Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/xiaolai/mac-it-guy-pro/checkupgit clone --depth 1 https://github.com/xiaolai/mac-it-guy-proWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/xiaolai/mac-it-guy-pro/checkup)<a href="https://agentmods.dev/commands/xiaolai/mac-it-guy-pro/checkup"><img src="https://agentmods.dev/badge/commands/xiaolai/mac-it-guy-pro/checkup.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00023 | $0.01470 |
| Opus 5 | $0.00012 | $0.00735 |
| Sonnet 5 | $0.00005 | $0.00294 |
| Haiku 4.5 | $0.00002 | $0.00147 |
Grade A, and why
checkup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Checkup — the regular health visit
Read ${CLAUDE_PLUGIN_ROOT}/skills/it-core/SKILL.md first — the safety contract and report format are binding. Read ~/ITGuy/machine.md if it exists (compare today's findings against its Watch List). If uname is not Darwin, say this version supports Mac only and stop.
This command changes nothing about the user's system — it diagnoses and recommends only. It does write its own bookkeeping: the visit log, the machine profile, and a declined pattern id if an automation offer is turned down. Those writes are required, not exceptions to skip.
Step 1: Gather evidence
Dispatch the mac-it-guy-pro:diagnostician agent (via Task) for all six areas: disk, memory & CPU, startup, updates, backups, hardware.
Step 2: Render the report
Use the it-core report format exactly: plain-language top line with the overall verdict, findings table (Area | Status | What I found | What I suggest, with 🟢🟡🔴), then exactly one recommended next step phrased as an offer — the highest-impact 🔴 item, or the top 🟡 if nothing is red.
Rules:
- Every startup item is named in plain language ("Google's software updater"), never just its plist filename.
- Backup findings distinguish "no backup configured" (🔴) from "backup disk not connected today" (🟡).
- A diagnostic that could not run appears as 🟡 "couldn't check" with the one-sentence reason — never silently dropped.
Step 2b: One automation offer — only when the machine has earned it
Read ${CLAUDE_PLUGIN_ROOT}/skills/toolbox-contract/SKILL.md and then its references/pattern-catalogue.md — the catalogue's rules refer to the declined array, the pattern field, and the registry schema, all of which are defined in the parent skill, so loading the reference alone leaves those terms undefined. Run its signals. Its rules are binding, and three of them decide whether you say anything at all:
- Skip this step entirely if any 🔴 finding is open. A full disk or a missing backup outranks any convenience, and raising both at once buries the one that matters.
- Skip any pattern already in
declinedor already built in~/ITGuy/toolbox.json. - At most one offer, the highest count among those that fired, appended as a single line below the recommended next step — never a list, never a second section.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 77 lines · 23 tokens per session scan A bedfc255f58a
checkup is a command published in the GitHub repository xiaolai/mac-it-guy-pro (5 stars, last pushed 1mo ago), licensed MIT. It adds 23 tokens to every session and 1,470 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
graphify
Turn your vault into a clustered knowledge graph with HTML and JSON outputs.
instinct-export
Export this project's instinct library to a portable YAML pack (Instinct Engine).
instinct-import
Import a portable YAML instinct pack with confidence-gated merge (Instinct Engine).
optimize-brain
Deep vault optimization: CRM, graphs, dashboards, compression, wikilinks.
patterns
Scan recent sessions for recurring patterns and turn them into captures (rules, concept notes, writing seeds).
second-brain-mapping
Map your vault: extract structured metadata from every typed file, surface cross-doc insights, optionally build a knowledge graph.