Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/achreftlili/code-index/docsnpx skills add achreftlili/code-index --skill docsgit clone --depth 1 https://github.com/achreftlili/code-indexWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00056 | $0.00663 |
| Opus 5 | $0.00028 | $0.00331 |
| Sonnet 5 | $0.00011 | $0.00133 |
| Haiku 4.5 | $0.00006 | $0.00066 |
Grade A, and why
code-search scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to code-search — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 64 lines — stays where its author put it; the contents beside it link to each section on GitHub.
code-search
You have access to a pre-built code index over this repo, exposed as MCP tools.
Default to the index for navigation. Only Read after you know the exact path
and line range.
Routing decision tree
| You have... | Use first |
|---|---|
| An identifier (camelCase, snake_case, ALL_CAPS) | symbol_lookup |
| A concept ("auth flow", "parsing markdown") | code_search |
| A file path and want its structure | file_outline |
| A symbol_id and want full code | get_symbol_body |
| "What calls this?" | callers |
| "What does this depend on?" | callees |
| "Who imports this file?" | dependents |
| "What does this file import?" | dependencies |
Composition recipes
Trace a feature end-to-end
code_search "<feature concept>"→ top hits.- For the most promising hit,
callersto find entry points. - For each entry point,
calleesto map the call graph. get_symbol_bodyonly on the symbols you actually need to understand.
Plan a refactor / assess blast radius
symbol_lookupthe function/class.callers symbol_id depth=2for transitive impact.dependents pathfor files importing the module.
Onboard to a new module
dependencies path→ upstream modules the file leans on.file_outline path→ structure.code_searchonly if you need a particular concept.
Anti-patterns
- Don't
Readbefore searching. Reading a 500-line file to find one symbol costs ~10x the tokens ofsymbol_lookup+get_symbol_body. - Don't
Grepfor an identifier. Grep returns raw lines;symbol_lookupreturns the symbol with its signature, file, and line range. - Don't read more than ~50 lines of a found chunk. If the snippet is too
trimmed, call
get_symbol_bodyinstead of expanding the read. - Don't ask the index to refresh itself. A
PostToolUsehook reindexes onEdit/Write/MultiEdit. The watcher catches IDE-side edits.
Staleness recovery
If a result's line numbers don't match the file you then Read (e.g. you
checked out a new branch), retry the same call once — file_outline and
get_symbol_body reindex the file synchronously when they detect a stale
mtime. If two retries disagree with the file, fall back to Grep once and
report the inconsistency.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 64 lines · 56 tokens per session scan A 0713133cb3c5
code-search is a skill published in the GitHub repository achreftlili/code-index (1 stars, last pushed 3mo ago), licensed MIT. It adds 56 tokens to every session and 663 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to code-search, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…