Borrowing it
Nothing to install: this file belongs to 8ddieHu0314/Skill-Lab. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/8ddieHu0314/Skill-Lab/main/CLAUDE.mdgit clone --depth 1 https://github.com/8ddieHu0314/Skill-LabWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/8ddiehu0314/skill-lab/claude-md)<a href="https://agentmods.dev/instructions/8ddiehu0314/skill-lab/claude-md"><img src="https://agentmods.dev/badge/instructions/8ddiehu0314/skill-lab/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.03027 | $0.03027 |
| Opus 5 | $0.01514 | $0.01514 |
| Sonnet 5 | $0.00605 | $0.00605 |
| Haiku 4.5 | $0.00303 | $0.00303 |
Grade A, and why
Skill-Lab CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 157 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
Python CLI tool (v0.7.0) that evaluates agent skills (SKILL.md files) via static analysis, LLM-as-judge quality review, trigger testing, and LLM-based test generation. Produces a 0-100 static score across 37 checks (structure:13, naming:3, description:3, content:13, security:5) / 5 dimensions, plus a 0-100 LLM judge score across 9 criteria / 2 axes (Activation Quality + Instruction Quality).
Attribution
NEVER include Co-Authored-By lines, "Generated with Claude Code", or any AI co-authorship attribution in commit messages, PR descriptions, PR reviews, or any other output.
Naming
| Name | Usage |
|---|---|
| Skill-Lab | GitHub repo / project name |
| skill-lab | PyPI package (pip install skill-lab) |
| sklab | CLI command (sklab evaluate ./my-skill) |
Docs
| Document | Contents |
|---|---|
| docs/ARCHITECTURE.md | Tech stack, data flow, CLI commands, check systems, design patterns |
| docs/IMPLEMENTATION_PLAN.md | Vision, roadmap, design decisions |
| docs/SECURITY.md | 5-layer security scan details |
| docs/PRIVACY.md | Telemetry & privacy policy |
| docs/DEV_STATS.md | Telemetry flow, SQLite schema, event types, CI detection |
| docs/versions/ | Per-version specs (v0.1.0–v1.0.0) |
After code changes: update ARCHITECTURE.md (modules/CLI) and the relevant docs/versions/vX.X.X.md.
ALWAYS READ THE DOCS BEFORE ACTIONING
Commands
pip install -e ".[dev]" # install with dev deps
sklab # auto-scan repo + getting started guide (no subcommand)
sklab evaluate ./my-skill # static analysis + LLM quality review (--optimize to chain into optimizer)
sklab evaluate --all # evaluate every skill in CWD (also: --repo for git root)
sklab check # quick pass/fail (exit 0/1, good for CI)
sklab info ./my-skill # metadata + token estimates
sklab prompt ./skill-a # export skill as XML prompt
sklab trigger # run trigger tests (requires Claude CLI, --provider local|docker)
sklab generate # generate trigger tests via LLM (multi-provider)
sklab optimize ./my-skill # LLM-powered SKILL.md optimization (multi-provider)
sklab stats # usage statistics
sklab setup # configure hooks for Claude Code/Cursor
sklab scan ./my-skill # security scan (BLOCK/SUS/ALLOW)
sklab list-checks # browse all checks (--spec-only, --suggestions-only)
pytest tests/ -v # run all tests
pytest tests/test_checks.py -v # run single test file
pytest tests/test_checks.py -k "keyword" -v # filter by keyword
mypy src/ # type check
ruff check src/ && ruff format src/
/verify # runs all of the above (pytest, mypy, ruff check, ruff format)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 157 lines · 3,027 tokens per session scan A 6beddc0df319
Skill-Lab CLAUDE.md is an instructions file published in the GitHub repository 8ddieHu0314/Skill-Lab (56 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 3,027 tokens to every session, about $0.0151 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.