Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/azure-samples/eshoplite/external-commsnpx skills add Azure-Samples/eShopLite --skill external-commsgit clone --depth 1 https://github.com/Azure-Samples/eShopLiteWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00020 | $0.03005 |
| Opus 5 | $0.00010 | $0.01503 |
| Sonnet 5 | $0.00004 | $0.00601 |
| Haiku 4.5 | $0.00002 | $0.00300 |
Grade A, and why
external-comms scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to external-comms — 658 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 330 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Context
Phase 1 is draft-only mode.
- PAO scans issues and discussions, drafts responses with the humanizer skill, and presents a review table for human approval.
- Human review gate is mandatory — PAO never posts autonomously.
- Every action is logged to
.squad/comms/audit/. - This workflow is triggered manually only ("PAO, check community") — no automated or Ralph-triggered activation in Phase 1.
Patterns
1. Scan
Find unanswered community items with GitHub MCP tools first, or gh issue list / gh api as fallback for issues and discussions.
- Include open issues and discussions only.
- Filter for items with no squad team response.
- Limit to items created in the last 7 days.
- Exclude items labeled
squad:internalorwontfix. - Include discussions and issues in the same sweep.
- Phase 1 scope is issues and discussions only — do not draft PR replies.
Discussion Handling (Phase 1)
Discussions use the GitHub Discussions API, which differs from issues:
- Scan:
gh api /repos/{owner}/{repo}/discussions --jq '.[] | select(.answer_chosen_at == null)'to find unanswered discussions - Categories: Filter by Q&A and General categories only (skip Announcements, Show and Tell)
- Answers vs comments: In Q&A discussions, PAO drafts an "answer" (not a comment). The human marks it as accepted answer after posting.
- Phase 1 scope: Issues and Discussions ONLY. No PR comments.
2. Classify
Determine the response type before drafting.
- Welcome (new contributor)
- Troubleshooting (bug/help)
- Feature guidance (feature request/how-to)
- Redirect (wrong repo/scope)
- Acknowledgment (confirmed, no fix)
- Closing (resolved)
- Technical uncertainty (unknown cause)
- Empathetic disagreement (pushback on a decision or design)
- Information request (need more reproduction details or context)
Template Selection Guide
| Signal in Issue/Discussion | → Response Type | Template |
|---|---|---|
| New contributor (0 prior issues) | Welcome | T1 |
| Error message, stack trace, "doesn't work" | Troubleshooting | T2 |
| "How do I...?", "Can Squad...?", "Is there a way to...?" | Feature Guidance | T3 |
| Wrong repo, out of scope for Squad | Redirect | T4 |
| Confirmed bug, no fix available yet | Acknowledgment | T5 |
| Fix shipped, PR merged that resolves issue | Closing | T6 |
| Unclear cause, needs investigation | Technical Uncertainty | T7 |
| Author disagrees with a decision or design | Empathetic Disagreement | T8 |
| Need more reproduction info or context | Information Request | T9 |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 330 lines · 20 tokens per session scan A a32cc840a78c
external-comms is a skill published in the GitHub repository Azure-Samples/eShopLite (168 stars, last pushed 1mo ago), licensed MIT. It adds 20 tokens to every session and 3,005 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to external-comms, differing in 658 lines, and is treated as a copy.
Other skills, from other repositories
foundry-agent-deploy
Build, register, and wire up a Foundry Hosted Agent end-to-end on Azure: build the container to ACR, register a hosted-agent version with the azure-ai-projects SDK, grant least-privilege RBAC, configure the CopilotKit runtime App Service, and verify through the Static Web App. Use when deploying or redeploying a…
foundry-hosted-agent-maf
Author a Microsoft Agent Framework (.NET) agent that is hosted as a Foundry Hosted Agent and speaks AG-UI over the invocations protocol. Use when building, refactoring, or reviewing a .NET agent that must run as a Foundry Hosted Agent and drive a CopilotKit / AG-UI frontend. WHEN: "build a Foundry hosted agent"…
mine
Mine a project or conversation into your MemPalace — extract and store memories for later retrieval.
status
Show MemPalace status — room counts, storage usage, and palace health.
mempalace-recall
Recall protocol for MemPalace — search the palace before answering about past work, people, projects, or prior decisions. Apply when the user asks what was decided, what happened before, who someone is, what was discussed last time, or anything that may already be filed in their memory palace; or when mempalace-recall…
multi-repo-release
Prepares and validates GPT-RAG umbrella releases across component repositories and the AI Landing Zone. Use for manifest pins, changelog entries, release branches, tags, and GitHub Release notes.