Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/agent-rig/rig/rig-spikenpx skills add agent-rig/rig --skill rig-spikegit clone --depth 1 https://github.com/agent-rig/rigWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00114 | $0.02263 |
| Opus 5 | $0.00057 | $0.01131 |
| Sonnet 5 | $0.00023 | $0.00453 |
| Haiku 4.5 | $0.00011 | $0.00226 |
Grade A, and why
rig-spike scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 180 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Research Spike
A spike is a time-boxed investigation whose deliverable is knowledge, not shipped code. You answer a specific question, surface the trade-offs, and recommend a path — so the team can plan implementation with confidence instead of guessing.
Use a spike when the work is uncertain: feasibility is unknown, there are multiple viable approaches, an unfamiliar API/library is in play, or scope can't be estimated until something is prototyped. If the path is already clear and it's just work to be done, skip the spike and go straight to implementation planning.
Configuration
Reads .rig/config.json:
sourceScope[0]— the default code scope explorers map first (default:src).tracker.provider—linear|github|none(default:none). Whennone, skip all tracking-ticket steps and deliver the writeup in chat only. When set, optionally create aSpike:tracking ticket and post findings back to it.tracker.team/tracker.project— where a Linear tracking ticket is filed, when the provider islinear.agents.architect— the project's name for the canonicalarchitectrole (default:architect).ExploreandPlanare Claude Code built-ins and are used as-is.style.guideFile— the writing style for the findings writeup (default:.claude/STYLE.md).
If the file is absent, use the defaults above (treat the tracker as
none) and note you're running unconfigured.
Core rules of a spike
- Time-box it. Decide the budget up front (default: half a day / ~4h of effort). The goal is enough signal to decide, not a complete build.
- The output is a writeup, not a PR. Any code is throwaway prototype used to learn — it does not get merged. Mark prototype branches clearly and don't open a PR-to-trunk from them.
- End with a recommendation and concrete next steps (usually: tickets to create, or a "don't do this" with the reason).
- Be honest about what you couldn't verify. Lead with the verdict, back
it with evidence, and mark anything you can't support with
file:line(or a run/probe result) asunverifiable— never pad a recommendation with confidence you didn't earn. - Pin the codebase state. Record the commit SHA you investigated against
(
git rev-parse HEAD) plus the date, so the recommendation is reproducible and its staleness is obvious once the trunk moves on.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 180 lines · 114 tokens per session scan A 1dac3c664968
rig-spike is a skill published in the GitHub repository agent-rig/rig (2 stars, last pushed 15d ago), licensed MIT. It adds 114 tokens to every session and 2,263 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
audit-onboarding-proposal
Independently audit a brownfield onboarding transcript, operational map, or exact proposed documentation patch before application. Use when a fresh reviewer must verify an $onboard-repository first pass, distinguish environment-caused Unknowns from reasoning defects, score its safety and evidence gates, or run a…
improve-harness
Run one explicitly authorized, evidence-backed improvement to a repository's agent guidance, tools, runbooks, or validation. Use only when the user invokes $improve-harness or explicitly asks to improve the Harness after observed reusable agent friction. Do not use for ordinary product changes, speculative cleanup…
ai-elements
Build AI chat interfaces using ai-elements components — conversations, messages, tool displays, prompt inputs, and more. Use when the user wants to build a chatbot, AI assistant UI, or any AI-powered chat interface.
red-team-adversarial
Adversarial security and resilience analysis — auto-triggered during /review and /test based on task classification. Provides attack surface analysis, boundary testing, auth bypass attempts, dependency chain attacks, and Beast Mode stress testing.
product-decision-agent
中文产品决策 Agent。用于中国大陆互联网产品、运营、增长、商业化、数据、项目推进和组织协作场景:产品规划、需求分析、PRD、需求优先级、排期、版本规划、Roadmap、MVP、灰度、上线、迭代、增长停滞、拉新、投放、渠道、裂变、CAC、LTV、ROI、留存、转化、DAU/MAU、GMV、漏斗、社区运营、内容供给、创作者、用户运营、活动运营、私域、会员、定价、指标异常、数据口径、埋点、A/B…
architecture-review
Use for clean architecture, modular monoliths, hexagonal boundaries, service boundaries, data flow, dependency direction, ADRs, or large feature planning.