Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/simonrowland/goal-flight/bug-sweepgit clone --depth 1 https://github.com/simonrowland/goal-flightWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/simonrowland/goal-flight/bug-sweep)<a href="https://agentmods.dev/commands/simonrowland/goal-flight/bug-sweep"><img src="https://agentmods.dev/badge/commands/simonrowland/goal-flight/bug-sweep.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00022 | $0.00801 |
| Opus 5 | $0.00011 | $0.00400 |
| Sonnet 5 | $0.00004 | $0.00160 |
| Haiku 4.5 | $0.00002 | $0.00080 |
Grade A, and why
bug-sweep scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 62 lines — stays where its author put it; the contents beside it link to each section on GitHub.
bug-sweep [--mode <milestone|qa|bug-hunt|predicate>] [--anchor ]
Launch a multi-worker bug-sweep over the repo without saturating controller
context. Full procedure: protocols/lane-fill-bug-sweep.md (read it before
running). Complements commands/execute.md (build) and
protocols/review-mining.md (mint/sweep classes).
When: at a milestone, before committing to a new arc, on an overdue review, or to hunt a bug class — when you want many findings fast and trustworthy without spending controller context on typos/noise.
Modes (set the frame + matrix content; same plumbing)
--mode |
Campaign |
|---|---|
milestone (default) |
broad correctness/quality pass when a milestone is due |
qa |
behaviour/UX/regression sweep of the running app |
bug-hunt |
open-ended class discovery; new catches get minted (see review-mining) |
predicate |
hunt under-searched bug-class predicates from the shared sweep-corpus |
Pipeline (see the protocol for detail)
- Frame + matrix — write a shared
audit-frame.txt(protocol, BLOCKING rule keyed to the queued backlog, finding schema) + anaudit-matrix.txtof Ndomain × lensrows underdocs-private/reviews/<date>-<slug>/. Row count = coverage need; lanes only set wall-clock (rows > lanes drain in waves). - Lane-fill audit — one READ-ONLY one-shot worker per row, lane-split by
difficulty (subtle/critical → stronger engine; breadth → cheaper/wider pool).
Findings inline to tails. Launch via the durable queue
(
--submit --drain-on-submit; use--no-drain-on-submitonly when an external drainer owns launch) so workers survive; codex workers: instruct "no context-mode / ctx_ tools"* to avoid the exec-mode wedge. - Harvest — parse the tails into append-only
BUG-LOG.jsonl(read-only workers can't write the sink themselves; this step is mandatory). - Consolidate — one serial worker: dedup → BLOCKING-vs-backlog triage →
rank → systemic clusters →
BUG-LOG-CONSOLIDATED.md; mintSPECULATIVEclass entries while context is loaded. - Adversarial verify — verifiers grouped by chunk, refute-by-default, classify REAL / FALSE-POSITIVE / ALREADY-FIXED / NOT-BLOCKING. Only verified blockers are work. (A suspiciously clean 0-FP means the refute stance was too soft.)
- Fix — routing tiers (A autonomous / B RAG-assisted / C controller-in-loop), disjoint file-set groups, patch-only, serial integrator; worktrees only for Tier-C; poison-pair tests + in-worker falsifier.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 62 lines · 22 tokens per session scan A c49fbee4d81d
bug-sweep is a command published in the GitHub repository simonrowland/goal-flight (20 stars, last pushed yesterday), licensed MIT. It adds 22 tokens to every session and 801 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
review-context7-updates
Please read the @README.md and @docs/tools/package-documentation.md to understand the high level context of my repo.
mine
Quickly capture relevant project context into Memento memory.
help
Show comprehensive Memento help — available MCP tools and usage patterns.
init
Set up Memento — configure MCP server and verify everything works.
search
Search your memories using Memento hybrid retrieval.
status
Show Memento server status and current configuration.