Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/AHappyAtlas/ai-knowledge-centernpx agentmods add skills/ahappyatlas/ai-knowledge-center/aikc-open-source-releaseWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release)<a href="https://agentmods.dev/skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release"><img src="https://agentmods.dev/badge/skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release"><img src="https://agentmods.dev/badge/skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00495 |
| Opus 5 | $0.00000 | $0.00247 |
| Sonnet 5 | $0.00000 | $0.00099 |
| Haiku 4.5 | $0.00000 | $0.00049 |
Grade A, and why
aikc-open-source-release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AIKC Open-Source Release Skill
Use this skill when preparing AI Knowledge Center for a public GitHub or npm release, or when validating release readiness after package, CLI, security, community, or documentation changes.
Release Contract
- License, contribution guide, security policy, code of conduct, changelog, issue templates, and CI must be present before a first public release.
- Preserve local-first defaults:
127.0.0.1, repository-scoped MCP, allowlisted commands, and telemetry opt-out withAIKC_TELEMETRY_EXPORTER=none. - Release notes must include user-visible changes, upgrade notes, rollback version, validation evidence, and supported platforms.
- The published CLI must expose
aikc doctor --jsonandaikc context-pack --project <path> --task <task>as direct verification and context-routing entrypoints. - Never print or commit npm tokens,
.env.local, private project content, or user registry data.
Validation
Run from the package repository:
node ai-knowledge/scripts/doctor.cjs --json
node ai-knowledge/scripts/eval-workflow.cjs
node ai-knowledge/scripts/code-review.cjs
node ai-knowledge/scripts/knowledge-check.cjs
npm run typecheck
npm run lint
npm run build
npm pack --dry-run
npm run smoke:package
smoke:package packs the built package, installs it in a clean local temporary
directory and a temporary npm global prefix, initializes projects through both
install modes, and runs doctor plus context-pack. It must use an isolated
AIKC_HOME and remove its temporary package and state after completion.
Platform Boundary
- Local host: Windows, macOS, or Linux. The smoke script must handle the local npm launcher safely on each platform.
- Remote target: GitHub Actions runners on Windows, macOS, and Linux. CI must run the same package smoke test across that matrix.
- No remote shell, SSH, production deployment, or broadened network binding is part of release preparation.
Publish
Use docs/release-checklist.md for the human publish sequence. Publishing and
creating a GitHub Release require explicit maintainer authority; do not attempt
them merely because the checks pass.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 57 lines · 0 tokens per session scan A 4262c1c3aac8
aikc-open-source-release is a skill published in the GitHub repository AHappyAtlas/ai-knowledge-center (0 stars, last pushed 1mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 495 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
agentplane-release-and-packaging-operator
Use when preparing, validating, publishing, auditing, or recovering an Agentplane release, especially package build ordering, version parity, npm/GitHub/GHCR/external distribution publication, public install smoke tests, hosted publish evidence, or release CI failures.
checking-release-readiness
Records a ship, block, defer, or ship-with-risk decision that ties baseline, evidence status, residual risk, rollback, monitoring, and handoff together. Use when a packet, PR, release, dependency change, or agent-authority change approaches merge. Do not use early in development before evidence exists.
brpr
(devtools plugin) Create a branch, commit changes, push, and open a PR — or just commit+push+PR if already on a feature branch. Links related issues from GitHub or Linear based on project tracker config.
release
Automate the release process. Use when user says "cut a release", "new version", "bump version", "publish release", or anything about versioning and publishing.
release-deploy
Prepare a public open-source project for release and deploy it to a detected target. Use at a release or submission boundary to verify setup, docs, secrets, tests, lint, build, and licenses, then follow the target-specific deployment path. Runs expensive checks sequentially. Never publishes, tags, commits, pushes, or…
bump-version
Bump this repository's version across VERSION and the four plugin manifests, then commit it. Use when preparing a release or when a merge into main needs its version bump.