Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/byronxlg/skillfold/skillfold-clinpx skills add byronxlg/skillfold --skill skillfold-cligit clone --depth 1 https://github.com/byronxlg/skillfoldWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/byronxlg/skillfold/skillfold-cli)<a href="https://agentmods.dev/skills/byronxlg/skillfold/skillfold-cli"><img src="https://agentmods.dev/badge/skills/byronxlg/skillfold/skillfold-cli.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00038 | $0.00608 |
| Opus 5 | $0.00019 | $0.00304 |
| Sonnet 5 | $0.00008 | $0.00122 |
| Haiku 4.5 | $0.00004 | $0.00061 |
Grade A, and why
skillfold-cli scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 52 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skillfold CLI
You use skillfold, a declarative skill manager for Claude config. Projects declare the skills they use in skillfold.yaml; skillfold installs them into .claude/skills and pins exact revisions in skillfold.lock.
Manifest
skillfold.yaml at the project root:
skills:
commit-helper: ./skills/commit-helper # local directory
frontend-design: github:owner/repo/path/to/[email protected] # GitHub (tag, branch, or SHA)
planning: npm:skillfold/[email protected] # npm package
compose:
reviewer:
description: Review code changes together with their tests.
use: [code-review, testing]
A trailing @ref after the last / pins a version. Composed skills concatenate the bodies of the skills they use into one generated skill.
Commands
skillfold init # scaffold a starter manifest + example skill
skillfold add <source> # add a skill and install it (--name to rename)
skillfold remove <name> # remove a skill and uninstall it
skillfold install # install everything, write skillfold.lock
skillfold install --frozen # CI mode: exact lockfile install, fail on drift
skillfold update [name...] # re-resolve moving refs, then reinstall
skillfold check # verify manifest, lockfile, and installed files agree
skillfold list # status table (ok / modified / not installed / not locked)
skillfold info <name> # source, pin, hash, and install path for one skill
skillfold search [query] # find skill packages on npm
Add -g / --global to manage ~/.claude/skills instead of the project.
Rules
- Commit both
skillfold.yamlandskillfold.lock. Never edit the lockfile by hand. - To change a skill's version, edit its
@refin the manifest (or runskillfold update <name>), then runskillfold install. - Never edit files under
.claude/skillsfor managed skills; edit the source (local directory or upstream) and reinstall.skillfold listshowsmodifiedwhen installed files drifted. - If
checkfails in CI, the fix is almost alwaysskillfold installlocally and committing the resulting lockfile. - Use
skillfold add npm:<package>/<skill>for published skills; theskillfoldpackage itself ships general-purpose skills (planning, research, code-review, testing, and more).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 52 lines · 38 tokens per session scan A c5a03904544b
skillfold-cli is a skill published in the GitHub repository byronxlg/skillfold (12 stars, last pushed 4d ago), licensed MIT. It adds 38 tokens to every session and 608 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
audit-onboarding-proposal
Independently audit a brownfield onboarding transcript, operational map, or exact proposed documentation patch before application. Use when a fresh reviewer must verify an $onboard-repository first pass, distinguish environment-caused Unknowns from reasoning defects, score its safety and evidence gates, or run a…
engineering-wisdom
Provide an explicitly requested, repository-grounded engineering review using contextual heuristics for code clarity, SOLID and design, testing, refactoring, architecture, and professional practice. Use only when the user invokes $engineering-wisdom or explicitly asks for this installed engineering-wisdom pack; do not…
proxmox-full
Complete Proxmox VE hypervisor management via REST API - VMs, containers, snapshots, backups, storage.
red-team-adversarial
Adversarial security and resilience analysis — auto-triggered during /review and /test based on task classification. Provides attack surface analysis, boundary testing, auth bypass attempts, dependency chain attacks, and Beast Mode stress testing.
marketing-copy
Write outbound promotional copy for a product or project: launch and update posts for community platforms and social media, store page descriptions and short blurbs, landing page headlines and calls to action, press-style announcements, and the naming of a product for another language or market. Covers what may be…
verification-before-completion
Enforce "no evidence = no completion"; run Gate Function verification before declaring done.