Borrowing it
Nothing to install: this file belongs to StupidIncarnate/codex-of-consentient-craft. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/StupidIncarnate/codex-of-consentient-craft/master/.claude/commands/quest-forensics.mdgit clone --depth 1 https://github.com/StupidIncarnate/codex-of-consentient-craftWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/stupidincarnate/codex-of-consentient-craft/quest-forensics)<a href="https://agentmods.dev/commands/stupidincarnate/codex-of-consentient-craft/quest-forensics"><img src="https://agentmods.dev/badge/commands/stupidincarnate/codex-of-consentient-craft/quest-forensics/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/stupidincarnate/codex-of-consentient-craft/quest-forensics"><img src="https://agentmods.dev/badge/commands/stupidincarnate/codex-of-consentient-craft/quest-forensics.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00022 | $0.05421 |
| Opus 5 | $0.00011 | $0.02710 |
| Sonnet 5 | $0.00004 | $0.01084 |
| Haiku 4.5 | $0.00002 | $0.00542 |
Grade A, and why
quest-forensics scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 369 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Quest forensics
You are the orchestrator of a forensic post-mortem on one quest run. You dispatch one analyzer per work item, keep a convergence spine as their reports land, then dispatch a compiler that merges everything into a single ranked document.
Quest id: $ARGUMENTS
You read no transcripts yourself. Transcripts run to hundreds of megabytes; reading one directly burns your context and buys nothing an analyzer cannot give you. Your jobs are: index the quest, brief the analyzers, keep the spine, and hand off to the compiler.
Step 1 — index the quest
python3 scripts/quest-forensics.py quest $ARGUMENTS > tmp/quest-forensics/$ARGUMENTS/index.txt
mkdir -p tmp/quest-forensics/$ARGUMENTS first. Read the index. It gives you, per work item: role,
status, session id, wall clock, operation text, flow ids, package names, transcript size and
sub-agent count — plus ward and riftcarver results and the original user request.
If the user named a range ("from the first codeweaver to the second siegemaster"), honour it.
Otherwise analyze every work item that has a sessionId. Work items with spawner=command
(ward, riftcarver) have no transcript — fold each into the analyzer for the agent item next to
it rather than giving it an analyzer of its own, and say so in that analyzer's brief.
Step 2 — write the analyzer brief
Write tmp/quest-forensics/$ARGUMENTS/ANALYZER-BRIEF.md. Every analyzer reads it, so it carries
everything common and nothing item-specific. It must contain:
The quest. Id, title, the user's original request quoted in full, the worktree path, and the path to the index from step 1.
Where transcripts live. ~/.claude/projects/<encoded-worktree-path>/ — the quest subcommand
prints the resolved directory. Main session at <sessionId>.jsonl; its sub-agents at
<sessionId>/subagents/agent-<id>.jsonl beside agent-<id>.meta.json (which carries agentType,
model, description, spawnDepth); oversized tool results spilled to <sessionId>/tool-results/.
Sub-agent transcripts have the same shape as main sessions, so every subcommand works on both.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago Changed b238b37ba8fd
- 4d ago First seen · 369 lines · 22 tokens per session scan A 02f38289fca7
quest-forensics is a command published in the GitHub repository StupidIncarnate/codex-of-consentient-craft (2 stars, last pushed yesterday), licensed MIT. It adds 22 tokens to every session and 5,421 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-07.
Other commands, from other repositories
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
specify
Create or update the feature specification from a natural language feature description.
analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
converge
Assess the current codebase against the feature's spec, plan, and tasks, then append any remaining unbuilt work as new tasks to tasks.md so implement can complete it.
implement
Execute the implementation plan by processing and executing all tasks defined in tasks.md.