Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/varienos/agentic-workflow/post-deploy.skeletongit clone --depth 1 https://github.com/varienos/agentic-workflowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.03606 |
| Opus 5 | $0.00000 | $0.01803 |
| Sonnet 5 | $0.00000 | $0.00721 |
| Haiku 4.5 | $0.00000 | $0.00361 |
Grade D, and why
post-deploy.skeleton scanned grade D with 3 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Hidden instructionshighPrompt injection
Directives inside HTML comments, invisible characters or bidirectional overrides are read by the model and not by the person reviewing the file.
<!-- GENERATE: SMOKE_TEST_ENDPOINTS Aciklama: Bu bolum Bootstrap tarafindan manifest verileriyle doldurulur. Gerekli manifest alanlari: environments, api_endpoints, project.api_prefix Ornek cikti: ## Smoke Test Endpoint' Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
cat > ../.claude/reports/deploys/deploy-$(date '+%Y%m%d-%H%M%S').md << 'DEPLOY_EOF' Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -sf --max-time 10 https://api.example.com/health | jq . How it starts
The opening of the file, as written. The whole thing — 372 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Post-Deploy — Coolify Deploy Dogrulama
Coolify uzerinden deploy sonrasinda production ortaminin sagligini dogrular. Kullanim:
/post-deploy
Kural: OTONOM CALIS
- Kullaniciya soru SORMA — tum kontrolleri sirayla calistir.
- Hicbir seyi DEGISTIRME — sadece kontrol et ve raporla.
- Tum adimlari CALISTIR — bir adimi atlama.
- Rollback gerekirse TALIMAT ver, kendin yapma.
Step 1 — Deploy Bekleme Suresi
Coolify build + deploy isleminin tamamlanmasini bekle:
echo "Coolify build + deploy bekleniyor (90 saniye)..." && sleep 90
NOT: Coolify build suresi projeye gore degisir. Tipik sureler:
- Basit Node.js uygulamasi: 30-60 saniye
- Multi-stage Docker build: 60-120 saniye
- Monorepo build: 90-180 saniye
Build tamamlandigini Coolify dashboard'dan kontrol edebilirsiniz.
Step 2 — Health Check
Production ortaminin saglik durumunu kontrol et.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 372 lines · 0 tokens per session scan D 8213ee4466cd
post-deploy.skeleton is a command published in the GitHub repository varienos/agentic-workflow (58 stars, last pushed 2mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 3,606 tokens. A static security scan graded it D with 3 findings (hidden instructions, reads agent configuration directories, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
status
Show current Craft progress — cycles, stories, backlog in a rich dashboard view.
story-archive
Move a story from a cycle back to the backlog.
project
Manage projects inside a topic wiki. Projects are folders under output/projects/ that group related outputs (playbooks, images, code, data) with a goal captured in WHY.md.
luda
Invoke Luda, your Scrum Master, for board integrity — orphan work items, plan-vs-tracker divergence, Done-without-negative-criteria, parked-without-a-trigger — plus ticket creation and team orchestration.
design-sprint
Orchestrate design-to-implementation workflow for a sprint or feature. Coordinates /ui (Aura) and /fe (Finn).
ledger-plan
Generate implementation plan with backlog, milestones, and test plan constrained by decisions and risks.