxueshuxue/gugu-docs/spec)<a href="https://agentmods.dev/commands/shuxueshuxue/gugu-docs/spec"><img src="https://agentmods.dev/badge/commands/shuxueshuxue/gugu-docs/spec/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/shuxueshuxue/gugu-docs/spec"><img src="https://agentmods.dev/badge/commands/shuxueshuxue/gugu-docs/spec.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00493 |
| Opus 5 | $0.00000 | $0.00246 |
| Sonnet 5 | $0.00000 | $0.00099 |
| Haiku 4.5 | $0.00000 | $0.00049 |
Grade A, and why
spec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
commands
The invocable command plugins live here: leaf plugins whose body is a prompt preset a human can pick
from the / dropdown while launching or driving a session, each carrying surface: command. Grouping them keeps .plugins/ legible at
a glance — the command presets on this shelf, the skill plugins on [[skills]], the auxiliary system
contracts on [[prompts]], with [[core]] (the dev-flow contract subsystem) a flat child beside them.
Invocation belongs to the backend prompt boundary, not to whichever client happens to render the picker.
Every compose surface sends the raw /<preset> [[node]]… <free text> prompt; the shared resolver expands the
live surface: command body before either launch starts a worker or dispatch sends text to one. At
launch, the raw invocation remains the session's originating prompt and identity source, so links inside a
plugin body can never invent a node target. Dashboard and phone menus are therefore discovery/insertion
chrome, while dashboard, phone, CLI, API, and in-process fallback all invoke through the same backend
resolution. A preset with {{targets}} always receives the resolved target block; one without that placeholder
gets a target block only when the invocation actually names a target, so a targetless utility remains a small
prompt. An unknown leading /name stays ordinary prompt text and is never swallowed or guessed.
This node is a shelf, not a surface (the [[prompts]] shape): it declares no surface field and
gathers nothing itself. Discovery is recursive and field-driven (surface), so a resident plugs in
exactly as it would at the root — the gather set is path-independent, so shelving a command changes
nothing about what /api/plugins and the launcher offer. A plugin that serves BOTH surfaces (e.g.
[[distill]], skill and command) shelves once by its primary identity, never duplicated. The init
templates mirror this layout. The shelf stays pure presentation: moving a resident beneath it changes
neither that plugin's identity nor the surfaces gathered from its frontmatter.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 31 lines · 0 tokens per session scan A 3261a387634a
spec is a command published in the GitHub repository shuxueshuxue/gugu-docs (2 stars, last pushed 15d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 493 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
specify
Create or update the feature specification from a natural language feature description.
analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
converge
Assess the current codebase against the feature's spec, plan, and tasks, then append any remaining unbuilt work as new tasks to tasks.md so implement can complete it.
implement
Execute the implementation plan by processing and executing all tasks defined in tasks.md.