Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/baek-labs/hames/setupnpx skills add baek-labs/hames --skill setupgit clone --depth 1 https://github.com/baek-labs/hamesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/baek-labs/hames/setup)<a href="https://agentmods.dev/skills/baek-labs/hames/setup"><img src="https://agentmods.dev/badge/skills/baek-labs/hames/setup.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00018 | $0.00382 |
| Opus 5 | $0.00009 | $0.00191 |
| Sonnet 5 | $0.00004 | $0.00076 |
| Haiku 4.5 | $0.00002 | $0.00038 |
Grade A, and why
setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Setup
Inspect the current project and use the bundled setup runtime. Show every proposed file change and wait for explicit approval before applying it.
Do not copy plugin skills into the project. Ask whether contracts should be Git-tracked; never infer that choice.
Preserve existing AGENTS.md and CLAUDE.md; propose only the bounded Hames block. A valid repeated setup is read-only.
If config is damaged or interrupted recovery state exists, report the error and recovery choices instead of guessing or writing.
The preview returns a plan_hash. Pass that exact value to apply as --plan-hash; if the project changed and the hash differs, stop and show a new preview for approval. Recovery also requires a read-only recovery preview, its exact recovery_hash, and a separate explicit approval before rollback.
When the bundled legacy manifests identify a previously distributed public Hames tree, present a same-folder transition plan instead of a generic setup. Classify protected names before reading or hashing anything, and show protected items only by relative path, kind, and existence. Never expose content, size, digest, or symlink target for those items.
Propose workspace candidates from project evidence rather than folder names. Register a path in place only when both the path and registration name are confirmed by an existing Hames mapping or the user; leave ambiguous folders preserved and pending. Do not move or copy workspaces.
Only remove files whose current digest and kind still match the selected public manifest. Preserve modified system files, user files, unknown files, protected files, and submodules. Do not change .git, history, index, branches, tags, or remote settings. Apply the new configuration and validate it before cleanup; on any failure, restore only changes made by this transition.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 23 lines · 18 tokens per session scan A 83b4dd6dcff6
setup is a skill published in the GitHub repository baek-labs/hames (5 stars, last pushed yesterday), licensed MIT. It adds 18 tokens to every session and 382 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.
Other skills, from other repositories
b3os-team-inbox
Skill "b3os-team-inbox" from b3rys/b3rys-team-os, covering b3os-team-inbox, 언제 쓰는가, 자기 id 자동 감지, 사용 예 and inbox 확인.
b3os-task-loop
Skill "b3os-task-loop" from b3rys/b3rys-team-os, covering b3os-task-loop — 과제 완료까지 끊기지 않게 도는 작업 루프, source of truth, 핵심 원칙, 언제 쓰나 and wait/review loop — 멈춤 방지 프로토콜.
b3os-task-mgmt
Deprecated compatibility stub. Use b3os-task-loop for Tasks 칸반, 주행모드, handoff, continuation guard, review-wait, scheduled workloop.
legion-implement
Deliver an issue end-to-end through scoped implementation, verification, and pull-request readiness.
to-prd
Turn the current conversation context into a PRD and write it to .context/prd/ so it can be sliced into iudex tickets. Use when the user wants to create a PRD from the current context.
to-issues
Break a plan, spec, or PRD into independently-grabbable iudex tickets using tracer-bullet vertical slices, and register them in the iudex queue with their dependencies. Use when the user wants to convert a plan into tickets, create implementation tickets, or break down work into the iudex queue.