Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add mmornati/leanproxy-mcp --skill bmad-loop-sweepgit clone --depth 1 https://github.com/mmornati/leanproxy-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mmornati/leanproxy-mcp/bmad-loop-sweep)<a href="https://agentmods.dev/skills/mmornati/leanproxy-mcp/bmad-loop-sweep"><img src="https://agentmods.dev/badge/skills/mmornati/leanproxy-mcp/bmad-loop-sweep.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00082 | $0.01083 |
| Opus 5 | $0.00041 | $0.00541 |
| Sonnet 5 | $0.00016 | $0.00217 |
| Haiku 4.5 | $0.00008 | $0.00108 |
Grade A, and why
bmad-loop-sweep scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 93 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Deferred-Work Sweep Triage
Goal: Classify every open entry in {implementation_artifacts}/deferred-work.md
into a machine-readable triage plan the orchestrator can validate and execute.
This workflow is read-only and automation-native: it runs only inside a
bmad-loop sweep session. You never edit the ledger, never edit code, never
ask questions. Your sole output is the result file. (The one exception is
migration mode, which edits exactly one file — the ledger.)
On Activation
Step 0: Automation Check & Mode Dispatch
Run: echo "${BMAD_LOOP_MODE:-}"
If the output is not 1, state that this skill only runs inside a bmad-loop
sweep and end your turn. Otherwise read ./automation-mode.md fully — its
rules and result schema govern this entire run.
If the invocation carries --migrate <manifest-path>, this is a migration
session, not triage: read ./migration-mode.md and follow it instead of
Steps 1–4 below.
Step 1: Locate the ledger
Read {project-root}/_bmad/bmm/config.yaml to resolve implementation_artifacts,
then read {implementation_artifacts}/deferred-work.md in full. Open entries
are ### DW-<n>: blocks whose status: line is open. If the ledger is
missing or unreadable, escalate CRITICAL (type: missing-ledger) per
automation-mode.md and end your turn.
If the invocation carries --feedback <path>, read that file FIRST — it lists
the deterministic validation errors your previous attempt's result.json failed
on. Fix exactly those defects in this attempt's output.
Step 2: Verify every open entry against the code
Ledger statuses are known-unreliable: entries are often resolved by later work but never marked done. For EACH open entry:
- Read its
location:(file/component) in the current tree. - Check whether the described issue still exists — read the code, grep for
the symptom, check
git logfor commits that touched the area since the entry'sorigin:date. - Record concrete evidence either way. "Probably fixed" is not evidence; a file:line or commit hash is.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 93 lines · 82 tokens per session scan A 26dee286d59b
bmad-loop-sweep is a skill published in the GitHub repository mmornati/leanproxy-mcp (5 stars, last pushed 7d ago), licensed MIT. It adds 82 tokens to every session and 1,083 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
notion-cli
Work with Notion from the terminal using the notion CLI. Use when the user needs to read, create, update, query, or manage Notion pages, databases, blocks, comments, users, or files programmatically. Covers the entire Notion API with 50+ commands. Triggers: Notion workspace automation, database queries, page creation…
lx
Codebase exploration tool that reads many files or whole directories in a single call, with per-file headers, glob include/exclude filters, function/type skeleton extraction (signatures only, no bodies), and head/tail line slicing.
taskctl
Run project tasks and pipelines with taskctl. Use when the project contains tasks.yaml or taskctl.yaml, or when asked to build/test/deploy via project task definitions.
slack-tools
Slack workspace management and automation specialist.
Send WhatsApp messages, list chats, and search history via wacli (local CLI backed by a synced store at /.wacli). Unpaired? Run the guided connect flow (scripts/guidedconnect.py) from chat — no terminal needed.
usage-audit
Audit a Claude Code setup for token waste and context bloat. Checks MCP servers, CLAUDE.md, skills, and settings against bloat filters. Triggers on: "audit my context", "usage audit", "token audit", "context bloat". NOT for codebase audits.