Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/boshu2/agentops/routenpx skills add boshu2/agentops --skill routegit clone --depth 1 https://github.com/boshu2/agentopsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00057 | $0.01595 |
| Opus 5 | $0.00028 | $0.00797 |
| Sonnet 5 | $0.00011 | $0.00319 |
| Haiku 4.5 | $0.00006 | $0.00160 |
Grade A, and why
route scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 152 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/route
Return the one skill that owns a request, the reason, and a confidence. Or return
none — that is a real answer, not a failure. This skill routes and stops. It
never performs the routed work.
Insight: a flat list of skill names in context is a catalog, not a router. The agent still has to guess, and it guesses from its own narrative of what it is doing — which is wrong exactly when the routing matters. Routing on the object being touched is more robust than routing on the activity, because the object survives a mistaken self-narrative and the activity does not.
The failure mode this exists to prevent: hand-rolling a discipline from first principles while the skill that owns it sits unused in the same repo. It happens because the request did not use the skill's vocabulary, so nothing matched, so the agent proceeded — producing a worse version of something already built and tested.
Modes
| Trigger phrases | Mode | Entry point |
|---|---|---|
| "which skill covers this", "route this" | route one request | the procedure below |
| "is there a skill for X" | existence check | the catalog query below |
| "why did that route there" | explain a routing | restate the matched layer and the runner-up |
Inputs
Required: the request to route, in the caller's own words. Do not paraphrase it into skill vocabulary first — the paraphrase is where the routing error enters.
Optional: the object being touched (path, artifact, external system).
Non-goals. This skill does not invoke the routed skill, rank skills by
quality, maintain the catalog, or create a skill when none matches. It does not
route to skills outside skills/ — other corpora on the host are the caller's to
manage. It does not chain: routing to rpi means routing to rpi, not
pre-deciding what rpi will do next.
Procedure
Four layers, in order. Stop at the first that yields a single owner.
- Object. Name the object the request touches: host × system × artifact
("this repo × git × branch history", "external service × credentials"). Match
the object against skill
effectsinskills/catalog.json. An effect is a declared fact about what a skill touches, so it survives a wrong self-narrative. - Declared trigger. Match the request against the
descriptiontrigger phrases in eachskills/*/SKILL.md. Triggers are authored to be the words a caller actually says. - Capability. Match the request's verb against declared
capabilitiesin the catalog. - Tier narrowing. If two or more skills survive, prefer by tier for the
request's shape: judgment work →
judgment, running an experiment →execution, choosing a shape →meta. If a tie survives this, setownertonone, list the tied skills as candidates, and say why they overlap — an unresolved tie is a catalog defect worth reporting, not a coin flip to hide.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 152 lines · 57 tokens per session scan A cb7f450e5235
route is a skill published in the GitHub repository boshu2/agentops (431 stars, last pushed 4d ago), licensed Apache-2.0. It adds 57 tokens to every session and 1,595 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
brainstorm
Explore vague or ambitious ideas into a right-sized requirements-only plan. Use when the user wants to brainstorm, think through scope, decide what to build, or needs collaborative product framing before planning, not for a decisive verdict on whether to adopt or switch to a specific external technology, library, or…
autolearn
Compound a solved problem into a durable in-repo learning doc. Use when a verified non-trivial fix lands, the user says "compound this", "document this fix", or "remember this". This is the automatic-capture entry point; for an explicitly requested one-off write-up, use compound.
doc-review
Use when the user asks to review or critique a prose planning document — a plan, spec, PRD, requirements doc, or design doc.
audit-project
Run an iterative multi-agent code audit until critical and high findings are resolved. Use when the user says "audit my code", "find all the bugs", "deep code audit", "iterative review", or "review until clean".
commit-push-pr
Use when asked to ship/open a PR, or for PR-description-only flows like writing, rewriting, or describing a PR body.
doubt-driven
Doubt-driven adversarial review. Use when correctness matters more than speed, the code is unfamiliar, stakes are high, a claim can't be checked by the type system or compiler, or verifying now is cheaper than debugging later.