Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/zilliztech/zilliz-plugin/quickstartgit clone --depth 1 https://github.com/zilliztech/zilliz-pluginWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00024 | $0.00484 |
| Opus 5 | $0.00012 | $0.00242 |
| Sonnet 5 | $0.00005 | $0.00097 |
| Haiku 4.5 | $0.00002 | $0.00048 |
Grade C, and why
quickstart scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
curl -fsSL https://raw.githubusercontent.com/zilliztech/zilliz-cli/master/install.sh | bash Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -fsSL https://raw.githubusercontent.com/zilliztech/zilliz-cli/master/install.sh | bash What it actually says
Guide the user through the complete Zilliz Cloud CLI setup. Follow these steps in order:
Step 1: Install zilliz-cli
Check if already installed:
zilliz --version
If not installed or needs upgrading:
curl -fsSL https://raw.githubusercontent.com/zilliztech/zilliz-cli/master/install.sh | bash
Verify:
zilliz --version
Step 2: Authenticate
Check if already logged in:
zilliz auth status
If not logged in, instruct the user to open their own terminal and run one of:
- Browser login (recommended) —
zilliz login— opens browser for OAuth, full feature access. - API Key via login —
zilliz login --api-key— prompts for API key, no browser needed. - API Key via configure (legacy) —
zilliz configure— prompts for API key, simpler setup. - Environment variable — add
export ZILLIZ_API_KEY=<key>to.zshrc/.bashrc.
IMPORTANT: These commands require interactive input and cannot run inside Claude Code. Do NOT ask the user to paste API keys into the chat.
Wait for the user to confirm login is complete, then verify:
zilliz auth status
Step 3: Select a Cluster
List available clusters:
zilliz cluster list
If no clusters exist, offer to create one:
zilliz project list
zilliz cluster regions
zilliz cluster create --type serverless --name <name> --project-id <id> --region <region>
Step 4: Set Cluster Context
Set the active cluster for data operations:
zilliz context set --cluster-id <selected-cluster-id>
Step 5: Verify
Confirm everything works:
zilliz context current
zilliz collection list
Report the setup result to the user, showing their cluster ID, endpoint, and database.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 85 lines · 24 tokens per session scan C ddfab5b4a116
quickstart is a command published in the GitHub repository zilliztech/zilliz-plugin (3 stars, last pushed 2d ago), licensed Apache-2.0. It adds 24 tokens to every session and 484 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
search
Search across all connected sources in one query.
digest
Generate a daily or weekly digest of activity across all connected sources.
start
Initialize the productivity system and open the dashboard.
update
Sync tasks and refresh memory from your current activity.
check
Run TYPO3 conformance check on current extension.
improve-prompt
Analyze and enhance vague or incomplete prompts before execution.