Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/bnet47/codexicon/shipnpx skills add bnet47/codexicon --skill shipgit clone --depth 1 https://github.com/bnet47/codexiconWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00025 | $0.00565 |
| Opus 5 | $0.00013 | $0.00282 |
| Sonnet 5 | $0.00005 | $0.00113 |
| Haiku 4.5 | $0.00003 | $0.00056 |
Grade A, and why
ship scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 65 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Ship
Determine the authorization ceiling from the request before acting:
- Commit only: verify and create the commit, then stop.
- Push: verify, commit when needed, and push the current non-protected branch; do not open a PR.
- Open a PR / ship: verify, commit, push, and open a draft PR.
None of these requests authorizes deployment or unrelated cleanup.
1. Verify
Run the narrowest feature checks plus:
./scripts/lint.sh
./scripts/test.sh
./scripts/security.sh
If a check fails, diagnose and fix only in-scope problems, rerun it, and stop if safe completion needs a product decision or unrelated change. Run the canonical scripts directly so lint/test one-use hook receipts reflect the real result; do not mark verification manually.
For a first production launch or material production change, run $production-readiness before publication. A NOT READY verdict blocks shipping; only the accountable human can accept a named residual risk.
2. Audit the change set
Inspect unstaged, staged, and untracked files. Confirm the diff matches the request, the security gate passed, and there is no accidental generated output or unresolved conflict marker.
Determine the intended base branch and confirm the current branch is not main or another protected branch. Create a scoped branch when needed; never force-push.
3. Review
Run the $review workflow or perform the same acceptance-focused review. Resolve actionable findings and rerun affected verification before committing.
4. Commit intentionally
Stage only files that belong to this request. Use the $conventional-commit format:
type(scope): imperative summary
Keep the subject concise and add a body when motivation or compatibility impact is not obvious. Confirm the resulting commit contains only the intended files.
5. Publish only to the authorized ceiling
If push was requested, push the current branch without force. If a PR or shipping was requested, open a draft pull request with:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 65 lines · 0 tokens per session scan A 0350ee11758a
ship is a skill published in the GitHub repository bnet47/codexicon (5 stars, last pushed 3d ago), licensed MIT. It adds 25 tokens to every session and 565 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
make_plan
For external plan request scenarios, guides the Agent to request a clear, actionable, step-by-step plan from a stronger Agent via listagents and chatwithagent, emphasizing that the plan is executed by the requester, not by the consulted Agent.
当用户需要对PDF文件进行任何操作时,请使用此技能。包括从 PDF 中读取或提取文本/表格、合并多个 PDF、拆分 PDF、旋转页面、添加水印、创建新PDF、填写PDF表单、加密/解密 PDF、提取图片,以及对扫描版 PDF 进行 OCR 使其可搜索。如果用户提到 .pdf 文件或要求生成 PDF,请使用此技能。.
oma-scholar
Scholarly research companion using Knows sidecar spec (.knows.yaml). Generates, validates, reviews, queries, and compares structured research-paper sidecars, and fetches them from knows.academy. Use for academic literature search, survey synthesis, paper authoring assistance, and peer review with token-efficient…
oma-hwp
Convert HWP / HWPX / HWPML files to Markdown using kordoc. Extracts text, headings, tables, lists, images, footnotes, and hyperlinks. Use for Korean word processor files (Hangul), government documents, and AI-ready data preparation.
systematic-debugging
4-phase root cause debugging: understand bugs before fixing.
architecture-diagram
Dark-themed SVG architecture/cloud/infra diagrams as HTML.