Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/product-on-purpose/agent-skills-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/product-on-purpose/agent-skills-toolkit/agent-skills-toolkit)<a href="https://agentmods.dev/plugins/product-on-purpose/agent-skills-toolkit/agent-skills-toolkit"><img src="https://agentmods.dev/badge/plugins/product-on-purpose/agent-skills-toolkit/agent-skills-toolkit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/product-on-purpose/agent-skills-toolkit/agent-skills-toolkit"><img src="https://agentmods.dev/badge/plugins/product-on-purpose/agent-skills-toolkit/agent-skills-toolkit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
agent-skills-toolkit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "agent-skills-toolkit",
"version": "1.18.0",
"description": "Toolkit and Standard for authoring, validating, governing, and scaling cross-agent skill libraries (Claude Code and Codex) to a tiered Bronze/Silver/Gold quality bar. Use when building or grading agent skill plugins, when emitting components for multiple agents, or when adopting the Advanced Skill Library Standard.",
"license": "Apache-2.0",
"author": {
"name": "product-on-purpose"
},
"homepage": "https://github.com/product-on-purpose/agent-skills-toolkit",
"repository": "https://github.com/product-on-purpose/agent-skills-toolkit",
"keywords": [
"agent-skills",
"skills",
"claude-code",
"codex",
"plugin",
"standard"
]
}
What it installs
The manifest is a name and a version. 27 skills, 2 commands, 7 agents, 1 hook, 1 plugin travel with it, and installing the plugin installs all of them — 2,078 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill askit-capability-gap-analysis A 99 tokens
- Skill askit-capability-whats-new A 88 tokens
- Skill askit-standards-watch A 75 tokens
- Skill askit-build-docs A 85 tokens
- Skill askit-build-skill A 49 tokens
- Skill askit-evaluate A 72 tokens
- Skill askit-init-plugin A 53 tokens
- Skill askit-build-hook A 60 tokens
- Skill askit-build-subagent A 59 tokens
- Skill askit-capability-advisor A 69 tokens
- Skill askit-migrate A 73 tokens
- Skill askit-backlog A 58 tokens
- Skill askit-build-agents-md A 64 tokens
- Skill askit-build-chain-contract A 61 tokens
- Skill askit-build-command A 54 tokens
- Skill askit-build-output-style A 53 tokens
- Skill askit-build-samples A 56 tokens
- Skill askit-build-settings A 45 tokens
- Skill askit-build-workflow A 67 tokens
- Skill askit-decision A 64 tokens
- Skill askit-init-marketplace A 53 tokens
- Skill askit-release A 66 tokens
- Skill askit-build-statusline A 41 tokens
- Skill askit-deprecate A 51 tokens
- Skill askit-template-manager A 45 tokens
- Skill REPLACE-with-kebab-case-name-matching-this-directory A 44 tokens
- Skill askit-build-mcp B 62 tokens
- Command askit-build-skill A 35 tokens
- Command askit-evaluate A 36 tokens
- Agent askit-quality-grader A 60 tokens
- Agent askit-reviewer A 50 tokens
- Agent askit-explorer A 45 tokens
- Agent askit-file-ops A 50 tokens
- Agent askit-file-search A 53 tokens
- Agent askit-skill-author A 41 tokens
- Agent askit-evaluator A 42 tokens
- Hook PreToolUse A not measured
- Plugin probe-collision-a 1 inside A not measured
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago Changed 8b89a043b6d3
- 8d ago First seen · 20 lines scan A d9a125ef46aa
agent-skills-toolkit is a plugin published in the GitHub repository product-on-purpose/agent-skills-toolkit (2 stars, last pushed 2d ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
paperthin
Low-level agentic design patterns. Turning old engineering wisdom into reflexes your agent reaches for on its own—on any agent.
jaiskills
Orchestration (insistir, constatar, remoto), prompting (metaprompt), knowledge compounding, file-based TODOs, an illustrated Claude Agent SDK wizard, and OpenAI tooling (askcodex, image-to-frontend) as one Claude Code plugin.
context-firewall
Context Firewall: use sub-agents to preprocess large inputs with evidence contracts and low-cost verification.
devloop
Iterate until ready to merge: create branch, fix, commit, open PR, wait for AI review, apply feedback, repeat.
sync-claude-skills-to-codex
Sync Claude Code skills to Codex CLI via symlinks. Share your skill library between both AI coding assistants.
meta-harness
Intelligent harness creator for Claude Code. Analyzes any project, selects optimal patterns from a curated library of proven architectures (ECC, gstack, OmO, OMC), and generates tailored agents, skills, hooks, and rules — while auto-checking official features to avoid duplication.