Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add Randroids-Dojo/skills/plugin install vibekitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/randroids-dojo/skills/vibekit-add)<a href="https://agentmods.dev/commands/randroids-dojo/skills/vibekit-add"><img src="https://agentmods.dev/badge/commands/randroids-dojo/skills/vibekit-add/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/randroids-dojo/skills/vibekit-add"><img src="https://agentmods.dev/badge/commands/randroids-dojo/skills/vibekit-add.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00014 | $0.00532 |
| Opus 5 | $0.00007 | $0.00266 |
| Sonnet 5 | $0.00003 | $0.00106 |
| Haiku 4.5 | $0.00001 | $0.00053 |
Grade A, and why
vibekit-add scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/vibekit add
Add @randroids-dojo/vibekit as a github: tag-pinned dependency in the current repo's package.json, and print the matching docs/DEPENDENCY_LEDGER.md entry.
When to use
In a project that consumes the VibeKit shared library and does NOT already have it pinned. After running this command, run /vibekit cookbook <module> for the wire-up patterns of any module the project uses.
How to invoke
bash ${CLAUDE_PLUGIN_ROOT}/scripts/add.sh [tag]
tag defaults to the latest published tag (resolved via gh api repos/Randroids-Dojo/VibeKit/releases/latest). Pass an explicit tag like v0.1.4 to pin to a specific release.
What the script does
- Confirms the repo has a
package.json. Aborts with a hint if not. - Reads the current
@randroids-dojo/vibekitpin (if any). If already present and equal to the target tag, prints "already up to date" and exits. - Resolves the target tag (passed argument or latest from GitHub).
- Edits
package.jsonto setdependencies["@randroids-dojo/vibekit"]togithub:Randroids-Dojo/VibeKit#<tag>. Creates the dependencies block if missing. - Runs the project's lockfile-refresh command. Picks
pnpm install,npm install, oryarn installbased on which lockfile is present. Skipped with--no-install. - Prints the boilerplate
DEPENDENCY_LEDGER.mdentry to paste intodocs/DEPENDENCY_LEDGER.md(or whichever case the project uses; FrackingAsteroids usesDocs/). The script does NOT modify the ledger directly to avoid clobbering project-specific text in already-existing entries. - Prints next steps: run
pnpm type-checkand any relevant tests; the kit's./servermodules are Node-only (do not import them from client code).
Output
A concise summary: target tag, package.json bump confirmation, install command run, and the ledger-entry boilerplate. The user pastes the ledger entry into their project's spiral ledger themselves.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago Changed · +6 lines · +14 tokens per session 34ac09d83a16
- 9d ago First seen · 30 lines · 0 tokens per session scan A ecf96f90fbd1
vibekit-add is a command published in the GitHub repository Randroids-Dojo/skills (46 stars, last pushed 9d ago), licensed MIT. It adds 14 tokens to every session and 532 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
specify
Create or update the feature specification from a natural language feature description.
analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
converge
Assess the current codebase against the feature's spec, plan, and tasks, then append any remaining unbuilt work as new tasks to tasks.md so implement can complete it.
implement
Execute the implementation plan by processing and executing all tasks defined in tasks.md.