Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/asteasolutions/ai-toolkit/setup-agentic-loopnpx skills add asteasolutions/ai-toolkit --skill setup-agentic-loopgit clone --depth 1 https://github.com/asteasolutions/ai-toolkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00043 | $0.01809 |
| Opus 5 | $0.00022 | $0.00905 |
| Sonnet 5 | $0.00009 | $0.00362 |
| Haiku 4.5 | $0.00004 | $0.00181 |
Grade A, and why
setup-agentic-loop scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Setup — install the /agentic-loop build loop
Install a delegated build loop whose code is written by one agent and judged by another in a fresh context. The developer approves a spec once, up front; implementation, verification, and review then run without them.
Works under Claude Code, GitHub Copilot in VS Code, and Cursor — all three run skills and delegate to sub-agents. One body per agent, translated per harness: see references/harnesses.md.
This skill fits the repo; it does not wire it. Detect where this repo already keeps agents and skills and place the scaffolding there. Creating shared-instruction files or harness projection config is out of scope — this skill installs a loop, not a repo layout. The one editor setting it offers to write is the one the loop cannot run without.
Prompt-driven, not a script. Detect, ask, preview, confirm, write, verify.
What lands
| Artifact | Role |
|---|---|
agentic-loop skill |
The front gate: spec + slices, approved in the developer's conversation, then handed off |
orchestrator agent |
Runs slices unattended: implement → verify → review → bounded fix rounds → report |
implementer agent |
Writes one slice against its clauses |
reviewer agent |
Read-only judge in a fresh context; writes findings, returns a verdict |
security-reviewer agent |
Bundled specialist: trust-boundary changes — untrusted input, authz, secrets, dependencies |
architecture-reviewer agent |
Bundled specialist: structural change no clause of the spec asked for |
<surface>-reviewer agents |
Optional repo-specific specialists (migrations, API contracts, infrastructure) |
Every specialist is dispatched by trigger, never on every slice — a slice that adds no structure never pays for an architecture review.
These are common names. A repo that already has an agent or skill by one of them gets a keep-or-replace decision in step 3, never a silent overwrite.
Process
What ships with it
11 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- LICENSE 1.0 KB
- references/detection.md 4.6 KB
- references/harnesses.md 6.0 KB
- templates/agentic-loop/LICENSE 1.0 KB
- templates/agentic-loop/SKILL.md 4.2 KB
- templates/agents/architecture-reviewer.md 3.5 KB
- templates/agents/implementer.md 2.5 KB
- templates/agents/orchestrator.md 7.2 KB
- templates/agents/reviewer.md 3.2 KB
- templates/agents/security-reviewer.md 4.0 KB
- templates/agents/specialist-reviewer.template.md 1.9 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 92 lines · 43 tokens per session scan A 6134e18d042e
setup-agentic-loop is a skill published in the GitHub repository asteasolutions/ai-toolkit (5 stars, last pushed 5d ago), licensed MIT. It adds 43 tokens to every session and 1,809 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…