Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ArabelaTso/Skills-4-SE --skill rtl-property-inferencegit clone --depth 1 https://github.com/ArabelaTso/Skills-4-SEWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/arabelatso/skills-4-se/rtl-property-inference)<a href="https://agentmods.dev/skills/arabelatso/skills-4-se/rtl-property-inference"><img src="https://agentmods.dev/badge/skills/arabelatso/skills-4-se/rtl-property-inference/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/arabelatso/skills-4-se/rtl-property-inference"><img src="https://agentmods.dev/badge/skills/arabelatso/skills-4-se/rtl-property-inference.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00097 | $0.01924 |
| Opus 5 | $0.00048 | $0.00962 |
| Sonnet 5 | $0.00019 | $0.00385 |
| Haiku 4.5 | $0.00010 | $0.00192 |
Grade A, and why
rtl-property-inference scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 252 lines — stays where its author put it; the contents beside it link to each section on GitHub.
RTL Property Inference
Overview
This skill analyzes Verilog/SystemVerilog RTL code and automatically infers implicit correctness properties, generating formal SystemVerilog Assertions (SVA). The skill identifies common hardware patterns and generates appropriate safety, liveness, and fairness properties with clear explanations.
Workflow
Step 1: Parse and Understand RTL Structure
Analyze the input RTL code to extract key components:
-
Identify signals and their roles:
- Clock and reset signals
- Control signals (valid, ready, enable, grant, request)
- Data signals
- State variables (FSM states, counters, flags)
-
Recognize structural patterns:
- State machines (one-hot, binary encoded)
- Handshake protocols (valid-ready, req-ack)
- Pipelines (with/without stalls)
- FIFOs and buffers
- Arbiters and mutual exclusion logic
- Counters (saturating, wraparound)
- Memory interfaces
-
Extract clock/reset conventions:
- Clock signal name and edge (posedge/negedge)
- Reset signal name, polarity (active high/low), and type (sync/async)
- Reset values for state variables
Step 2: Identify Control-Flow Invariants
Systematically analyze the design for common invariant patterns:
-
Mutual Exclusion:
- Grant signals from arbiters
- Mutually exclusive enable signals
- One-hot state encodings
- Look for: Multiple signals that should never be active simultaneously
-
Valid-Ready Handshakes:
- Data stability during valid-without-ready
- Valid persistence until handshake completes
- No data loss (eventual completion)
- Look for: Pairs of valid/ready signals with associated data
-
Pipeline Ordering:
- Valid bit propagation through stages
- Data stability in pipeline stages
- Stall behavior (freezing pipeline state)
- Look for: Arrays of valid signals, stage indices, pipeline registers
-
Safety Properties (bad things never happen):
- Buffer overflow/underflow prevention
- Invalid state detection
- Address conflict prevention
- Counter bounds
- Look for: Boundary conditions, error states, conflict scenarios
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 252 lines · 97 tokens per session scan A 529d2618577c
rtl-property-inference is a skill published in the GitHub repository ArabelaTso/Skills-4-SE (252 stars, last pushed 21d ago), licensed Apache-2.0. It adds 97 tokens to every session and 1,924 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
opentrons-integration
Author, review, migrate, simulate, and troubleshoot official Opentrons Python Protocol API v2 protocols for Flex and OT-2 robots. Use for robot-specific liquid handling, deck and labware setup, pipettes, modules, runtime parameters, liquid classes, and Opentrons App analysis. Use pylabrobot instead when one workflow…
offensive-wifi-recon
Wi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspace mapping, hidden SSID discovery, BSSID/ESSID/channel/PMF/encryption fingerprinting, client probe analysis, vendor OUI lookup, war-driving with Kismet/airodump-ng/Wigle, and…
offensive-zigbee-thread-matter
Zigbee, Thread, and Matter mesh-protocol attack methodology — IEEE 802.15.4 sniffing with TI CC2531 / CC2540 / Sonoff Zigbee Dongle E, KillerBee toolkit, Touchlink commissioning abuse with the well-known transport key, replay/injection attacks, Zigbee Cluster Library command abuse for door locks and bulbs, Thread…
offensive-krack-fragattacks
KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants. Covers Vanhoef's test scripts, viability against modern patched stacks (mostly mitigated post-2021), residual unpatched embedded devices and IoT…
OT / ICS / SCADA Security
Operational Technology and industrial control system security — Purdue model segmentation, industrial protocol analysis (Modbus, DNP3, S7, EtherNet/IP), PLC/HMI exposure, IEC 62443 alignment, and MITRE ATT&CK for ICS, for authorized and safety-conscious assessments.
endpoint-management
Manages laptops, desktops and mobile devices — enrollment, configuration, patching, software distribution, and lost or compromised devices. Use this to set up device management, standardize builds, roll out software or an OS upgrade, handle a lost device, or bring an unmanaged fleet under control.