Borrowing it
Nothing to install: this file belongs to tyejcoleman/tokenroom. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/tyejcoleman/tokenroom/main/.claude/commands/add-fixture.mdgit clone --depth 1 https://github.com/tyejcoleman/tokenroomWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/tyejcoleman/tokenroom/add-fixture)<a href="https://agentmods.dev/commands/tyejcoleman/tokenroom/add-fixture"><img src="https://agentmods.dev/badge/commands/tyejcoleman/tokenroom/add-fixture.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00016 | $0.00295 |
| Opus 5 | $0.00008 | $0.00148 |
| Sonnet 5 | $0.00003 | $0.00059 |
| Haiku 4.5 | $0.00002 | $0.00030 |
Grade A, and why
add-fixture scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Add a payload fixture for: $ARGUMENTS
The fixture corpus (test/fixtures/) is the foundation of ADR-5 (degrade, never crash).
Every payload shape observed in the wild — especially broken ones — becomes a fixture.
- Sanitize the payload: replace
session_id, paths, and any identifying values with synthetic ones; keep the structural anomaly byte-faithful (that's the point). - Save as
test/fixtures/statusline-<short-name>.jsonwith a name describing the shape (e.g.statusline-epoch-leak.json, notstatusline-bug3.json). - Add assertions to
test/state.test.mjs: whatparsePayloadmust produce — bad fields becomenull(never crash, never out-of-range), good fields survive, and the result validates against the schema (validateResourceState→[]). - If the tap/hook surface behavior changes (HUD/stamp text), cover it in
test/cli.test.mjs. npm testgreen; mention the fixture in the PR with where/how the payload was observed (Claude Code version, plan, model).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 21 lines · 16 tokens per session scan A 7c0cda15bb6c
add-fixture is a command published in the GitHub repository tyejcoleman/tokenroom (0 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 16 tokens to every session and 295 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
ijfw-audit
Run the IJFW audit gate for the current workflow phase. Usage: /ijfw-audit [phase name].
api-aqa-flow-execution-and-report-analysis
Phase 6 Execution & Report Analysis of api-aqa-flow (USER INTERACTION REQUIRED).
ng-red-team
Portable command prompt generated from skills/stress-testing-agent-changes/SKILL.md. Edit the skill, then run python tools/ng.py gen-commands; do not edit this file by hand.
fire-verify-uat
Conversational User Acceptance Testing with automatic parallel diagnosis on failures.
generate-tests
Generate comprehensive tests for specified code.
dream
Memory dream pass — judge undreamed days, promote durable signal to long-term, then sweep.