Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/webcoyote/sandvault/releasegit clone --depth 1 https://github.com/webcoyote/sandvaultWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01344 |
| Opus 5 | $0.00000 | $0.00672 |
| Sonnet 5 | $0.00000 | $0.00269 |
| Haiku 4.5 | $0.00000 | $0.00134 |
Grade A, and why
release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 129 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Release
Prepare a new release for sandvault. This command updates the changelog, bumps the version, and creates a PR
Steps
-
Determine the new version number
- Use
.github/scripts/bump-version minorto bump the minor version unless the user specifies otherwise (e.g., 0.12.0 → 0.13.0) - Get the current version by running
./sv --version
- Use
-
Create a release branch
- Create branch:
git checkout -b release/vX.Y.Z
- Create branch:
-
Generate release data
- Run the data-gathering script, which collects commits, PR metadata, issue metadata, and contributors (PR authors, issue reporters, commit authors) into structured JSON:
.github/scripts/generate-release-data > /tmp/sv-release-data.json - If the script fails (e.g.
ghnot authenticated), fix the issue and retry
- Run the data-gathering script, which collects commits, PR metadata, issue metadata, and contributors (PR authors, issue reporters, commit authors) into structured JSON:
-
Generate changelog section via AI agent
- Pipe a prompt into
sv claudethat instructs it to read the release data and write a polished changelog section. The prompt should include the Changelog Guidelines and Contributor Credits rules from this document:cat <<'PROMPT' | ./sv claude Read the file /tmp/sv-release-data.json — it contains structured release data with commits, PR numbers, and contributor information. Generate a changelog section following these rules: - Only include end-user visible changes (ignore CI, docs, tests, internal refactoring) - Categorize into: Added, Changed, Fixed, Removed (omit empty categories) - Write clear, user-facing descriptions in present tense — not raw commit messages - Link PRs: ([#N](https://github.com/webcoyote/sandvault/pull/N)) - Credit non-core contributors inline: — thanks @user! - Credit bug reporters if different from PR author: — thanks @reporter for the report! - Core team (webcoyote) gets no inline credit - Add a "### Thanks to N contributors!" section listing all contributors alphabetically, linked to GitHub profiles - Use the version and date from the JSON for the heading: ## [X.Y.Z] - YYYY-MM-DD Write the result to /tmp/sv-changelog-section.md — nothing else, no explanation. If there are no user-facing changes, write a single line: _No user-facing changes._ PROMPT - If the output contains
_No user-facing changes._, ask the user if they still want to release
- Pipe a prompt into
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 129 lines · 0 tokens per session scan A c1d11a5e55c2
release is a command published in the GitHub repository webcoyote/sandvault (393 stars, last pushed 2d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 1,344 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
app
Control macOS apps via peekaboo app.
mcp
Run Peekaboo as an MCP server via peekaboo mcp.
drag
Execute drag-and-drop flows via peekaboo drag.
move
Position the cursor via peekaboo move.
set-value
Set accessibility element values directly via peekaboo set-value.
merge-and-status
Merge the current PR, pull main, surface any open contributor PRs and untriaged contributor issues, and show open milestone issues.