Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/stefan-jansen/claude-code-toolkit/spikegit clone --depth 1 https://github.com/stefan-jansen/claude-code-toolkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00403 |
| Opus 5 | $0.00000 | $0.00201 |
| Sonnet 5 | $0.00000 | $0.00081 |
| Haiku 4.5 | $0.00000 | $0.00040 |
Grade A, and why
spike scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Spike - Time-boxed Technical Exploration
Isolated environment for experimental code exploration with automatic cleanup.
Commands
| Command | Description |
|---|---|
/spike start "topic" |
Create spike branch, start timer |
/spike start "topic" --duration 60 |
Custom duration (minutes) |
/spike complete |
Generate findings report |
/spike abandon |
Discard and cleanup |
/spike status |
Check current spike |
Process
Start
- Create isolated branch:
spike/topic-timestamp - Create tracking file:
.claude/spikes/current.json - Set time box (default: 2 hours)
During Spike
- Experiment freely, quality doesn't matter
- Try multiple approaches
- Focus on learning
- Document findings as you go
Complete
- Generate findings report to
.claude/spikes/report_*.md - Options: keep branch / merge useful code / delete
Abandon
- Switch to main branch
- Delete spike branch
- Remove tracking file
Report Structure
# Spike Report: [Topic]
## Executive Summary
- What was explored
- Key findings
- Recommendation (proceed/pivot/abandon)
## Technical Findings
- What worked / didn't work
- Performance observations
- Libraries evaluated
## Recommendations
- Suggested approach
- Estimated effort
- Next steps
File Locations
.claude/spikes/
├── current.json # Active spike tracking
├── completed_*.json # Archived spikes
└── report_*.md # Spike reports
Guidelines
DO: Experiment, break things, time-box strictly, document findings DON'T: Polish code, write tests, exceed time limit
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 76 lines · 0 tokens per session scan A 9d4e8475080e
spike is a command published in the GitHub repository stefan-jansen/claude-code-toolkit (85 stars, last pushed 1mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 403 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
ctx
Search agent history or trace code to its original agent session.
enrich
Enrich project memory by mining 100 recently merged PRs: extracts decisions, conventions, gotchas, and architectural facts from PR discussions, review comments, and PR bodies.
reportloop
Interactively walk through all issues in REVIEWREPORT.md: explains each issue, asks to fix or skip, handles follow-up questions, and applies fixes one by one in severity order.
a11y
Audit and fix WCAG AA compliance — semantic HTML, ARIA, keyboard, contrast, reduced-motion.
components
Build component catalog with props, states, and accessibility.
docs
Audit docs, fix doc rot, enforce README and changelog standards.