Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/skullninja/coco-workflow/executegit clone --depth 1 https://github.com/skullninja/coco-workflowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00028 | $0.03397 |
| Opus 5 | $0.00014 | $0.01699 |
| Sonnet 5 | $0.00006 | $0.00679 |
| Haiku 4.5 | $0.00003 | $0.00340 |
Grade A, and why
execute scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 393 lines — stays where its author put it; the contents beside it link to each section on GitHub.
User Input
$ARGUMENTS
You MUST consider the user input before proceeding (if not empty).
Setup
- Read
.coco/config.yamlfor project configuration (includingprsection). - Determine the active epic (from
$ARGUMENTSor most recent open epic). - Determine the feature branch:
- If on a
feature/*branch, that is the feature branch - Otherwise, read
feature_branchfrom the first task's metadata in the epic
- If on a
Pre-Execution Gate (MANDATORY)
Before starting the execution loop, verify the epic was imported correctly:
coco-tracker epic-status {epic-id}
Check ALL before writing any code:
- Tracker tasks exist with correct dependencies
- If issue tracker configured: every task has
issue_keyin metadata - Commit message issue keys are real -- keys must reference actual issues
- If
pr.enabled: verify on afeature/*branch and remote origin is configured
If any check fails, STOP and use the import skill first.
Execution Loop
1. Find Next Task
coco-tracker ready --json --epic {epic-id}
Never manually pick tasks -- always use ready which respects dependency order.
2. Claim Task
coco-tracker update {task-id} --status in_progress
3. Create Issue Branch
If pr.enabled is false: skip this step.
Read issue_key from task metadata. Determine branch name:
- If
pr.branch.issue_branch_namingis"issue_key": use{issue_key}(e.g.,AUTH-3) - If
"task_id": use the tracker task ID (e.g.,epic-001.3) - Normalize: lowercase, replace spaces with hyphens
git checkout -b "{feature-branch}/{issue_key}"
4. Bridge to Issue Tracker (Start)
Read issue_key from task metadata. Based on issue_tracker.provider in config:
If "linear": Update issue to status_map.in_progress using mcp__plugin_linear_linear__update_issue
If "github":
- If
github.use_projectsis true and task hasgh_project_item_idin metadata: Read.coco/state/gh-projects.jsonand find the feature entry whereproject_numbermatches the task'sgh_project_numbermetadata. Extractproject_id,status_field_id, andstatus_optionsfrom that entry. Then:gh project item-edit --project-id {project_id} --id {gh_project_item_id} --field-id {status_field_id} --single-select-option-id {status_options[status_map.in_progress]} - Otherwise (legacy fallback):
gh issue edit {issue_number} --add-label "{status_map.in_progress from config, lowercase with hyphens}"(label must exist in repo)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 393 lines · 28 tokens per session scan A 8df7f092e13a
execute is a command published in the GitHub repository skullninja/coco-workflow (7 stars, last pushed yesterday), licensed MIT. It adds 28 tokens to every session and 3,397 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
interactive-planning
File-based planning with interactive gates + native task tracking. Supports task-based (single plan file) and spec-driven (multi-file specs with manifest) modes. Phase/Sprint/Spec hierarchy with dependency DAG.
set-tracker
Set the issue tracker for the current project.
maggy-init
Interactive wizard that configures Maggy for the user's org, issue tracker, and codebases. Writes /.maggy/config.yaml and ensures deps are installed.
specmanager-board
Open the SpecManager kanban board in your default browser.
progress
You are generating a visual progress report showing which phases are complete, in-progress, or pending for the current feature.
commit
You are creating a conventional commit scoped to the current phase of work.