Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/xcodethink/open-claude-code-skills/lessongit clone --depth 1 https://github.com/xcodethink/open-claude-code-skillsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00036 | $0.00481 |
| Opus 5 | $0.00018 | $0.00241 |
| Sonnet 5 | $0.00007 | $0.00096 |
| Haiku 4.5 | $0.00004 | $0.00048 |
Grade A, and why
lesson scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
经验沉淀
用户刚刚解决了一个 bug 或者学到了一个经验。按以下步骤将其沉淀到记忆系统。
1. 总结刚才发生的事
简短总结:
- 出现了什么问题
- 根本原因是什么
- 怎么解决的
- 对未来有什么提示
2. 提取两个版本
项目特定版本(细节):
- 包含具体的文件路径、错误堆栈、配置值
- 写到当前项目的 lessons.md
- 用于该项目内部排错
通用版本(提炼):
- 去掉所有项目特定信息(项目名、域名、API key、project ID、URL、IP、文件路径)
- 只保留模式、原理、避坑思路
- 写到 global wing 的踩坑记录
- 用于跨项目防错
3. 调用 memory_lesson MCP 工具
参数:
project_wing: 当前项目 wing 名称(小写下划线)title: 简短标题specific_version: 项目特定版本general_version: 通用版本(必须去敏感)
4. 验证去敏感
提交前自检通用版本:
- 不含任何 *.projectc.io 之类的具体域名
- 不含 *-prod 之类的 GCP project ID
- 不含 IP 地址
- 不含 secret 名称(如 STRIPE_WEBHOOK_SECRET_projectd)
- 不含项目名
如果有任何一项,重新提炼。
5. 给用户确认
向用户展示两个版本:
项目特定版(写入 [当前项目]/lessons.md):
[内容]
通用版(写入 global 踩坑记录):
[内容]
确认保存吗?
得到确认后再调用 memory_lesson。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 64 lines · 36 tokens per session scan A 0d512bf88305
lesson is a command published in the GitHub repository xcodethink/open-claude-code-skills (2 stars, last pushed 27d ago), licensed MIT. It adds 36 tokens to every session and 481 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
go-test
Go TDD workflow with table-driven tests.
go-review
Go code review for idiomatic patterns.
review-branch
Review the current branch's diff against base by dispatching atomic-reviewer. No orchestration loop, no spec required — pre-flight before /commit pr or /commit merge.
handoff
Generate or load a session handoff. Usage: /handoff [create|resume].
example-only
This command documents how to dispatch. Example only.
test
Run all PandaFilter verification steps in order. Stop and report on first failure. This is the required pre-commit gate.