Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add cboone/agent-harness-plugins --skill add-community-filesgit clone --depth 1 https://github.com/cboone/agent-harness-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cboone/agent-harness-plugins/add-community-files)<a href="https://agentmods.dev/skills/cboone/agent-harness-plugins/add-community-files"><img src="https://agentmods.dev/badge/skills/cboone/agent-harness-plugins/add-community-files.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00078 | $0.01918 |
| Opus 5 | $0.00039 | $0.00959 |
| Sonnet 5 | $0.00016 | $0.00384 |
| Haiku 4.5 | $0.00008 | $0.00192 |
Grade A, and why
add-community-files scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 164 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Add Community Files
Add standard community files to a project preparing for public release. Detects the project's build system and tooling to populate contribution guidelines with relevant setup, test, and lint commands.
Files generated:
| File | Description |
|---|---|
CONTRIBUTING.md |
Contribution guidelines |
CODE_OF_CONDUCT.md |
Contributor Covenant v3.0 |
.github/SECURITY.md |
Security vulnerability report policy |
.github/PULL_REQUEST_TEMPLATE.md |
Pull request template |
Workflow
1. Gather Parameters
Auto-detect project identity
- Run
git remote get-url originto get the remote URL. - Normalize the remote and extract owner/repo:
- Strip any trailing
.gitsuffix. - If the remote is SSH-style (e.g.,
[email protected]:owner/repo), convert thehost:prefix to an HTTPS-style URL (e.g.,https://github.com/owner/repo). - From the normalized URL, take the last two path segments as
GITHUB-OWNER/PROJECT-NAME.
- Strip any trailing
- If no remote exists, fall back to the README.md H1 heading, then the directory name.
- Store
PROJECT-NAMEandGITHUB-OWNER/PROJECT-NAMEfor placeholder substitution.
Detect contact method for Code of Conduct
- Try
git config user.email. - Ask the user which contact method to use for Code of Conduct reports:
- Email address (pre-fill with the detected email)
- GitHub Discussions URL:
https://github.com/GITHUB-OWNER/PROJECT-NAME/discussions - GitHub Issues URL:
https://github.com/GITHUB-OWNER/PROJECT-NAME/issues
- Store the chosen value as
CONTACT-EMAIL.
Detect build system
Scan for build system markers using Glob. Use the first match:
| Marker | Build system | Install | Build | Test | Lint | Format |
|---|---|---|---|---|---|---|
Makefile |
Make | (check targets) | make build |
make test |
make lint |
make fmt |
package.json |
Node.js | npm install |
npm run build |
npm test |
npm run lint |
npm run format |
Cargo.toml |
Cargo | (none) | cargo build |
cargo test |
cargo clippy |
cargo fmt |
pyproject.toml |
Python (uv) | uv sync |
(none) | uv run pytest |
uv run ruff check |
uv run ruff format |
go.mod |
Go | go mod download |
go build ./... |
go test ./... |
golangci-lint run |
gofmt -w . |
Gemfile |
Ruby | bundle install |
(none) | bundle exec rake test |
bundle exec rubocop |
bundle exec rubocop -A |
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 164 lines · 78 tokens per session scan A 92a18c5e9652
add-community-files is a skill published in the GitHub repository cboone/agent-harness-plugins (2 stars, last pushed 1mo ago), licensed MIT. It adds 78 tokens to every session and 1,918 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
release-check
Pre-release verification checklist. Validates features, tests, docs, security, and quality gates before shipping. Delegates to the Centinela (QA) agent.
05-review
Review a diff read-only on three axes, code, behavior versus the plan, and relevancy, into one verdict report. Use before shipping a change. Not for fixing findings or auditing a codebase.
00-repo-init
Initialize a project repository with git init, a default branch, a bootstrap commit, CONTRIBUTING.md, and optionally the remote. Use when the user wants to init or set up a new repo, or publish to a remote. Not for committing, opening a PR, or tagging.
01-commit
Create an atomic git commit with a conventional message, optionally pushing. Use when the user wants to commit changes, optionally pushing the branch. Not for amending, rebasing, opening a pull request, or tagging a release.
02-pull-request
Create a draft pull or merge request from the current branch, in whatever VCS tool the project uses. Use when the user wants to open a pull or merge request. Not for committing, pushing, or merging a branch.
03-release-tag
Cut a semver release with an annotated tag and release notes. Use when the user wants to release, tag a release, bump the version, or cut a version. Not for a plain commit, a pull request, or amending an existing tag.