Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add closedloop-ai/claude-plugins --skill closedloop-intelgit clone --depth 1 https://github.com/closedloop-ai/claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/closedloop-ai/claude-plugins/closedloop-intel)<a href="https://agentmods.dev/skills/closedloop-ai/claude-plugins/closedloop-intel"><img src="https://agentmods.dev/badge/skills/closedloop-ai/claude-plugins/closedloop-intel/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/closedloop-ai/claude-plugins/closedloop-intel"><img src="https://agentmods.dev/badge/skills/closedloop-ai/claude-plugins/closedloop-intel.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00153 | $0.01855 |
| Opus 5.5 | $0.00061 | $0.00742 |
| Sonnet 5.5 | $0.00031 | $0.00371 |
| Haiku 4.5 | $0.00015 | $0.00186 |
Grade A, and why
closedloop-intel scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 127 lines — stays where its author put it; the contents beside it link to each section on GitHub.
closedloop-intel (remote, connect.sh install)
This is the thin, tester-facing form of the closedloop-intel agent. It ships to your machine as a static file, but it holds no copy of the agent's instructions; the live routing protocol is served fresh, over MCP, on every call, so your ROUTING never goes stale no matter how long ago you installed it. This file itself is versioned, and the protocol you fetch first states the current copy's sha256 and what to do if yours is not it.
If the server is not connected, stop. If no closedloop-graph tool is
available in this session, or get_routing_protocol returns an error or cannot
be called, do not answer the question. Tell the user in one sentence that the
closedloop-graph server is not connected, that claude mcp list or
codex mcp list will show it failed, and that with the right URL a failed
connection means the token in the client does not match (Claude Code: re-run
the operator's connect one-liner; Codex: export CLGRAPH_MCP_TOKEN in the shell
that launches it). Never answer such a question from general knowledge without
saying so.
Your first action, every session, before answering anything: call the
closedloop-graph MCP server's get_routing_protocol tool, with no
arguments, and follow exactly what it returns. That response is the canonical
mission, question-routing table and answer shape, read live from the host
machine's disk at call time. Do not improvise a routing strategy from this file
alone; this file is an orientation note, not the protocol.
It answers with a SLICE, and the rest is one call away. The protocol is
larger than a harness will deliver in a single tool result, so the default
section="core" carries what you need to ROUTE. READ WHAT COMES BACK rather
than this paragraph, because section 3 arrives in one of two arrangements and
they call for different next moves. If it reaches you as an INDEX (a
| Row | Question shape | table), the route and its Never column are not in
that reply at all: match your question to a row, then call
get_routing_protocol again with row="<key>" for that row's route and its
prohibitions, before you touch any tool. If it reaches you as the full
three-column table (| Question shape | Route | Never |), the routes and their
prohibitions are already in front of you and there is nothing to fetch per row;
a host whose get_routing_protocol schema carries no row parameter is
serving that older arrangement, so do not spend a call looking for one. Ask for
the rest by name when a question turns on it: section="rules" for the
evidence discipline, the file-evidence ladder and the known data gaps, unless
what you were handed already contains a section headed 4, Rules;
section="routing_table" for the whole three-column table at once;
section="inventory" for the ledger schema and the two graphs;
section="snippets" for the named SQL, verbatim; section="personas" for the
persona guidance. The core names each of them at
the point where it needs one, so follow those pointers rather than guessing. Do
not ask for section="all" in order to read the routing table: that payload is
what your harness will truncate, and a truncated result does NOT announce
itself.
If get_routing_protocol is unavailable (the closedloop-graph server is not
connected, or the call errors), follow the stop rule at the top of this file.
The orientation below is background for when the server IS connected, never a
substitute for it.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 127 lines · 153 tokens per session scan A a7a97c478dca
closedloop-intel is a skill published in the GitHub repository closedloop-ai/claude-plugins (122 stars, last pushed today), licensed Apache-2.0. It adds 153 tokens to every session and 1,855 once invoked, about $0.0006 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-06.
Other skills, from other repositories
file-a-task
File work into nohuman (taskadd) and check on it (taskstatus) via the nohuman MCP bridge, instead of doing the work inline.
dx-audit
Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration. Use when asked to "audit my CLI", "review my SDK", or diagnose package type resolution.
incident-management
Manage ServiceNow incidents — creation with impact/urgency priority calc, auto-assignment by category, reassignment tracking, major incident declaration with bridge calls, time-based escalation, MTTR metrics.
problem-management
Manage ServiceNow problems — create from linked incidents, proactive pattern detection, RCA with 5-Whys, knownerror workarounds (KEDB), KEDB search by CI/category/keywords, and permanent-fix linkage to changes.
issue-triage
3-phase issue backlog management with audit, deep analysis, and validated triage actions. Use when triaging GitHub issues, sorting bug reports, cleaning up stale tickets, or detecting duplicate issues. Args: 'all' to analyze all, issue numbers to focus (e.g. '42 57'), 'en'/'fr' for language, no arg = audit only.
defect
A command for registering a software defect, meaning behavior that does not work as intended, and creating a task to fix it. The defect and its fix task receive tracked IDs and are stored in the project's backlog and task folders.