control-cli

control-cli is a skill for Codex from OutlineDriven/outline-driven-development. It costs 42 tokens per session (736 once invoked), scanned A, original, Apache-2.0.

A testing aid for reproducing, measuring, or checking command-line and terminal user-interface behavior. It records a repeatable session or performance profile and cleans up the temporary session afterward.

In plain words
What is it for?
Use it to exercise a supplied CLI or TUI command, capture its output, profile it, and verify a stated scenario.
Why use it?
It helps turn interactive terminal behavior into evidence that can be reviewed and compared.

Skill for Codex

Written for Codex: agents/openai.yaml present.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/outlinedriven/outline-driven-development/control-cli
Any agent
npx skills add OutlineDriven/outline-driven-development --skill control-cli
Clone the repo
git clone --depth 1 https://github.com/OutlineDriven/outline-driven-development

Made for: Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for control-cli

README.md
[![agentmods](https://agentmods.dev/badge/skills/outlinedriven/outline-driven-development/control-cli.svg)](https://agentmods.dev/skills/outlinedriven/outline-driven-development/control-cli)
Your own site
<a href="https://agentmods.dev/skills/outlinedriven/outline-driven-development/control-cli"><img src="https://agentmods.dev/badge/skills/outlinedriven/outline-driven-development/control-cli.svg" alt="Measured on agentmods" height="20"></a>
Per session 42 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 736 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00042 $0.00736
Opus 5 $0.00021 $0.00368
Sonnet 5 $0.00008 $0.00147
Haiku 4.5 $0.00004 $0.00074

Measured today against content hash d869a3ad3d69, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

control-cli scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

.devin/skills/control-cli/SKILL.md · 41 lines

How it starts

The opening of the file, as written. The whole thing — 41 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Control CLI

Contract

Field Bound contract
Trigger Reproduce, profile, or verify CLI/TUI behavior.
Authority Reversible local: writes only temporary transcript or profile artifacts under a system temp directory and may spawn local PTY sessions; rollback is terminating the PTY process and removing its runtime scratch. No remote mutation. No source or VCS mutation. No credential or paid mutation.
Side effect Runs temporary terminal sessions and captures evidence.
Done A deterministic transcript or profile proof artifact exists and the live PTY session is terminated with its runtime scratch removed.

Inputs

  • The CLI/TUI binary or command to exercise (must be supplied).
  • The exact reproduction steps, profile target, or verification scenario (must be supplied).
  • Optional: expected output, timeout, and environment variables.

Procedure

  1. Create a fresh session directory under the system temp path for the captured artifact and PTY/tmux runtime scratch. Record the directory for cleanup. Done when: the session directory is created and recorded.
  2. Spawn the target CLI/TUI under a PTY, or a tmux session attached to a PTY, so interactive behavior is observable. Apply one action per observation: send one input, then capture the full terminal render before sending the next. Done when: the PTY or tmux session is spawned and interactive behavior is observable.
  3. For reproduction: drive the supplied steps in order, appending the terminal state after each action to the transcript artifact. Done when: every step is driven in order and the transcript artifact captures the terminal state after each action.
  4. For profiling: run the target under the chosen profiler, capturing timing or allocation output into the profile artifact. Done when: the profile artifact captures timing or allocation output.
  5. For verification: exercise the scenario, compare the observed output against the expected output when supplied, and record the pass or fail classification in the transcript artifact. Done when: the pass or fail classification is recorded in the transcript artifact.
  6. Terminate the PTY process, or detach and kill the tmux session. Done when: the PTY process or tmux session is terminated.
  7. Remove the PTY/tmux runtime scratch (pipes and sockets); the captured transcript or profile artifact file remains as the retained proof. Done when: runtime scratch is removed and the artifact file remains.

Read the full file on GitHub · 41 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today Changed d869a3ad3d69
  2. 2d ago First seen · 41 lines · 42 tokens per session scan A 66f4d4cd158a

Subscribe to this mod's changes

control-cli is a skill published in the GitHub repository OutlineDriven/outline-driven-development (52 stars, last pushed today), licensed Apache-2.0. It adds 42 tokens to every session and 736 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

strict-validation-setup

Use when a user invokes a strict-mode validation or verifiable-goals loop setup. Bootstraps strict-mode tooling and per-task GOALS.md scaffolding so an agentic loop can self-verify. Don't use for remote, credential, publish, deploy, or irreversible changes.

OutlineDriven/odin-claude-plugin · 61 tokens

validation-first-driven

Use when building protocols, workflows, concurrent systems, or lifecycle-heavy state that needs explicit states, transitions, and temporal properties. Defines the state machine, encodes invariants in types, and for high-risk designs runs a TLA+ or Alloy model checker. Not for encoding domain models in types — use…

OutlineDriven/odin-claude-plugin · 78 tokens

testing-handbook-generator

Use when the user asks to discover, generate, refresh, or validate skills from the Trail of Bits Testing Handbook or appsec.guide. Not for tasks that require source or remote-system changes.

OutlineDriven/odin-claude-plugin · 44 tokens

ios-device-qa

Use when the user runs /ios-device-qa to drive a real iPhone over USB through a debug-bridge daemon and return a device QA report with verified interactions. Do not use for remote, credential, publish, deploy, or irreversible changes.

OutlineDriven/odin-claude-plugin · 55 tokens

property-test-review

Use when reviewing existing property tests for coverage and defects. Reports tautological, vacuous, assertion-free, reimplemented, weak, or over-filtered tests with evidence, severity, and strongest replacement property. Not for generating tests — use property-test-authoring.

OutlineDriven/odin-claude-plugin · 56 tokens

exhaustive

Use when asked to prove coverage, find missing cases, or enumerate a state, decision, requirement, or behavior space. Enumerates every cell as covered, gap, or deferred with an executed check per cell, and emits a coverage manifest with a tally. Not for round-based questioning — use askme; not for testing one property…

OutlineDriven/odin-claude-plugin · 77 tokens