Borrowing it
Nothing to install: this file belongs to TheAstrelo/Claude-Pipeline. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/TheAstrelo/Claude-Pipeline/main/.claude/commands/pmatch.mdgit clone --depth 1 https://github.com/TheAstrelo/Claude-PipelineWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/theastrelo/claude-pipeline/pmatch)<a href="https://agentmods.dev/commands/theastrelo/claude-pipeline/pmatch"><img src="https://agentmods.dev/badge/commands/theastrelo/claude-pipeline/pmatch.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00564 |
| Opus 5 | $0.00000 | $0.00282 |
| Sonnet 5 | $0.00000 | $0.00113 |
| Haiku 4.5 | $0.00000 | $0.00056 |
Grade B, and why
pmatch scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
SESSION_DIR=$(cat .claude/artifacts/current.txt 2>/dev/null) How it starts
The opening of the file, as written. The whole thing — 115 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Verify plan-design alignment before build.
Prerequisites
Check that both design and plan exist:
SESSION_DIR=$(cat .claude/artifacts/current.txt 2>/dev/null)
if [ -z "$SESSION_DIR" ]; then
echo "ERROR: No active session. Run /arm first."
exit 1
fi
if [ ! -f "$SESSION_DIR/design.md" ]; then
echo "ERROR: No design.md found. Run /design first."
exit 1
fi
if [ ! -f "$SESSION_DIR/plan.md" ]; then
echo "ERROR: No plan.md found. Run /plan first."
exit 1
fi
Drift Detection
Use the drift-detector agent.
Input:
- Read
design.mdfrom the current session directory - Read
plan.mdfrom the current session directory
Process:
-
Extract all design requirements:
- Components to create
- APIs to implement
- Database changes
- Behavior specifications
- Error handling requirements
-
Map each requirement to plan step(s)
-
Check for drift types:
- Missing Coverage: Design requirement not in plan
- Scope Creep: Plan step not justified by design
- Contradictions: Plan conflicts with design
- Incomplete Steps: Plan step missing required detail
-
Output
drift-report.md
Verdict Rules
ALIGNED if:
- All design requirements covered
- No unjustified scope creep
- No contradictions
- All steps complete
DRIFT_DETECTED if:
- Any requirement uncovered
- Unjustified scope creep
- Any contradiction
- Critical incomplete step
Output
After detection, report:
## Drift Detection Complete
**Session:** {session-directory}
**Verdict:** [ALIGNED | DRIFT_DETECTED]
### Coverage
- Design requirements: [N]
- Covered by plan: [N]
- Missing: [N]
### Issues Found
[List any drift issues]
### Next Step
[If ALIGNED] Run `/build` to implement the plan.
[If DRIFT_DETECTED] Fix the drift issues:
- Missing coverage: Update /plan
- Scope creep: Justify or remove
- Contradictions: Resolve which is correct
User Override
If drift is detected but the user wants to proceed anyway:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 115 lines · 0 tokens per session scan B 01bde36ef964
pmatch is a command published in the GitHub repository TheAstrelo/Claude-Pipeline (44 stars, last pushed 3d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 564 tokens. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
status
Summarise what Fabrik is doing right now — board state, in-flight workers, worktrees with uncommitted changes.
setup-forge
First-run onboarding — asks name/goal/project-type/language, then beginner-safe API-key setup, then scaffolds the per-project Forge system. User-invoked only. Run once per project. Subcommands: doctor · keys · reset.
spreadsheet-audit
Perform a 6-step audit of an Excel spreadsheet for formula correctness, formatting consistency, data integrity, boss-auditable simplicity, and spec compliance. Uses the excel-screenshot MCP server tools — no Excel installation required.
custom-brief
Deep-research a specific topic and produce a comprehensive news-focused briefing with optional Notion/Obsidian/Teams/Slack publishing.
diagnose-roast-curve
Diagnose a logged roast curve for the classic defects — crash, flick, stall/bake, tipping, scorching — and assess RoR smoothness and development-time ratio.
gsd:resume-work
Resume work from previous session with full context restoration.