Borrowing it
Nothing to install: this file belongs to benoror/obsidianos_work. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/benoror/obsidianos_work/main/.agents/skills/sync-upstream-obsidianos/SKILL.mdgit clone --depth 1 https://github.com/benoror/obsidianos_workWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/benoror/obsidianos_work/sync-upstream-obsidianos)<a href="https://agentmods.dev/skills/benoror/obsidianos_work/sync-upstream-obsidianos"><img src="https://agentmods.dev/badge/skills/benoror/obsidianos_work/sync-upstream-obsidianos/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/benoror/obsidianos_work/sync-upstream-obsidianos"><img src="https://agentmods.dev/badge/skills/benoror/obsidianos_work/sync-upstream-obsidianos.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00022 | $0.00450 |
| Opus 5 | $0.00011 | $0.00225 |
| Sonnet 5 | $0.00004 | $0.00090 |
| Haiku 4.5 | $0.00002 | $0.00045 |
Grade A, and why
sync-upstream-obsidianos scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Sync Upstream ObsidianOS
Shortcut to run .scripts/sync-upstream.sh.
Usage
| Command | What it does |
|---|---|
/sync-upstream-obsidianos |
Preview and merge upstream updates |
/sync-upstream-obsidianos preview |
Preview only — show what's new without merging |
Workflow
1. Check prerequisites
- Verify
upstreamremote exists:git remote get-url upstream. If missing, tell the user to add it:git remote add upstream <url-to-upstream-repo> - Verify working tree is clean (
git status --short). If dirty, ask the user to commit or stash first.
2. Preview
Run .scripts/sync-upstream.sh --preview and show the output (new commits and changed files).
If there are no new commits, report "already up to date" and stop.
If the user only asked for preview, stop here.
3. Confirm and merge
Present the preview results and ask the user to confirm before merging.
On confirmation, run the full sync:
echo y | ./.scripts/sync-upstream.sh
4. Report results
Show the merge outcome:
- Which files were updated.
- Whether any files were excluded via
.sync-exclude. - The final commit (
git log -1 --oneline).
If the merge had conflicts, relay the conflict list and instruct the user to resolve manually.
Important Notes
- The script protects personal files (Meetings, Teams, Templates, etc.) via
.gitattributesmerge=ours rules. - Files matching patterns in
.sync-excludeare auto-removed from the merge (e.g. upstream example files). - This skill never pushes — the user decides when to push.
- If the
upstreamremote doesn't exist, do not create it automatically — prompt the user for the URL.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 61 lines · 22 tokens per session scan A f6f25a54ec7e
sync-upstream-obsidianos is a skill published in the GitHub repository benoror/obsidianos_work (165 stars, last pushed 3mo ago), licensed MIT. It adds 22 tokens to every session and 450 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
pre-publish-review
Nuclear-grade 12-agent pre-publish release gate. Runs /get-unpublished-changes to detect all changes since last npm release, spawns up to 10 ultrabrain agents for deep per-change analysis, invokes /review-work (orchestrator manual QA plus one gate reviewer) for holistic review, and 1 oracle for overall release…
publish
Publish oh-my-opencode to npm by triggering the GitHub Actions publish workflow and verifying its artifacts. Ship-only: never runs pre-publish-review or re-reviews merged code unless the user explicitly asks. Argument: . Triggers: publish, release, deploy, npm publish.
work-with-pr
Full PR lifecycle in a fresh task-owned git worktree: implement via the ulw-loop skill with mandatory evidence-bound manual QA → reviewer-readable English PR → verification loop (CI + Cubic, where Cubic is skipped only when its quota is exhausted) → merge by default → worktree cleanup. Decomposes one task into the…
lcx-contribute-bug-fix
Contribute a verified bug fix for LazyCodex, lazycodex-ai, omo-codex, bundled Codex skills, or upstream Codex CLI bugs. Opens a fork PR only for upstream openai/codex; LazyCodex-owned defects become a verified-fix issue on code-yeongyu/lazycodex (never a PR — that repo is a generated distribution mirror). Use when the…
git-master
Handles git work: atomic commits, rebase, squash, blame, bisect, reflog, and history questions. Use whenever a task needs a commit or a git-history investigation; skip for ordinary code edits.
get-unpublished-changes
Compare HEAD with the latest published npm versions and list all unpublished changes by release layer. Triggers: unpublished changes, changelog, what changed, whats new.