Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/5uck1ess/devkit/setup-rulesnpx skills add 5uck1ess/devkit --skill setup-rulesgit clone --depth 1 https://github.com/5uck1ess/devkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00099 | $0.00548 |
| Opus 5 | $0.00049 | $0.00274 |
| Sonnet 5 | $0.00020 | $0.00110 |
| Haiku 4.5 | $0.00010 | $0.00055 |
Grade A, and why
setup-rules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Setup Coding Rules
Install language-specific coding rules to ~/.claude/rules/. These auto-activate when Claude reads matching files and complement devkit's hooks — rules guide how to write, hooks catch what you missed. Non-Claude hosts do not read ~/.claude/rules/; use AGENTS.md and the files in resources/rules/ as project guidance.
What it does
Copies rule files from this plugin's resources/rules/ to ~/.claude/rules/. Existing files are overwritten — if the user has customized rules, warn them before overwriting. CLAUDE_PLUGIN_ROOT is set automatically by the Claude Code plugin runtime.
Steps
- Verify plugin context and create the rules directory:
if [ -z "${CLAUDE_PLUGIN_ROOT:-}" ]; then
echo "ERROR: CLAUDE_PLUGIN_ROOT is not set. Run this as /devkit:setup-rules." >&2
exit 1
fi
mkdir -p ~/.claude/rules
- Check for existing customized rules — warn before overwriting:
If any files in ~/.claude/rules/ differ from the plugin versions, tell the user which files will be overwritten and ask for confirmation before proceeding.
- Copy each rule file from the plugin:
cp "${CLAUDE_PLUGIN_ROOT}/resources/rules/go.md" ~/.claude/rules/go.md
cp "${CLAUDE_PLUGIN_ROOT}/resources/rules/typescript.md" ~/.claude/rules/typescript.md
cp "${CLAUDE_PLUGIN_ROOT}/resources/rules/python.md" ~/.claude/rules/python.md
cp "${CLAUDE_PLUGIN_ROOT}/resources/rules/rust.md" ~/.claude/rules/rust.md
cp "${CLAUDE_PLUGIN_ROOT}/resources/rules/shell.md" ~/.claude/rules/shell.md
- Confirm installation:
echo "Installed rules:" && ls ~/.claude/rules/*.md
Report which files were installed.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 48 lines · 99 tokens per session scan A e6d525b45611
setup-rules is a skill published in the GitHub repository 5uck1ess/devkit (5 stars, last pushed 14d ago), licensed MIT. It adds 99 tokens to every session and 548 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
dynamic-workflows
Ultracode / Max-Parallel mode — dynamic workflows fan work out across tens–hundreds of adversarially-verified parallel subagents for large, decomposable jobs (codebase-wide audits, big migrations, cross-checked research). Opt-in; higher token spend.
agent-teams
Experimental Agent Teams orchestration — run CCGodMode agents as parallel teammates with SharedTaskList coordination (requires CLAUDECODEEXPERIMENTALAGENTTEAMS=1).
cost-efficiency
Smart Routing — the DEFAULT CCGodMode routing policy. Risk-based, minimal-agent paths that preserve required safety gates for the changed scope.
quality-gates
Parallel quality gate orchestration — @validator and @tester run simultaneously after @builder, with mandatory decision matrix for pass/fail routing.
sprint-planning
Plan-first orchestration (ADR-004): comprehensive PLAN.md, sprint files with write-scope ownership, preflight checks, serialized integration, and the release sprint. Use for any non-trivial or multi-part request BEFORE dispatching agents.
workflows
CCGodMode Full-Gates workflow definitions — used for high-risk work and when Smart Routing escalates. Default routing is Smart Routing (skills/cost-efficiency/).