Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add thedavidweng/skillsnpx agentmods add plugins/thedavidweng/skills/skillsgit clone --depth 1 https://github.com/thedavidweng/skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/thedavidweng/skills/skills)<a href="https://agentmods.dev/plugins/thedavidweng/skills/skills"><img src="https://agentmods.dev/badge/plugins/thedavidweng/skills/skills.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
david-skills scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "david-skills",
"skills": [
"./maintenance/roast-my-computer",
"./maintenance/skill-repo-maintenance",
"./maintenance/stale-docs-cleanup",
"./content-ops/youtube-content-ops",
"./code-review/entropy-reduction",
"./code-review/go-production-review",
"./web-dev/aeo-audit",
"./document-generation/cli-invoice",
"./document-generation/cover-letter",
"./document-generation/json-resume",
"./writing/david-weng-writing-style",
"./wiki/wiki-audit",
"./wiki/wiki-core",
"./wiki/wiki-inline-link-audit",
"./wiki/wiki-inline-linking",
"./wiki/wiki-link-audit",
"./wiki/wiki-quartz-publish",
"./wiki/wiki-slug-rename",
"./wiki/wiki-source-document-ingest",
"./wiki/wiki-source-integration",
"./wiki/wiki-sources-integrity",
"./wiki/wiki-vcf-import"
]
}
What it installs
The manifest is a name and a version. 22 skills travel with it, and installing the plugin installs all of them — 1,660 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill aeo-audit A 59 tokens
- Skill wiki-core A 64 tokens
- Skill wiki-inline-link-audit A 63 tokens
- Skill wiki-quartz-publish A 74 tokens
- Skill roast-my-computer A 78 tokens
- Skill wiki-audit A 66 tokens
- Skill cover-letter A 66 tokens
- Skill json-resume A 60 tokens
- Skill cli-invoice A 70 tokens
- Skill go-production-review A 109 tokens
- Skill wiki-link-audit A 59 tokens
- Skill wiki-vcf-import A 70 tokens
- Skill stale-docs-cleanup A 93 tokens
- Skill wiki-slug-rename A 86 tokens
- Skill wiki-source-document-ingest A 78 tokens
- Skill wiki-sources-integrity A 70 tokens
- Skill wiki-inline-linking A 80 tokens
- Skill youtube-content-ops A 40 tokens
- Skill david-weng-writing-style A 134 tokens
- Skill entropy-reduction A 85 tokens
- Skill wiki-source-integration A 59 tokens
- Skill skill-repo-maintenance C 97 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 28 lines scan A 5e9f8d6e8360
david-skills is a plugin published in the GitHub repository thedavidweng/skills (11 stars, last pushed 15d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
@tekmidian/pai
Personal AI Infrastructure — persistent memory, session continuity, and knowledge graph for Claude Code.
claude-mega-brain
OKF-powered knowledge context for Claude Code — injects your project knowledge base at every session.
tree-ring-memory
Local-first memory lifecycle, project bootstrap, and receipt-backed harness guidance for Claude Code using Tree Ring Memory v0.15+.
vault-template
Personal Knowledge Management system for Obsidian with AI-powered workflows, goal tracking, and productivity coaching.
ctx
Persistent memory for Claude Code agents. Stores decisions, patterns, and knowledge in a structured graph database that persists across sessions.
claude-bestpractice
Enforcement, memory and parallel-session coordination for solo founders running several Claude Code sessions on one repository.