Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/vscarpenter/gsd-task-manager/qcheckgit clone --depth 1 https://github.com/vscarpenter/gsd-task-managerWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00019 | $0.00504 |
| Opus 5 | $0.00010 | $0.00252 |
| Sonnet 5 | $0.00004 | $0.00101 |
| Haiku 4.5 | $0.00002 | $0.00050 |
Grade A, and why
qcheck scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Review all changed files in this session as a skeptical staff engineer for the gsd-taskmanager codebase. Apply the full coding-standards.md and CLAUDE.md rules.
Run git status and git diff first to see what has changed. Then evaluate each changed file against:
- Standards compliance — Files ≤350 lines, functions ≤30 lines, ≤3 nesting levels, no magic numbers, descriptive naming.
- Type safety — All function signatures typed, no
anywithout justification, Zod validation at boundaries (user input, import, MCP tool inputs). - TDD evidence — Were tests written first? Check git log if uncertain. Each new behavior should have a behavior-named test.
- Test quality — Positive AND negative cases. Coverage ≥80% for changed files. Independent tests (no shared mutable state). Mocks at boundaries, not deep.
- Error handling — Typed errors, no swallowed exceptions,
toast.error()from sonner instead ofwindow.alert(). - Project-specific gotchas:
- PocketBase:
client_updated_at(notupdated) in sort/filter,_superusersadmin endpoint, 100ms push throttle, batch lookups not N+1. - Schema:
.safeParse()(not.parse()) on user input paths; import uses.strip(), export uses.strict(). - Tests:
bun run test(notbun test);localStorage.removeItem(key)(notclear()). - UI:
toast.error()(notalert()); accessibility baseline from coding-standards Part 2.
- PocketBase:
- Security — Input validation, no committed secrets, parameterized queries, least privilege.
- Observability — Structured logging via
lib/logger.ts, noconsole.*in production paths, no PII in logs. - Definition of Done — Every box in coding-standards.md Part 7 "Definition of Done" checklist.
Distinguish blocking issues from suggestions. Prefix non-blocking comments with nit: or suggestion:.
Do not rewrite the code. Return a structured list of findings, organized by file, with file:line — issue — fix.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 26 lines · 19 tokens per session scan A 93614b7a0c62
qcheck is a command published in the GitHub repository vscarpenter/gsd-task-manager (24 stars, last pushed 4d ago), licensed MIT. It adds 19 tokens to every session and 504 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
methodology
View your cognitive methodology profile and reasoning patterns.
release
Comprehensive workflow for releasing a new version of the VectorMCP Ruby gem following best practices.
compile
Compile a FIBER decision context (world + query) and report the oracle verdict, omission accounting, and certificate digest faithfully.
safety-check
Verify the EA1 safety gate blocks all destructive actions on a page.
2-spec
Command "2-spec" from clchinkc/document-mcp, covering requirements gathering generation, behavioral scenario generation (optional), design document creation generation and implementation planning generation.
git
Git operations with intelligent commit messages and workflow optimization.