Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/avibebuilder/claude-prime/diagnosenpx skills add avibebuilder/claude-prime --skill diagnosegit clone --depth 1 https://github.com/avibebuilder/claude-primeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/avibebuilder/claude-prime/diagnose)<a href="https://agentmods.dev/skills/avibebuilder/claude-prime/diagnose"><img src="https://agentmods.dev/badge/skills/avibebuilder/claude-prime/diagnose.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00153 | $0.00995 |
| Opus 5 | $0.00077 | $0.00498 |
| Sonnet 5 | $0.00031 | $0.00199 |
| Haiku 4.5 | $0.00015 | $0.00100 |
Grade A, and why
diagnose scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 89 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Think harder.
Process
Check conversation context and skip completed steps.
1. Understand the symptom
- Read the bug report, errors, logs, and surrounding code carefully
- Clarify reproduction steps, expected behavior, and environment when they are unclear
- Separate confirmed facts from working assumptions. List them explicitly:
Fact (confirmed):the server returns 200Assumption (unconfirmed):the client receives the full HTML body Misidentifying an assumption as a fact is the most common source of wasted investigation.
2. Build hypotheses
-
Form 2-4 plausible root-cause hypotheses that are mechanistically distinct — different failure layers (e.g., server render vs. client hydration vs. network layer), not variations of the same idea
-
Rank them by likelihood
-
For each hypothesis, state both sides:
Confirm if:[what observation would prove this is the cause]Eliminate if:[what observation would rule this out]
A hypothesis you can't falsify in both directions is too vague to test.
3. Choose the lightest evidence method
Start with the cheapest source of truth that can kill hypotheses:
- existing logs, traces, stack traces, metrics, and error output
- static code inspection around the suspected path
- config, environment, deploy, cache, queue, and permissions state that could explain the symptom
- targeted reproduction in the relevant environment
Only add new instrumentation when existing evidence is insufficient.
- If you need runtime probes, read
diagnose/references/runtime-debugging.md - Use
#region agent log/#endregionmarkers for any instrumentation you add - Tag each log point with the relevant
hypothesisId - Log only the minimum fields needed to discriminate between hypotheses; never log secrets, tokens, passwords, cookies, or full sensitive payloads
- If runtime probes require starting the local debug server, ask the user before launching it
- For browser/UI bugs, combine with the
agent-browserskill when reproduction or inspection needs it
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 89 lines · 153 tokens per session scan A 5884a816c52c
diagnose is a skill published in the GitHub repository avibebuilder/claude-prime (119 stars, last pushed 3mo ago), licensed MIT. It adds 153 tokens to every session and 995 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
phx-deps-audit
Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs. Use after mix deps.update, when checking if a package upgrade is safe, or reviewing mix.lock PR diffs.
release
CONTRIBUTOR TOOL - Cut a plugin release: bump plugin.json version, finalize CHANGELOG, update README if needed, gate on make ci, commit, tag vX.Y.Z, and create the GitHub release. Use when shipping a new plugin version. NOT distributed.
session-deep-dive
Deep qualitative analysis of high-signal sessions. Spawns subagents with v2 template, synthesizes patterns, compares against known findings. Use after /session-scan.
brainstorm
Brainstorm Elixir/Phoenix features — explore ideas, compare approaches, gather requirements. Use when vague idea, not sure how to approach, or want to discuss before plan.
elixir-idioms
OTP/BEAM patterns and Elixir idioms — GenServer, Supervisor, Task, Registry, pattern matching, with chains, pipes. Use when designing processes or debugging BEAM issues.
security
Enforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS, SQL injection, input validation, secrets. Use when editing auth files, login flows, RBAC, or API keys.