Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add swt-labs/vibe-better-with-claude-code-vbw/plugin install vbwWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/swt-labs/vibe-better-with-claude-code-vbw/list-todos)<a href="https://agentmods.dev/commands/swt-labs/vibe-better-with-claude-code-vbw/list-todos"><img src="https://agentmods.dev/badge/commands/swt-labs/vibe-better-with-claude-code-vbw/list-todos/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/swt-labs/vibe-better-with-claude-code-vbw/list-todos"><img src="https://agentmods.dev/badge/commands/swt-labs/vibe-better-with-claude-code-vbw/list-todos.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00016 | $0.01378 |
| Opus 5 | $0.00008 | $0.00689 |
| Sonnet 5 | $0.00003 | $0.00276 |
| Haiku 4.5 | $0.00002 | $0.00138 |
Grade A, and why
vbw:list-todos scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 90 lines — stays where its author put it; the contents beside it link to each section on GitHub.
VBW List Todos $ARGUMENTS
Context
- Working directory: current workspace root.
- Plugin cache root:
"${CLAUDE_CONFIG_DIR:-$HOME/.claude}/plugins/cache/vbw-marketplace/vbw"(respects non-defaultCLAUDE_CONFIG_DIR; always quote — path may contain spaces). - Session startup creates a symlink at
/tmp/.vbw-plugin-root-link-${CLAUDE_SESSION_ID:-default}pointing to the plugin root. The cache-based tiers are authoritative; symlinks are a fallback. See Step 1 for full resolution order.
Guard
- Not initialized (no .vbw-planning/ dir): STOP "Run /vbw:init first."
- Restricted mode: If the current permission mode does not allow Bash execution, STOP: "
/vbw:list-todosneeds Bash access to run helper scripts. If you're in read-only or another restricted mode, switch to a write-enabled mode (for example bypass permissions) and rerun the command."
Steps
- Resolve plugin root: Determine the plugin root path. Always quote derived paths (they may contain spaces). Try in order:
(a) The
local/subdirectory under the plugin cache root (i.e."${CLAUDE_CONFIG_DIR:-$HOME/.claude}/plugins/cache/vbw-marketplace/vbw/local/"), if it exists and containsscripts/hook-wrapper.sh. (b) The numerically highest versioned directory under the plugin cache root — list subdirectories matching a dotted-version pattern (e.g.1.30.0), sort by each numeric component (major, minor, patch), pick the highest, and accept it only if it containsscripts/hook-wrapper.sh. (c) Any other (non-versioned) subdirectory under the plugin cache root — pick the newest by name, accept only if it containsscripts/hook-wrapper.sh. This covers non-standard cache layouts. (d) The session symlink/tmp/.vbw-plugin-root-link-${CLAUDE_SESSION_ID:-default}, or any existing/tmp/.vbw-plugin-root-link-*symlink whose target containsscripts/hook-wrapper.sh. (e) Extract--plugin-dir <path>from the process tree (ps axww) and use that path if it containsscripts/hook-wrapper.sh. If none resolves to a valid directory, STOP: "Plugin root not found. The session startup hook may not have run. Try restarting your Claude session." Store the resolved path asPLUGIN_ROOTfor subsequent steps.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 90 lines · 16 tokens per session scan A e5190a07e537
vbw:list-todos is a command published in the GitHub repository swt-labs/vibe-better-with-claude-code-vbw (79 stars, last pushed 2mo ago), licensed MIT. It adds 16 tokens to every session and 1,378 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
template
Manage issue templates for streamlined issue creation.
sync-linear
Sync current work with Linear ticket status.
add-note
Add an internal or external note to a ConnectWise PSA ticket.
fest-show
Show festival progression (in-progress tasks, roadmap, and dependency view).
dispatcher
Pick the next-best repo to work on across the portfolio — rank free repos, recommend one, claim its lease atomically, and route to the entry command.
workpm
A project-management workflow for coordinating multiple AI workers through five stages. It includes task assignment, shared activity logs, worker replacement, and final checks.