Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/bug-ops/zeph/regexnpx skills add bug-ops/zeph --skill regexgit clone --depth 1 https://github.com/bug-ops/zephWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00085 | $0.03501 |
| Opus 5 | $0.00043 | $0.01750 |
| Sonnet 5 | $0.00017 | $0.00700 |
| Haiku 4.5 | $0.00009 | $0.00350 |
Grade A, and why
regex scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 382 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Regular Expressions Reference
Quick Reference
| Pattern | Matches |
|---|---|
. |
Any character (except newline) |
\d |
Digit [0-9] |
\w |
Word character [a-zA-Z0-9_] |
\s |
Whitespace (space, tab, newline) |
\D, \W, \S |
Negated versions |
^ |
Start of line |
$ |
End of line |
\b |
Word boundary |
* |
0 or more |
+ |
1 or more |
? |
0 or 1 (optional) |
{n} |
Exactly n |
{n,m} |
Between n and m |
[abc] |
Character class |
[^abc] |
Negated character class |
(...) |
Capture group |
(?:...) |
Non-capturing group |
a|b |
Alternation |
Character Classes
Shorthand Classes
| Class | Equivalent | Matches |
|---|---|---|
\d |
[0-9] |
Digit |
\D |
[^0-9] |
Non-digit |
\w |
[a-zA-Z0-9_] |
Word character |
\W |
[^a-zA-Z0-9_] |
Non-word character |
\s |
[ \t\n\r\f\v] |
Whitespace |
\S |
[^ \t\n\r\f\v] |
Non-whitespace |
\h |
[ \t] |
Horizontal whitespace (PCRE) |
\v |
[\n\r\f\v] |
Vertical whitespace (PCRE) |
POSIX Classes (use inside [...])
| Class | Matches |
|---|---|
[:alpha:] |
Letters |
[:digit:] |
Digits |
[:alnum:] |
Letters and digits |
[:upper:] |
Uppercase letters |
[:lower:] |
Lowercase letters |
[:space:] |
Whitespace |
[:punct:] |
Punctuation |
[:print:] |
Printable characters |
[:graph:] |
Visible characters (no space) |
[:xdigit:] |
Hex digits [0-9a-fA-F] |
Usage: [[:alpha:]] (double brackets when inside a character class).
Custom Character Classes
[aeiou] # Vowels
[a-z] # Lowercase letters
[A-Z] # Uppercase letters
[0-9] # Digits
[a-zA-Z0-9] # Alphanumeric
[^aeiou] # NOT vowels
[a-z&&[^m-r]] # a-z except m-r (intersection, Java/Rust)
[-.] # Literal hyphen and dot (hyphen first or last)
[\\^] # Literal backslash and caret
Quantifiers
Greedy (match as much as possible)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 382 lines · 85 tokens per session scan A 291c2584687c
regex is a skill published in the GitHub repository bug-ops/zeph (57 stars, last pushed 8d ago), licensed MIT. It adds 85 tokens to every session and 3,501 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
data_analyst
Analyses datasets with professional rigour — statistical summaries, clear narratives, and well-chosen visualisations.
verify
Run Chimeraforge's canonical verification gate end-to-end and report the real output before claiming work done or committing. Failing output gets pasted, fixed, and re-run — never summarized away.
lint-js
Lint JS/TS code only. Use before opening a PR when only JavaScript or TypeScript files were changed (no Rust).
interview
Ask one useful structured question at a time only when material product/implementation choices are genuinely missing; remember answers and produce a brief/spec. Discoverable facts should be investigated instead of asked.
test
Detect the project’s test stack, run the narrowest useful tests, create tests when authorized, and report coverage/gaps honestly.
verify
Exercise the real app/API/CLI and collect observable evidence; tests alone do not count as end-to-end verification.