Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/smicolon/ai-kit/wtgit clone --depth 1 https://github.com/smicolon/ai-kitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/smicolon/ai-kit/wt)<a href="https://agentmods.dev/commands/smicolon/ai-kit/wt"><img src="https://agentmods.dev/badge/commands/smicolon/ai-kit/wt.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00030 | $0.00606 |
| Opus 5 | $0.00015 | $0.00303 |
| Sonnet 5 | $0.00006 | $0.00121 |
| Haiku 4.5 | $0.00003 | $0.00061 |
Grade A, and why
wt scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Git Worktree Manager
Manage git worktrees with automatic isolation for parallel development.
Usage
/wt <command> [args]
Commands
| Command | Alias | Description |
|---|---|---|
create <branch> |
c |
Create worktree with isolation (env, docker, db) |
list |
ls |
List all worktrees for current repo |
remove <branch> |
rm |
Remove worktree (stops Docker, add -d to delete branch) |
open <branch> [--editor] |
o |
Open worktree (--cursor|-c, --agy|-a, --code|-v) |
Instructions
Run the worktree manager script:
"${CLAUDE_PLUGIN_ROOT}/scripts/wt.sh" $ARGUMENTS
Examples
# Create worktree for new feature (with full isolation)
/wt create feature/authentication
# Short form
/wt c feat-payments
# List all worktrees
/wt ls
# Remove worktree (stops Docker containers first)
/wt rm feature/authentication
# Remove worktree AND delete branch
/wt rm feat-payments -d
# Open in editor (auto-detect)
/wt o feat-payments
# Open in specific editor
/wt o feat-payments --agy
/wt o feat-payments -c
Naming Convention
~/code/retail-plus/ → main repo
~/code/retail-plus--feat-auth/ → worktree (sibling with --)
Auto-Setup on Create
- Loads
.worktreeinclude(generates default if missing) - Copies files matching glob patterns
- Rewrites env vars (DB_NAME, DATABASE_URL, etc.) with branch suffix
- Patches compose file with env var isolation (ports + container names)
- Auto-creates database in running Postgres
- Detects package manager (bun → pnpm → yarn → npm)
- Runs install at root (monorepo-aware)
.worktreeinclude Format
# File patterns to copy
.env*
apps/*/.env*
[rewrite]
auto # suffix DB_NAME, DATABASE_URL, etc.
# MY_DB=app_{{BRANCH}} # template mode
[docker]
auto # auto-detect compose file
# file=apps/backend/docker-compose.local.yml
# port_offset=10
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 94 lines · 30 tokens per session scan A 906e32f98bf6
wt is a command published in the GitHub repository smicolon/ai-kit (6 stars, last pushed today), licensed MIT. It adds 30 tokens to every session and 606 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other commands, from other repositories
update-threat-db
AgentSec Triage is the canonical technical source for threat evidence, dated fiches, detector inputs, and the public security feed. Do not research or edit the guide database first.
security-check
Quick configuration security check against known threats database. Verifies your Claude Code setup for known malicious skills, vulnerable MCPs, dangerous patterns, and exposed secrets.
import
Import reads the legacy Maestro flat-file store (/.maestro) read-only and ports its projects and per-project settings into the rewrite database. Legacy files are never modified, and a re-run skips rows that already exist, so it is safe to run more than once. The daemon must be stopped before running: it is the sole…
review-renovate
Review and merge renovate PRs with automerge configuration updates.
config
Command "config" from sdebruyn/fabric-dw-mcp-cli, covering configuration & defaults, http retry budget, sql retry budget, mcp workspace allowlist {#mcp-workspace-allowlist} and mcp server log level.
database-setup
Use when a project needs to store data and has no database yet. Setting up Supabase, creating tables, writing queries, and connecting them to the frontend. Written for designers.