Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/luanpdd/kit-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/luanpdd/kit-mcp/golden-signals)<a href="https://agentmods.dev/commands/luanpdd/kit-mcp/golden-signals"><img src="https://agentmods.dev/badge/commands/luanpdd/kit-mcp/golden-signals/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/luanpdd/kit-mcp/golden-signals"><img src="https://agentmods.dev/badge/commands/luanpdd/kit-mcp/golden-signals.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00043 | $0.01671 |
| Opus 5 | $0.00022 | $0.00835 |
| Sonnet 5 | $0.00009 | $0.00334 |
| Haiku 4.5 | $0.00004 | $0.00167 |
Grade A, and why
golden-signals scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 143 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Cria/Atualiza:
- Patches OTel nos arquivos do
<target>(Latency + Traffic + Errors + Saturation) GOLDEN-SIGNALS.mdpor target com tabela de instrumentação aplicada (output do agent)
Após: os 4 signals estão instrumentados e o user pode rodar smoke local para verificar histogram/counter/gauge no backend OTel.
Flags:
--service <name>— nome canônico do serviço (default: deriva depackage.json#nameou diretório)--saturation <resource>— recurso de saturation (db_connection_pool|cache_memory|queue_depth|concurrency_limit|cpu_load|egress_bandwidth); se omitido, agent infere via heurística--runtime <node|deno|python>— runtime; se omitido, detecta viapackage.json/deno.json/pyproject.toml
Exemplos:
/golden-signals src/orders/handler.ts # 1 arquivo
/golden-signals supabase/functions/process-emails # 1 Edge Function
/golden-signals 38 # todos os arquivos modificados pela Phase 38
/golden-signals src/api --service orders-api --saturation db_connection_pool
Pré-requisito: OTel SDK pode estar ausente — agent flagga deps necessárias no output. Caller decide instalar.
1. Parsear argumentos
TARGET=$(echo "$ARGUMENTS" | awk '{print $1}')
SERVICE=$(echo "$ARGUMENTS" | grep -oE -- '--service [^ ]+' | awk '{print $2}')
SATURATION=$(echo "$ARGUMENTS" | grep -oE -- '--saturation [^ ]+' | awk '{print $2}')
RUNTIME=$(echo "$ARGUMENTS" | grep -oE -- '--runtime [^ ]+' | awk '{print $2}')
if [ -z "$TARGET" ]; then
echo "Uso: /golden-signals <target> [--service N] [--saturation R] [--runtime RT]"
echo "Exemplos:"
echo " /golden-signals src/orders/handler.ts"
echo " /golden-signals supabase/functions/process-emails"
echo " /golden-signals 38 # todos arquivos da Phase 38"
exit 1
fi
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 143 lines · 43 tokens per session scan A 917820482151
golden-signals is a command published in the GitHub repository luanpdd/kit-mcp (1 stars, last pushed 2d ago), licensed MIT. It adds 43 tokens to every session and 1,671 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other commands, from other repositories
init
Initialize configurations for Supabase local development.
http-service
Build, review or debug a Bun HTTP service. Loads the http-service skill, then works the task through its workflow.
start-10-1
A guided lesson on setting up clasp, a command-line tool for managing Google Apps Script projects, and connecting it to Google’s Apps Script API.
api-contract-review
Review an API contract (endpoints, request/response shapes, error codes, auth model) BEFORE implementation for naming consistency, versioning, pagination, idempotency, and alignment with existing endpoints. Distinct from review-hard (post-implementation risk) and repo-consistency-sweep (pattern matching on written…
build
Discover an AI Gateway's models and MCP tools, retrieve a credential, and integrate them into your app — call a model, connect MCP tools, or scaffold a runnable agent.
fastapi
FastAPI application design and implementation conventions. Use this skill when building, updating, or reviewing FastAPI services, routers, dependencies, request/response schemas, streaming endpoints, or API tests. Trigger on FastAPI-specific work such as path operation design, dependency injection, response models…