workload

A manager for declared runs on machines, where each run has a file describing what it should be and who owns it. The actual machine unit is treated as something that can be rebuilt from that declaration.

In plain words
What is it for?
It helps you declare, provision, list, inspect, reconcile, adopt, and retire machine runs, with optional notifications when reconciliation finds work to do.
Why use it?
It makes the intended setup explicit and lets you compare it with the machine's current setup, including cases where something was created manually.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/bks-lab/open-bridge/workload
Any agent
npx skills add bks-lab/open-bridge --skill workload
Clone the repo
git clone --depth 1 https://github.com/bks-lab/open-bridge

Made for: Claude Code, Codex.

Per session 248 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 9,368 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00248 $0.09368
Opus 5 $0.00124 $0.04684
Sonnet 5 $0.00050 $0.01874
Haiku 4.5 $0.00025 $0.00937

Measured 2d ago against content hash 58311567063a, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

workload scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

The scan reads SKILL.md. This mod also ships 33 executable files (engine/__init__.py, engine/backends/__init__.py, engine/backends/base.py, …), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/workload/SKILL.md · 607 lines

How it starts

The opening of the file, as written. The whole thing — 607 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Workload

One declared run, on one machine, with an owner. The declaration in workflow/workloads/<id>.yaml is the source of truth; the unit file on the machine is an artifact and may be rebuilt from the declaration at any time.

The engine is skills/workload/engine/ behind the shim skills/workload/workload.sh. The data is the declaration plus _schema.yaml and _template.yaml next to it. Nothing instance specific lives in the code: hosts come from infra/remotes/, paths and prefixes from the workloads: block of bridge-config.yaml.

Guard

workloads.enabled must not be false in bridge-config.yaml. A missing block means defaults, never a crash. A false refuses every subcommand with exit 3 and names the key and the file it read.

reconcile --notify speaks through the program declared in workloads.notify_via, never through a name this skill knows:

workloads:
  notify_via:
    command: ["~/bin/my-notifier", "--subject", "{what}", "--host", "{where}",
              "--action", "{todo}"]
    detail:  ["--body", "{detail}"]        # appended only when there is detail

Substitution is per argv element, so a value with a space stays one argument. With no notify_via, --notify sends nothing and says so, naming the key: an alarm path this skill invented would be a dependency the repository does not ship.

Commands

workload list       [--host H] [--kind K] [--runtime R] [--owner O] [--scope S] [--retired] [--json]
workload show       <id> [--render] [--json]
workload validate   [<id>...] [--all] [--strict]
workload declare    <id> --kind K --runtime R --host H [--title T] [--purpose P] [--command ARGV...] [--timeout-sec N] [--force]
workload render     <id> [--offline --uid U --home P]
workload provision  <id> [--dry-run] [--yes] [--force] [--accept-degraded] [--enable]
workload adopt      <id> [--yes]        # a hand made unit: declare its placement.label_prefix
workload reconcile  [<id>...] [--all] [--host H] [--no-probe] [--verbose] [--propose-inventory] [--json] [--notify]
workload view       [<id>...] [--host H] [--no-probe] [--out PATH] --now STAMP [--poll-sec S]
workload publish    [<id>...] [--host H] [--no-probe] --to HOST --dest DIR --now STAMP [--page-name NAME] [--attach PATH]... [--url URL] [--stale-after-min N] [--poll-sec S] [--yes]
workload retire     <id> --reason TEXT [--superseded-by ID] [--keep-artifact] [--yes] [--dry-run]

Read the full file on GitHub · 607 lines

Files

What ships with it

60 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 607 lines · 248 tokens per session scan A 58311567063a

Subscribe to this mod's changes

workload is a skill published in the GitHub repository bks-lab/open-bridge (8 stars, last pushed 2d ago), licensed MIT. It adds 248 tokens to every session and 9,368 once invoked, about $0.0012 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

xlsx

Comprehensive spreadsheet creation, editing, and analysis with support for formulas, formatting, data analysis, and visualization. When Claude needs to work with spreadsheets (.xlsx, .xlsm, .csv, .tsv, etc) for: (1) Creating new spreadsheets with formulas and formatting, (2) Reading or analyzing data, (3) Modify…

AminulIslamSifat/Sable · 96 tokens

pdf

Comprehensive PDF manipulation toolkit for extracting text and tables, creating new PDFs, merging/splitting documents, and handling forms. When Claude needs to fill in a PDF form or programmatically process, generate, or analyze PDF documents at scale.

AminulIslamSifat/Sable · 50 tokens

pptx

Presentation creation, editing, and analysis. When Claude needs to work with presentations (.pptx files) for: (1) Creating new presentations, (2) Modifying or editing content, (3) Working with layouts, (4) Adding comments or speaker notes, or any other presentation tasks.

AminulIslamSifat/Sable · 62 tokens

docx

Comprehensive document creation, editing, and analysis with support for tracked changes, comments, formatting preservation, and text extraction. When Claude needs to work with professional documents (.docx files) for: (1) Creating new documents, (2) Modifying or editing content, (3) Working with tracked changes, (4)…

AminulIslamSifat/Sable · 77 tokens

process-builder

Scaffold new babysitter process definitions following SDK patterns, proper structure, and best practices. Guides the 3-phase workflow from research to implementation.

a5c-ai/babysitter · 32 tokens

retrospect-external-babysitter-run

For a repository in the babysitter-users catalog, locate its babysitter processes and any committed runs (.a5c/runs/ /) and perform a retrospective on a chosen run -- what went well, what failed, process suggestions, quality of effect design, breakpoint patterns -- mirroring the /babysitter:retrospect workflow but…

a5c-ai/babysitter · 120 tokens