Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/smicolon/ai-kit/fastlane-setupgit clone --depth 1 https://github.com/smicolon/ai-kitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/smicolon/ai-kit/fastlane-setup)<a href="https://agentmods.dev/commands/smicolon/ai-kit/fastlane-setup"><img src="https://agentmods.dev/badge/commands/smicolon/ai-kit/fastlane-setup.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00019 | $0.01091 |
| Opus 5 | $0.00010 | $0.00545 |
| Sonnet 5 | $0.00004 | $0.00218 |
| Haiku 4.5 | $0.00002 | $0.00109 |
Grade A, and why
fastlane-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 189 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Fastlane Setup Command
Initialize Fastlane configuration for Flutter iOS and/or Android deployment.
Parse Arguments
Extract from user input:
- platform:
ios,android, orboth(default: both)
Gather Information
Ask user for required information:
iOS Configuration
- Apple Developer Team ID
- App Store Connect API Key (or Apple ID)
- Bundle Identifier (from
ios/Runner.xcodeproj) - Match repository URL (for certificates)
Android Configuration
- Package name (from
android/app/build.gradle) - Google Play Console access (service account JSON path)
Setup Steps
1. Install Fastlane
# Check if Fastlane installed
which fastlane || gem install fastlane
# Create Gemfile if not exists
cat > Gemfile << 'EOF'
source "https://rubygems.org"
gem "fastlane"
plugins_path = File.join(File.dirname(__FILE__), 'fastlane', 'Pluginfile')
eval_gemfile(plugins_path) if File.exist?(plugins_path)
EOF
bundle install
2. iOS Fastlane Setup
Create ios/fastlane/Appfile:
app_identifier("com.company.app")
apple_id("[email protected]")
team_id("TEAM_ID")
Create ios/fastlane/Matchfile:
git_url("[email protected]:company/certificates.git")
storage_mode("git")
type("appstore")
app_identifier(["com.company.app"])
username("[email protected]")
Create ios/fastlane/Fastfile:
default_platform(:ios)
platform :ios do
before_all do
setup_ci if ENV['CI']
end
desc "Push to TestFlight"
lane :beta do
match(type: "appstore", readonly: true)
build_app(
workspace: "Runner.xcworkspace",
scheme: "Runner",
export_method: "app-store"
)
upload_to_testflight(
skip_waiting_for_build_processing: true
)
end
desc "Push to App Store"
lane :release do
match(type: "appstore", readonly: true)
build_app(
workspace: "Runner.xcworkspace",
scheme: "Runner",
export_method: "app-store"
)
upload_to_app_store(
submit_for_review: true,
automatic_release: false,
force: true
)
end
end
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 189 lines · 19 tokens per session scan A e7973513b66d
fastlane-setup is a command published in the GitHub repository smicolon/ai-kit (6 stars, last pushed today), licensed MIT. It adds 19 tokens to every session and 1,091 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
xcode-test
Build and test iOS apps on simulator using XcodeBuildMCP.
security-review
CWE 기반 보안 검토 + STRIDE 위협 모델링 (v6 - effort:max 강제).
auto-browse
Auto-browse — learn, optimize, and graduate browser operations or web data-mining workflows.
docs-review
Phase 4 of documenting-projects: Quality gate with 8 measurable criteria and iteration. Triggers: '/docs-review', invoked by documenting-projects orchestrator.
app-store-audit
Run an enterprise pre submission compliance audit on an iOS or Android app against Apple App Store and Google Play rejection rules. Pass a project path or run from the project root.
build-verify
Run the full build / test / analyze / format verification pass for this Flutter app.