Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/butttons/dora/docsnpx skills add butttons/dora --skill docsgit clone --depth 1 https://github.com/butttons/doraWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00024 | $0.02866 |
| Opus 5 | $0.00012 | $0.01433 |
| Sonnet 5 | $0.00005 | $0.00573 |
| Haiku 4.5 | $0.00002 | $0.00287 |
Grade A, and why
dora scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 345 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Philosophy
IMPORTANT: Use dora FIRST for ALL code exploration tasks.
dora understands code structure, dependencies, symbols, and architectural relationships through its indexed database. It provides instant answers about:
- Where symbols are defined and used
- What depends on what (and why)
- Architectural patterns and code health
- Impact analysis for changes
When to use dora vs other tools:
- dora: Code exploration, symbol search, dependency analysis, architecture understanding
- Read: Reading actual source code after finding it with dora
- Grep: Only for non-code files, comments, or when dora doesn't have what you need
- Edit/Write: Making changes after understanding with dora
- Bash: Running tests, builds, git commands
Workflow pattern:
- Use dora to understand structure and find relevant code
- Use Read to examine the actual source
- Use Edit/Write to make changes
- Use Bash to test/verify
Commands
Overview
dora status- Check index health, file/symbol counts, last indexed timedora map- Show packages, file count, symbol count
Files & Symbols
dora ls [directory] [--limit N] [--sort field]- List files in directory with metadata (symbols, deps, rdeps). Default limit: 100dora file <path>- Show file's symbols, dependencies, and dependents. Note: includes local symbols (parameters).dora symbol <query> [--kind type] [--limit N]- Find symbols by name across codebasedora refs <symbol> [--kind type] [--limit N]- Find all references to a symboldora exports <path>- List exported symbols from a file. Note: includes function parameters.dora imports <path>- Show what a file imports
Dependencies
dora deps <path> [--depth N]- Show file dependencies (what this imports). Default depth: 1dora rdeps <path> [--depth N]- Show reverse dependencies (what imports this). Default depth: 1dora adventure <from> <to>- Find shortest dependency path between two files
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 345 lines · 24 tokens per session scan A 554091d7432f
dora is a skill published in the GitHub repository butttons/dora (108 stars, last pushed 5mo ago), licensed MIT. It adds 24 tokens to every session and 2,866 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
roam
Codebase comprehension via roam-code CLI. Use when exploring codebases, planning modifications, debugging failures, assessing PR risk, or checking architecture health. Triggers on: understanding project structure, pre-change safety checks, finding symbols/files, blast radius analysis, affected tests, health scoring…
orchestrate
Tree-aware multi-agent GitHub-issue pool. Conductor manages task-tree from task-splitting-evaluation, executing depth-first per branch while parallelizing roots/orphans. Each worker agent owns its subtree lifecycle. Conductor tracks state (pending/started/in-progress/completed/halted) in GitHub +…
bonsai-ninja
Use bonsai-ninja as compiler-backed structural evidence when mapping a codebase, finding symbols, tracing behavior, inspecting dataflow, debugging across files, reviewing change impact, exporting graph facts, or running SAST.
task-splitting-evaluation
Recursive pre-implementation GitHub task splitting and evaluation flow. Use when the user wants Claude agents to evaluate unhandled tasks, skip already-processed tasks, mark easy leaves with detailed executor-ready comments, split broad tasks into GitHub subtasks, and keep recursing until every leaf is well described…
mastermind-task-planning
Choose the lightest Mastermind workflow that fits the risk, then create an evidence-grounded verified or strict task contract for delegated implementation. Direct work deliberately uses no task spec.
mastermind-task-executor
Execute an approved Mastermind task contract within Scope, prove its Acceptance Criteria, and write the canonical file-backed executor report. Use when the user hands off a .mastermind/tasks/ - /spec.md or explicitly asks to execute an approved Mastermind task.