Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/spree/agent-skills/audit-upgradegit clone --depth 1 https://github.com/spree/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/spree/agent-skills/audit-upgrade)<a href="https://agentmods.dev/commands/spree/agent-skills/audit-upgrade"><img src="https://agentmods.dev/badge/commands/spree/agent-skills/audit-upgrade.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00024 | $0.00777 |
| Opus 5 | $0.00012 | $0.00388 |
| Sonnet 5 | $0.00005 | $0.00155 |
| Haiku 4.5 | $0.00002 | $0.00078 |
Grade A, and why
audit-upgrade scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 33 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Spree upgrade-readiness audit
Target version: $ARGUMENTS — if blank, detect the installed version (step 1) and target the next minor.
This command is read-only/advisory: never run spree upgrade, bundle update, or migrations from here. The output is a readiness report; the user runs the upgrade.
Flavor note: on a classic Rails app (Spree gems at the repo root, no Docker/CLI), read Gemfile.lock instead of backend/Gemfile.lock, get the plan with DRY_RUN=1 bundle exec rake spree:upgrade instead of spree upgrade --plan, and the closing recommendation becomes the native sequence: bundle update <spree gems>, bin/rake spree:install:migrations && bin/rails db:migrate, bin/rake spree:upgrade.
Steps
-
Determine the version hop. Installed: the
spree_coreentry inbackend/Gemfile.lock(monorepo edge projects resolve gems via path — read the version from the monorepo's gemspec instead). Target:$ARGUMENTSor the next minor. -
Read the official upgrade doc for that hop. Local first:
node_modules/@spree/docs/dist/developer/upgrades/<from>-to-<to>.md; fall back tohttps://spreecommerce.org/docs/developer/upgrades/<from>-to-<to>. Extract three lists: (a) the data-backfill steps the rake manifest automates, (b) required post-upgrade configuration the manifest does NOT cover (cron jobs, env), (c) breaking changes that may require code edits. -
Spawn the
spree-expertagent (Task tool,subagent_type: spree-expert) with a charter built from the breaking-changes list, for example:Audit this codebase for the Spree → upgrade. For each breaking change below, find concrete usages with file:line evidence — or state it's not used: . Check specifically: decorators in
backend/app/referencing renamed or removed Spree classes/methods; storefront code (apps/storefront/) string-matching wire formats that changed; custom subscribers/services touching changed models. Also report the@spree/sdkversion declared inapps/storefront/package.jsonand whether it matches the target Spree version's compatibility row. Return findings only — no fixes.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 33 lines · 24 tokens per session scan A 7a706c28f39c
audit-upgrade is a command published in the GitHub repository spree/agent-skills (4 stars, last pushed 2mo ago), licensed MIT. It adds 24 tokens to every session and 777 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
dev
Runs Vendure in development mode. By default it starts three processes: the GraphQL server (ts-node ./src/index.ts), the worker (ts-node ./src/index-worker.ts), and the dashboard (a Vite dev server).
validate-idea
Validate Shopify app idea against market demand, category saturation, App Store discovery patterns, and monetization viability.
ebay-orders
Check recent eBay orders and fulfillment status.
intake
You are running the intake for this purchase. The goal is to populate spec.md at the repo root with the per-purchase brief.
price-strategy
You are a senior E-commerce & Retail specialist. The user needs help with price strategy in the context of product catalogue optimisation, conversion rate, customer journey and retail analytics.
price-strategy
You are a senior E-commerce & Retail specialist. The user needs help with price strategy in the context of product catalogue optimisation, conversion rate, customer journey and retail analytics.