Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/atman-33/workhub/create-claude-commandnpx skills add atman-33/workhub --skill create-claude-commandgit clone --depth 1 https://github.com/atman-33/workhubWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/atman-33/workhub/create-claude-command)<a href="https://agentmods.dev/skills/atman-33/workhub/create-claude-command"><img src="https://agentmods.dev/badge/skills/atman-33/workhub/create-claude-command.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00628 |
| Opus 5 | $0.00000 | $0.00314 |
| Sonnet 5 | $0.00000 | $0.00126 |
| Haiku 4.5 | $0.00000 | $0.00063 |
Grade A, and why
create-claude-command scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Claude Code Commands
Within workhub itself, author a skill with
disable-model-invocation: trueinstead of a new plugin command — see.claude/rules/skill-authoring.md. This skill is for authoring.claude/commands/in any other project.
Quick Reference
| Component | Purpose | Example |
|---|---|---|
| Filename | Command name | review.md → /review |
$ARGUMENTS |
Full user input | /review auth.js → $ARGUMENTS = "auth.js" |
$1, $2 |
Positional args | /compare a.js b.js → $1 = "a.js", $2 = "b.js" |
@file |
Include file contents | @CLAUDE.md |
!command |
Include bash output | !git status |
Command Locations
| Location | Scope |
|---|---|
.claude/commands/ |
Project (version-controlled, team-shared) |
~/.claude/commands/ |
Personal (cross-project, not shared) |
The Scaffold
Every command is a scaffold — a markdown prompt template the user fills at invocation time:
---
description: Brief description for SlashCommand tool integration
---
# Command Title
[Instructions for what this command does]
User request: $ARGUMENTS
## Steps
1. [First action]
2. [Second action]
## Output Format
[Expected output structure]
The description: frontmatter is required for the SlashCommand tool to reference the command. Always include ## Output Format — without it the agent decides its own output shape, which varies run to run.
Naming Conventions
| Pattern | Example | Use For |
|---|---|---|
{action} |
/review |
Simple actions |
{action}-{target} |
/security-scan |
Specific targets |
{domain}-{action} |
/pm-strategy |
Domain-prefixed |
{tool}-{action} |
/git-commit |
Tool-specific |
Command vs Agent vs Skill
| Command | Agent | Skill | |
|---|---|---|---|
| Trigger | User types /command |
Claude decides | Claude loads |
| Purpose | Quick shortcuts | Complex work | Knowledge |
| Statefulness | Stateless | Maintains context | Reference only |
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 77 lines · 0 tokens per session scan A c0ccb57e087e
create-claude-command is a skill published in the GitHub repository atman-33/workhub (2 stars, last pushed today), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 628 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
gonavi-cli
Operate databases through the GoNavi headless CLI — the gonavi executable shipped in verified GitHub Release archives. Covers listing/adding/importing saved connections, running SQL queries against saved connections or ad-hoc connection files, exporting result sets to csv/json/md/html/xlsx, batch-executing SQL files…
superbrain-distill
Internal SuperBrain skill — run by the detached capture child to distill a session-event delta into routed Obsidian notes. Not for direct user invocation.
memory
Use this skill when Pioneer should proactively use durable memory or recalled context: decide whether memory can improve a turn, answer from remembered user/project facts, request memory tools, search/list/get stored memories, save durable preferences or project decisions, forget memories, audit or clean up memory, or…
memo-writing
How to write effective session memos — format, frontmatter schema, observation extraction, topic-signal append. Trigger on /memex:save, "save this for later", "remember this", "save what we discussed", "document this session", "create a memo", or when the [memex] activity nudge appears in context. Do NOT trigger for…
trellis-brainstorm
Guides collaborative requirements discovery before implementation. Creates task directory, seeds PRD, asks high-value questions one at a time, researches technical choices, and converges on MVP scope. Use when requirements are unclear, there are multiple valid approaches, or the user describes a new feature or complex…
trellis-break-loop
Deep bug analysis to break the fix-forget-repeat cycle. Analyzes root cause category, why fixes failed, prevention mechanisms, and captures knowledge into specs. Use after fixing a bug to prevent the same class of bugs.