Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/bromso/metapowers/checklistnpx skills add bromso/metapowers --skill checklistgit clone --depth 1 https://github.com/bromso/metapowersWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/bromso/metapowers/checklist)<a href="https://agentmods.dev/skills/bromso/metapowers/checklist"><img src="https://agentmods.dev/badge/skills/bromso/metapowers/checklist.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00014 | $0.00525 |
| Opus 5 | $0.00007 | $0.00262 |
| Sonnet 5 | $0.00003 | $0.00105 |
| Haiku 4.5 | $0.00001 | $0.00052 |
Grade A, and why
checklist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 68 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Checklist
Run a quick WCAG 2.1 AA accessibility checklist against "$ARGUMENTS". This is a lightweight check — use the full audit workflow (scope → evaluate → report) for comprehensive testing.
Prerequisites
None — this is a utility skill that can run anytime.
Process
-
Read the target:
- Read the source code of "$ARGUMENTS" (file, component, or page)
- If "$ARGUMENTS" is a directory, check all relevant files
-
Check each category:
Images & Media:
- All images have meaningful alt text (or alt="" if decorative)
- Videos have captions
- Audio has transcripts
Structure:
- Page has one h1
- Heading hierarchy is sequential (no skipped levels)
- Landmark regions used (main, nav, header, footer)
- Lists use proper list elements
- Tables have headers
Color & Contrast:
- Text contrast ratio >= 4.5:1 (3:1 for large text)
- UI component contrast >= 3:1
- Color is not the only way information is conveyed
Keyboard:
- All interactive elements are keyboard accessible
- Focus order is logical
- Focus indicator is visible
- No keyboard traps
Forms:
- All inputs have associated labels
- Required fields are indicated
- Error messages are descriptive and associated with inputs
- Form validation provides suggestions
ARIA:
- ARIA roles are correct
- ARIA states update dynamically
- Status messages use aria-live
- Native HTML preferred over ARIA
Motion:
- prefers-reduced-motion is respected
- Auto-playing content can be paused
-
Report results directly to the user (no artifact file):
- Checklist items passed/failed
- Quick fixes for any failures
- Recommendation: full audit needed? (yes/no)
Output
Present the checklist results directly to the user. No artifact file created — this is a quick check, not a formal audit.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 68 lines · 14 tokens per session scan A 66cd5e67d152
checklist is a skill published in the GitHub repository bromso/metapowers (1 stars, last pushed 4mo ago), licensed MIT. It adds 14 tokens to every session and 525 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
design-method
Use when starting any design task — resolves register, sets the 3 dials, locks Gate 0, and routes to the right move and target skill.
design-webapp
Use when building or extending a dashboard, SaaS screen, or any authenticated app surface — use design-web instead for a marketing site.
design-web
Use when building or revising a marketing/landing/campaign page, register brand locked at Gate 0 — use design-webapp for app screens instead.
react-tanstack-router
Use when implementing routing in a React app (NOT Next.js) with TanStack Router — file-based routes, loaders, search params.
git-flow
Use when committing, branching, opening PRs, or deciding merge/branch strategy.
fusecore
Use when creating modules, understanding FuseCore structure, or implementing features in a FuseCore modular-monolith Laravel project.