Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/caslubbers/code-design-skills/java-clean-codenpx skills add CasLubbers/code-design-skills --skill java-clean-codegit clone --depth 1 https://github.com/CasLubbers/code-design-skillsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00072 | $0.01599 |
| Opus 5 | $0.00036 | $0.00800 |
| Sonnet 5 | $0.00014 | $0.00320 |
| Haiku 4.5 | $0.00007 | $0.00160 |
Grade A, and why
java-clean-code scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
The source is not reproduced here
No licence file
A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 99 lines · 72 tokens per session scan A 2761f8f68e88
java-clean-code is a skill published in the GitHub repository CasLubbers/code-design-skills (1 stars, last pushed 7d ago), with no licence file. It adds 72 tokens to every session and 1,599 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
crawlberg
Crawl, scrape, and convert websites to Markdown using the local crawlberg CLI and its MCP server. Use when the user wants to fetch a page, follow links across a domain, enumerate URLs, or drive a real browser. Covers installation, the subcommands (scrape, crawl, map, interact, batch-scrape, batch-crawl, download…
automating-the-browser
Use when extracting a page needs scripted interaction first — click, type, press a key, scroll, wait, screenshot, or run JS before capturing the DOM. Covers crawlberg interact URL --actions with the real action schema, result shape, limits, and external-CDP options.
crawling-a-site
Use when the user wants to follow links across a domain and capture every reachable page as Markdown. Covers crawlberg crawl with depth, page caps, concurrency, rate limiting, domain scoping, robots, and output selection.
headless-fallback
Use when a static fetch returns nothing useful and the page needs a real browser. Covers --browser-mode auto|always|never, external CDP via --browser-endpoint, symptoms of JS-only pages and WAF blocks, and the performance cost.
scraping-html-to-markdown
Use when the user wants a single page rendered as clean Markdown plus structured metadata. Covers crawlberg scrape URL, JSON vs Markdown output, what metadata is returned, and how to handle JS-heavy pages.
serving-the-api
Use when the user wants a long-running HTTP service for scrape/crawl/map instead of one-shot CLI calls or the MCP server — for example wiring crawlberg into other apps over REST. Covers crawlberg serve, the Firecrawl-v1-compatible endpoints, --host/--port, and when to prefer it.