Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add byerlikaya/claude-starter-kit --skill reflectgit clone --depth 1 https://github.com/byerlikaya/claude-starter-kitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/byerlikaya/claude-starter-kit/reflect)<a href="https://agentmods.dev/skills/byerlikaya/claude-starter-kit/reflect"><img src="https://agentmods.dev/badge/skills/byerlikaya/claude-starter-kit/reflect/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/byerlikaya/claude-starter-kit/reflect"><img src="https://agentmods.dev/badge/skills/byerlikaya/claude-starter-kit/reflect.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00047 | $0.00973 |
| Opus 5 | $0.00023 | $0.00487 |
| Sonnet 5 | $0.00009 | $0.00195 |
| Haiku 4.5 | $0.00005 | $0.00097 |
Grade A, and why
reflect scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 60 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Reflect — step back and audit the work, not just the code
Trigger phrases: "reflect", "retro", "retrospective", "what did we miss", "step back", "introspect"
When
A nontrivial chunk of work just finished (a feature, a plan, a debugging session) and it's worth a deliberate step back before committing or moving on. This is the meta-cognitive counterpart to [[iterate]]: iterate drives a change to its exit test; reflect asks whether the exit test — and the approach behind it — was even the right one. Skip it for a one-line, unambiguous change; there's nothing to reflect on.
Measure first, then remember
Run bash .claude/hooks/session-stats.sh before answering anything below, and open the pass with what it
reports. A retro built only on recall is an interview with the least reliable witness in the room: the model
reconstructs a tidy story from a context that has already been summarised, and the stretches where it span on a
failing approach are exactly the ones it remembers least. The script counts what actually happened — prompts,
tool calls, failing loops, near-duplicate prompts, interrupts, auto-compactions.
Treat each ⚠️ as a question to answer in the pass, not a verdict: a runaway loop asks what assumption kept
failing; a repeated prompt asks what context never landed; an interrupt asks where intent diverged; an auto
compaction asks what state was silently dropped. If the numbers and your recollection disagree, the numbers are
the record. If the script is missing (a plugin install has no .claude/hooks/), say the retro is recall-based —
do not present recall as measurement.
The pass
Ask each question honestly and write the answer, not a reassurance:
- Unverified assumptions — what did I take for granted that I never checked? Name each one and whether it was actually confirmed (read the code / ran the flow) or just assumed.
- What got skipped — an edge case, an error path, a test, a doc update, a security/privacy angle. What was silently dropped, and was that a conscious trade-off or an oversight?
- Right approach? — with hindsight, is this the direction we'd still pick? Did scope creep in? Is there a simpler path we walked past ([[code-review]] altitude: could 200 lines be 50)?
- Evidence gap — which claims of "done" / "works" rest on having observed behavior vs. on inference? An unobserved "it works" is a finding (see [[iterate]] / verify: drive the real flow).
- What I'd tell the next session — the one thing a fresh context most needs to know (feeds [[handoff]]).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 60 lines · 47 tokens per session scan A f3232b0e8444
reflect is a skill published in the GitHub repository byerlikaya/claude-starter-kit (22 stars, last pushed today), licensed MIT. It adds 47 tokens to every session and 973 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
security-compliance
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security operations and incident response, and embedding security throughout the SDLC.
stride-analysis-patterns
Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
review-loop
Run the adversarial verification loop — implement, then hand the change to a fresh checker that did not write it, fix what it finds, and re-dispatch until APPROVE. Use before claiming any behavioural change is done, and on requests like "review loop", "adversarial review", "independent review", "get this verified"…
prompts-chat
Use when searching, installing, or improving AI skills and prompts via prompts.chat or skills.sh. Triggers on skill search, prompt lookup, install skill, improve prompt, prompts.chat.
writing-fragments
Grilling session that mines the user for fragments — heterogeneous nuggets of writing (claims, vignettes, sharp sentences, half-thoughts) — and appends them to a single document as raw material for a future article. Use when the user wants to develop ideas before imposing structure, or mentions "fragments", "ideate"…
caveman-help
Quick-reference card for all caveman modes, skills, and commands. One-shot display, not a persistent mode. Trigger: /caveman-help, "caveman help", "what caveman commands", "how do I use caveman".