Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/anoopsg/agent_rules/create-packagenpx skills add anoopsg/agent_rules --skill create-packagegit clone --depth 1 https://github.com/anoopsg/agent_rulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00054 | $0.01092 |
| Opus 5 | $0.00027 | $0.00546 |
| Sonnet 5 | $0.00011 | $0.00218 |
| Haiku 4.5 | $0.00005 | $0.00109 |
Grade A, and why
create-package scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 148 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Package Creation Skill
This skill defines the process for adding a new local package to the root
Dart pub workspace, following the pattern established by
packages/app_ui (UI kit) and packages/framework (foundation utilities).
1. When to Create a Package vs. a Feature/Infrastructure Domain
Create a new workspace package only when the code is genuinely reusable
outside the app itself, or needs a hard dependency boundary (e.g. it must
not depend on Flutter, or must not depend on other app code). If the code
is app-specific business logic, use create-feature or
create-infrastructure instead — most new work belongs in lib/src/, not
a new package.
2. Directory Structure
packages/<name>/
├── lib/
│ ├── <name>.dart # Public barrel — only export what's public API
│ └── src/
│ └── ... # Implementation, not exported directly
├── test/
│ └── ... # Mirrors lib/src/
├── analysis_options.yaml
└── pubspec.yaml
- Package name:
snake_case, matching the directory name. - Never import a package's
src/internals from outside the package — only the barrel file is the public contract.
3. pubspec.yaml
Use resolution: workspace (not a version constraint on the SDK
environment beyond what the app requires) so the package resolves against
the root workspace's single lockfile:
name: <name>
description: "<One-line description>"
version: 0.0.1
publish_to: 'none'
environment:
sdk: ^3.12.0
flutter: ">=3.44.0"
resolution: workspace
dependencies:
flutter:
sdk: flutter
dev_dependencies:
flutter_test:
sdk: flutter
very_good_analysis: ^10.2.0
- Only add
flutter:as a dependency if the package actually needs Flutter (widgets,Color, etc.). A pure-Dart package (like a data model or algorithm library) should omit it to keep the dependency surface minimal —frameworkincludes it today only becauseScaleBinding/ViewPropsneed Flutter types; don't treat that as a requirement. - If the package needs codegen (
build_runner+ a generator such asriverpod_generator,dart_mappable_builder, orchopper_generator), add both asdev_dependencies—melos run generatealready targets every package viapackageFilters: dependsOn: build_runner, so no script changes are needed. - Never add a dependency on another local package (
app_ui,framework, or the root app) unless it is a deliberate, one-directional layering decision —app_uiandframeworkdo not depend on each other today.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 148 lines · 54 tokens per session scan A 5af540768147
create-package is a skill published in the GitHub repository anoopsg/agent_rules (2 stars, last pushed 1mo ago), licensed MIT. It adds 54 tokens to every session and 1,092 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
spawn-session
新しい detached な Claude Code Remote Control セッションを Herdr 内に起動し、Claude モバイルアプリのセッション一覧に出す。生きている任意のセッションから(多くは iPhone の Remote Control 越しに)呼んで、別プロジェクトの新規セッションを Mac に触れず立ち上げる。Use when the user says 「新しいセッション立てて」「AAP のセッション開いて/立ち上げて」「contemplative のセッション作って」「spawn a (new) session」「launch a remote control session」「start a…
orca-emulator-android
Control an Android emulator / device from inside Orca using the orca CLI. Use for listing/booting AVDs, taps, swipes, typing, hardware buttons (incl. Back and Recents), rotation, app install/launch, runtime permissions, the accessibility tree, and logcat — driving a real adb-connected device or emulator.…
add-sample
Create a SamplesApp sample page with correct theming and attributes. Use when adding UI samples for controls.
mapping-to-snomed
Maps clinical concept spans extracted by OpenMed to SNOMED CT concepts through a USER-SUPPLIED terminology server (the user's own Ontoserver, Snowstorm, or UMLS/UTS), never a bundled vocabulary. Use when the user wants to code findings, disorders, procedures, body structures, or substances to SNOMED CT, run an ECL…
android-tombstone-symbolication
Symbolicate the .NET runtime frames in an Android tombstone file. Extracts BuildIds and PC offsets from the native backtrace, downloads debug symbols from the Microsoft symbol server, and runs llvm-symbolizer to produce function names with source file and line numbers. USE FOR triaging a .NET MAUI or Mono Android app…
auditing-subgroup-fairness
Audit an OpenMed NER or de-identification model for performance disparities across demographic subgroups (sex, age band, race/ethnicity when available) using openmed.eval.fairnessreport. Use when the user wants per-subgroup recall and leakage, wants to check whether de-identification under-protects a group, wants to…