Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/bidiche49/claude-conf/checknpx skills add Bidiche49/claude-conf --skill checkgit clone --depth 1 https://github.com/Bidiche49/claude-confWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/bidiche49/claude-conf/check)<a href="https://agentmods.dev/skills/bidiche49/claude-conf/check"><img src="https://agentmods.dev/badge/skills/bidiche49/claude-conf/check.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00018 | $0.00418 |
| Opus 5 | $0.00009 | $0.00209 |
| Sonnet 5 | $0.00004 | $0.00084 |
| Haiku 4.5 | $0.00002 | $0.00042 |
Grade A, and why
check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Detect the project stack and run the full validation pipeline.
Stack detection
Check these files at project root:
| File | Stack | Pipeline |
|---|---|---|
package.json |
Node/TS | Read scripts in package.json. Run lint, typecheck, build, test (in that order, using the actual script names found) |
pubspec.yaml |
Flutter | flutter analyze then flutter test |
composer.json |
PHP | composer lint or phpcs then phpunit |
*.xcodeproj or Package.swift |
Swift | swiftlint then xcodebuild test |
go.mod |
Go | go vet then golangci-lint run then go test ./... |
Cargo.toml |
Rust | cargo clippy then cargo test |
pyproject.toml |
Python | ruff check then mypy then pytest |
Gemfile |
Ruby | rubocop then rspec or rails test |
Makefile |
Generic | Look for targets: make lint, make test, make check |
Rules
- Detect the stack from the table above
- Read the config file (package.json scripts, Makefile targets, pyproject.toml, etc.) to find the real commands — never guess
- Run in order: lint, build (if applicable), tests
- Stop on first error — fix the issue, then re-run the failed step
- If a command doesn't exist (e.g. no "lint" script in package.json), skip it with a warning
- When everything passes: print "Ready to commit" and run
git diff --stat
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 32 lines · 18 tokens per session scan A a81d8fe5837e
check is a skill published in the GitHub repository Bidiche49/claude-conf (2 stars, last pushed 4mo ago), licensed MIT. It adds 18 tokens to every session and 418 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
hooks-eval
Evaluate hook security, performance, and SDK compliance. Use for audits.
webmcp-setup
Bootstraps webmcp-react into an existing React or Next.js app. Installs dependencies, adds WebMCPProvider, creates a first tool, and configures the MCP client bridge. Use when the user wants to set up WebMCP, add MCP tools to their app, integrate webmcp-react, or make their React app accessible to AI agents.
react-expert
Expert-level React development with hooks, performance optimization, state management, and modern patterns. Use when the user mentions frontend, hooks, JSX, TypeScript, or Next.js, or when the task involves Modern React, State Management, Forms, or Performance Optimization.
issue-triage
3-phase issue backlog management with audit, deep analysis, and validated triage actions. Use when triaging GitHub issues, sorting bug reports, cleaning up stale tickets, or detecting duplicate issues. Args: 'all' to analyze all, issue numbers to focus (e.g. '42 57'), 'en'/'fr' for language, no arg = audit only.
review-pr
Perform a comprehensive code review of a pull request.
talk-stage5-script
Produces a complete 5-act pitch with speaker notes, a slide-by-slide specification, and a ready-to-paste Kimi prompt for AI slide generation. Requires validated angle and title from Stage 4. Use when you have a confirmed talk angle and need the full script, slide spec, and AI-generated presentation prompt.