Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/studioKjm/ai-harness-templatenpx agentmods add commands/studiokjm/ai-harness-template/rfcWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/studiokjm/ai-harness-template/rfc)<a href="https://agentmods.dev/commands/studiokjm/ai-harness-template/rfc"><img src="https://agentmods.dev/badge/commands/studiokjm/ai-harness-template/rfc.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00021 | $0.01786 |
| Opus 5 | $0.00010 | $0.00893 |
| Sonnet 5 | $0.00004 | $0.00357 |
| Haiku 4.5 | $0.00002 | $0.00179 |
Grade A, and why
rfc scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 196 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/rfc — RFC Lifecycle Management
"Architectural changes need a paper trail. Code changes don't have to wait for a meeting."
When to use
- Change touches >1 module's design or contract
- Migration affecting multiple consumers
- New dependency / framework / language
- Security-relevant architecture (encryption, auth)
- Scale/cost decisions ($X/month threshold)
- Deprecation with stakeholder impact
Not for:
- Bug fixes
- Single-feature additions following existing patterns
- Refactors that don't change interfaces
- Dependency patch updates
Usage
/rfc new <slug> --title "..." [--authors A1 A2 ...]
/rfc list [--status draft|proposed|accepted|rejected|superseded]
/rfc show <rfc-id>
/rfc propose <rfc-id> # draft → proposed (validates completeness)
/rfc accept <rfc-id> --decided-by NAME --rationale "..." [--conditions C1 ...]
/rfc reject <rfc-id> --decided-by NAME --rationale "..."
/rfc supersede <rfc-id> --by <new-rfc-id>
/rfc link <rfc-id> --files F1 [F2 ...] [--modules M1 [...]]
For per-PR linking, see /rfc-link.
State machine
[draft] → [proposed] → [accepted] → [superseded]
↓ ↑
[rejected] (replaced by new RFC)
↓
[draft] (rollback for revision)
| State | Meaning | Move when |
|---|---|---|
| draft | Author iterating | Author ready for review |
| proposed | Under review | Stakeholder decision made |
| accepted | Decision: yes | Implementation can begin |
| rejected | Decision: no | (terminal — record reason) |
| superseded | Replaced by newer RFC | (terminal — links to replacement) |
Instructions
Step 1 — Locate the script
.harness/methodologies/rfc-driven/scripts/rfc.py
Step 2 — Create RFC
python3 .harness/methodologies/rfc-driven/scripts/rfc.py \
new eventbus-replacement \
--title "Replace in-process event bus with Kafka for cross-service events" \
--authors jimin
Step 3 — Fill yaml fields (manual)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 196 lines · 21 tokens per session scan A b6497f0a2911
rfc is a command published in the GitHub repository studioKjm/ai-harness-template (43 stars, last pushed 3mo ago), licensed MIT. It adds 21 tokens to every session and 1,786 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
harness-review
Review the current change set from an opposing harness-engineering perspective.
api-reviewer
Reviews Next.js route handlers and server actions - input validation, status codes, error handling, auth checks, rate limiting, response shape. Use when API...
code-reviewer
Reviews a diff for correctness, security, and maintainability against the dev-pack standards. Use after writing or modifying code, and inside /plan-build-rev...
db-reviewer
Reviews Postgres/Supabase schema, migrations, queries, and RLS for safety and performance. Use when DB code changes, before applying a migration, or inside /...
frontend-reviewer
Reviews React/Next.js UI for accessibility, the anti-template design bar, animation safety, responsiveness, and component architecture. Use when UI changes,...
performance-reviewer
Reviews a change for performance - N+1 queries, missing indexes, slow queries, client bundle size, Core Web Vitals, caching/revalidation, render performance....