Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/zircote-plugins/sdlc-quality/add-testgit clone --depth 1 https://github.com/zircote-plugins/sdlc-qualityWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00014 | $0.00791 |
| Opus 5 | $0.00007 | $0.00396 |
| Sonnet 5 | $0.00003 | $0.00158 |
| Haiku 4.5 | $0.00001 | $0.00079 |
Grade A, and why
add-test scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
91% identical to add-test — 63 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 150 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Add Test Definition
Interactively create a new test definition and add it to the test suite.
Process
Question 1: Component Type If not provided via argument, ask:
- Command
- Agent
- Skill
- Other
Question 2: Test ID
Ask for a unique test identifier.
Suggest format: category_component_action (e.g., cmd_setup_basic)
Question 3: Description Ask for a human-readable description of what the test validates.
Question 4: Action Ask what Claude should do for this test. Provide examples based on component type:
- Command: "Run the /sdlc-setup command"
- Agent: "Use the ci-architect agent to analyze CI configuration"
- Skill: "Ask: 'set up SDLC compliance'"
Question 5: Expectations Ask what should be validated:
- Text that should appear (contains)
- Text that should NOT appear (not_contains)
- Pattern to match (regex)
Question 6: Variable Capture Ask if any value should be captured for later tests. If yes, ask for variable name and capture pattern.
Question 7: Dependencies Ask if this test depends on another test running first.
Question 8: Tags Ask for tags to categorize the test:
- smoke, critical, regression, slow, etc.
Example output (YAML):
- id: cmd_setup_basic
description: Basic test for sdlc-setup command
category: commands
action: "Run the /sdlc-setup command"
expect:
- contains: "SDLC"
- not_contains: "error"
tags: [smoke, commands]
Confirm success:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 150 lines · 14 tokens per session scan A 1fb888b965c2
add-test is a command published in the GitHub repository zircote-plugins/sdlc-quality (10 stars, last pushed 1mo ago), licensed MIT. It adds 14 tokens to every session and 791 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 91% identical to add-test, differing in 63 lines, and is treated as a copy.
Other commands, from other repositories
merge
Finish a PR properly: every check green, every review addressed — human and bot — then merge and clean up.
pr
Prepare and open a pull request the senior way: gate, template, scrubbed, everything visible.
spec
Spec-first design: a gap-closing interview that produces a complete spec, with a quality controller that blocks until every section is answered and every question resolved.
copilot-leak
Copilot's auto-review escapes: find them since the last look, sanitise them, and turn each one into a lesson.
docs
The documentation report: references, diagrams, drift, API docs, badges, README structure, links, Pages.
plan
Turn an approved spec into an implementation plan an engineer with zero context could execute — with a quality controller that blocks placeholders and hollow tasks.