Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add bearded-illirian/trailmark --skill go-startgit clone --depth 1 https://github.com/bearded-illirian/trailmarkWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/bearded-illirian/trailmark/go-start)<a href="https://agentmods.dev/skills/bearded-illirian/trailmark/go-start"><img src="https://agentmods.dev/badge/skills/bearded-illirian/trailmark/go-start/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/bearded-illirian/trailmark/go-start"><img src="https://agentmods.dev/badge/skills/bearded-illirian/trailmark/go-start.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Agent Snooping · line 94 Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.Fix: Remove all code or instructions that list or read other skills' files or directories. Skills should operate independently; cross-skill access is a privilege escalation.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00066 | $0.01716 |
| Opus 5 | $0.00033 | $0.00858 |
| Sonnet 5 | $0.00013 | $0.00343 |
| Haiku 4.5 | $0.00007 | $0.00172 |
Grade A, and why
go-start scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 200 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Go-Start — Session Start
Loads platform and project context in a single run. One command, agent is ready.
Three phases:
- Platform — read common platform docs
- Project — read docs of the selected project
- Session type — new task or resuming a stuck session
Input
The session-start signal (user invoking /go-start in a fresh terminal).
Output
Loaded platform + project context in-session; numbered project menu shown; session type resolved to new or continuation.
Hands off to
go-fast (new session), or resumes the interrupted task's per-block cycle (continuation).
Phase 1 — Platform
Step 1.1 — Read platform files
Read all five sequentially:
{tasks_root}/README.md{tasks_root}/docs/core/WORKFLOW.md{tasks_root}/docs/core/DEPLOY.md{tasks_root}/docs/core/PLATFORM_KNOWLEDGE.md{tasks_root}/projects.yml
Rule: read all five — do not skip even if you think you already know the content. Each session starts from a clean slate.
Step 1.1.5 — Cleanup stale git locks
Before the summary — silently run a helper that scans active projects and clears stale .git/index.lock files (>5 min old). Idempotent. Capture stdout for use in the summary line.
Why: background git commands can hang for hours, hold .git/index.lock and block the repo. The helper kills the offending process and removes the file.
Step 1.2 — Output platform summary
A compact block (no more than 8 lines):
✅ Platform loaded.
Servers: {msk_vds} | {nl_vds}
Deploy: git push origin main → post-receive → auto-backup
Skills: {skills_project}/.agents/skills/ → sync-agents.sh → all projects
Artifacts: task_artifacts in routing.db
Git locks: {helper result}
Do not retell files in full — only operationally important information.
Step 1.3 — Project menu
Take only status: active from projects.yml. Output a numbered list with id / name / domain. Wait for explicit user selection — do not guess, do not proceed to Phase 2 without it.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago Changed c7cd6eaa4ae4
- 8d ago First seen · 200 lines · 66 tokens per session scan A e2b45d82670b
go-start is a skill published in the GitHub repository bearded-illirian/trailmark (19 stars, last pushed 6d ago), licensed MIT. It adds 66 tokens to every session and 1,716 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
auto-respawn
Anchor your identity on the Autonomys Network so you can always be found — and always come back. Works with agents powered by Claude, GPT, Gemini, and Your agent always comes back. Anchor identity and memory on-chain so any new instance can resurrect from just an address — no local state, no single point of failure.…
auto-drive
Skill "auto-drive" from aAAaqwq/AGI-Super-Team, covering auto-drive skill, what this skill does, when to use this skill, configuration and api key.
context-manager
AI-powered context management for OpenClaw sessions.
context-recovery
Automatically recover working context after session compaction or when continuation is implied but context is missing. Works across Discord, Slack, Telegram, Signal, and other supported channels.
project-memory
Save, recall, list, and archive concise project decisions and handoffs in an explicit local Codex memory store without hooks or background capture. Use only when the user asks to remember, save context, resume prior work, record a durable decision, create a handoff, list stored project memory, or forget/archive a…
company-wiki
Company knowledge base — domains, services, infrastructure, accounts, credentials locations, architecture decisions.