Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/asimons81/hardproof/implementnpx skills add asimons81/hardproof --skill implementgit clone --depth 1 https://github.com/asimons81/hardproofWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00023 | $0.00305 |
| Opus 5 | $0.00012 | $0.00152 |
| Sonnet 5 | $0.00005 | $0.00061 |
| Haiku 4.5 | $0.00002 | $0.00030 |
Grade A, and why
implement scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Implement the Plan
Purpose
Produce the approved behavior in buildable increments while preserving an inspectable task ledger.
When to use
Use for the IMPLEMENT stage selected by the active run context.
Inputs
Use approved design and plan records, ready tasks, project guidance, current code, tests, and profile-specific policy.
Procedure
- Select a dependency-ready task with
hardproof_task. - Add or identify a failing behavioral test where practical.
- Make the smallest complete code and documentation change for that task.
- Run focused checks and inspect the diff.
- Update the task with acceptance notes through
hardproof_task. - Record consequential deviations with
hardproof_record; return to DESIGN or PLAN when approval assumptions no longer hold.
Required records
Keep task status, acceptance evidence, changed scope, and new decisions durable. At least one completed task or recorded change is required before review.
Exit criteria
Planned implementation tasks are complete or explicitly blocked, the repository remains buildable, and the resulting diff is ready for independent challenge.
Failure modes
Stop on unsafe mutation, approval gaps, destructive actions, or design drift. Never mark a task complete without acceptance notes.
Verification
Run task-focused checks, review the actual diff, and call hardproof_transition for REVIEW. Full verification evidence belongs to VERIFY.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 36 lines · 23 tokens per session scan A 145a92a7eec1
implement is a skill published in the GitHub repository asimons81/hardproof (5 stars, last pushed 3d ago), licensed Apache-2.0. It adds 23 tokens to every session and 305 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
repo-readiness-audit
Use when a user asks whether an identified repository is ready for further development, release work, a new feature, handoff, or a new contributor, requiring a disciplined read-only audit before an evidence-backed verdict.
dont-lie-to-me
Use when the user explicitly wants evidence-disciplined answers that separate observed facts, sourced claims, user reports, inference, unknowns, and contradictions before making strong factual or completion claims.
x-analytics-import
Use when X Analytics CSV exports must be inspected, validated, normalized, imported, or compared through a repeatable private-by-default workflow.
x-post-writer
Use when drafting, rewriting, or repurposing short-form X content, including single posts, quote posts, replies, threads, launches, and personal stories, with source fidelity and claim verification built in.
hermes-skill-consolidate
Use when installed Hermes skills must be safely consolidated, restructured, deprecated, split, or given shared references after overlap has been established, with a read-only plan, explicit approval, rollback snapshot, staged writes, and post-change verification.
hermes-environment-migration
Use when a Hermes environment must be safely migrated between machines with staged exports, integrity manifests, secret separation, selective imports, verification, and rollback.