Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/ushibo/brigade/versiongit clone --depth 1 https://github.com/ushibo/brigadeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00010 | $0.00354 |
| Opus 5 | $0.00005 | $0.00177 |
| Sonnet 5 | $0.00002 | $0.00071 |
| Haiku 4.5 | $0.00001 | $0.00035 |
Grade A, and why
version scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Print the current version of the brigade plugin and what changed most recently.
Steps:
-
Read
~/.claude/plugins/cache/claude-research/dev/*/\.claude-plugin/plugin.json— pick the version from whichever install path is active (the directory named after the version, e.g.0.6.0/). If multiple versions are cached, the active one is the one that resolved when this command ran — use theplugin.jsonfrom whatever directory this command file itself lives in (that is always the active install). -
Print in this exact format:
brigade plugin — v{version}
{description from plugin.json}
Author: {author.name}
Install path: ~/.claude/plugins/cache/claude-research/dev/{version}/
- Do not guess the version. If you cannot read plugin.json for any reason, say so explicitly:
Could not read plugin.json — install may be corrupted. Reinstall with:
/plugin uninstall dev@claude-research
/plugin marketplace update claude-research
/plugin install dev@claude-research
- Do not print a full changelog — the user can check
git login the source repo for that. Just one line: "See claude-research repo git log for full changelog."
Hard rules
- Read-only. This command never writes anything.
- No guessing. Version must come from plugin.json on disk, not from memory.
- Fast. Three bash commands at most. Do not probe network, do not list all installed plugins.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 37 lines · 10 tokens per session scan A 8b23c3a856f0
version is a command published in the GitHub repository ushibo/brigade (1 stars, last pushed 1mo ago), licensed MIT. It adds 10 tokens to every session and 354 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
riskreview
The user invoked the /riskreview facade command from the risk-review-pipeline pack.
music-suno-prompt
Grounded Suno prompt synthesis from local knowledge corpus + persona canon + label canon. No vibes-prompting.
triage
Triage review findings one by one — present pending TODOs for user decision (approve, skip, modify).
audit-plugin
Audit plugin skills, commands, and agents for structure, size, and naming issues.
youtube-pulse
Summarize latest videos from tracked YouTube channels and extract short-term investment signals relevant to current holdings. Run after /market-pulse for context, or standalone for a quick opinion check.
mega-plan
Generate a mega-plan for project-level multi-feature orchestration. Breaks a complex project into parallel features with dependencies. Usage: /plan-cascade:mega-plan [--flow ] [--tdd ] [--confirm] [--no-confirm] [--spec ] [--first-principles] [--max-questions N] [design-doc-path].