Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/boshu2/agentops/fitnessnpx skills add boshu2/agentops --skill fitnessgit clone --depth 1 https://github.com/boshu2/agentopsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/boshu2/agentops/fitness)<a href="https://agentmods.dev/skills/boshu2/agentops/fitness"><img src="https://agentmods.dev/badge/skills/boshu2/agentops/fitness.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00028 | $0.00671 |
| Opus 5 | $0.00014 | $0.00336 |
| Sonnet 5 | $0.00006 | $0.00134 |
| Haiku 4.5 | $0.00003 | $0.00067 |
Grade A, and why
fitness scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 82 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Fitness — read-only goal measurement
Inspect the active goals document and run only the caller-selected measurement, validation, drift, history, export, or meta-goal command.
Renamed from goals (2026-07-29): the semantic skill is fitness; the
ao goals CLI command family is a separate product surface and keeps its
name. The goals compatibility alias skill was deleted 2026-09-03.
Measurement stays trustworthy only because it cannot mutate what it measures; the moment a fitness report edits a goal, the next report measures the editor, not the project.
Named failure mode — advice creep: a measurement report that ends with "you should…" has silently become work selection.
Anti-pattern: padding the report with recommendations to look helpful. Corrective: return the numbers, the evidence gaps, and checked/not-checked scope, and let the caller decide.
Boundary
- Prefer
GOALS.mdwhen both Markdown and legacy YAML exist. - Preserve stable directive and gate identities in the report.
- Every measured gate must name its executable check and observed outcome.
- Do not add, remove, prioritize, recommend, apply, prune, migrate, or otherwise mutate goals.
- Do not translate a fitness gap into work selection or a next action.
- No subcommand edits the goals source through its own logic.
measure,drift, andexportpersist a best-effort JSON snapshot under the fixed derived path.agents/ao/goals/baselines/.render --out <file>writes a Gherkin spec to whatever path the caller names — the CLI does not constrain it, so never point--outat the goals source or any non-derived file.
Commands
All eight subcommands read the goals source without mutating it. The snapshot
write (fixed derived path) and the render --out write (caller-chosen path,
caller's responsibility) are the only side effects.
ao goals measure --json
ao goals validate --json
ao goals drift
ao goals history
ao goals export
ao goals meta --json
ao goals scenarios
ao goals render # append --out <file> to write the spec instead of stdout
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed 9dcf9013b87d
- 6d ago First seen · 82 lines · 28 tokens per session scan A 6049f114d3c6
fitness is a skill published in the GitHub repository boshu2/agentops (433 stars, last pushed today), licensed Apache-2.0. It adds 28 tokens to every session and 671 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
brainstorm
Explore vague or ambitious ideas into a right-sized requirements-only plan. Use when the user wants to brainstorm, think through scope, decide what to build, or needs collaborative product framing before planning, not for a decisive verdict on whether to adopt or switch to a specific external technology, library, or…
doc-review
Use when the user asks to review or critique a prose planning document — a plan, spec, PRD, requirements doc, or design doc.
audit-project
Run an iterative multi-agent code audit until critical and high findings are resolved. Use when the user says "audit my code", "find all the bugs", "deep code audit", "iterative review", or "review until clean".
commit-push-pr
Use when asked to ship/open a PR, or for PR-description-only flows like writing, rewriting, or describing a PR body.
deps-upgrade
Use when dependency upgrades need tiered batches for CVEs, a major release, forced compatibility, scheduled hygiene, a pre-release lockfile audit, or a cadence-driven or vulnerability-triggered sweep. Classifies each update on a risk ladder, verifies it, or defers it with a reason. Not for PR queue triage; use…
drift-detect
Use when the user says "plan drift", asks whether the roadmap, plans, or docs still match the code, or is deciding what to rebuild when restarting a stalled project. For doc-vs-code drift inside a specific diff, use sync-docs.