Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/ccheney/robust-skills/bazelnpx skills add ccheney/robust-skills --skill bazelgit clone --depth 1 https://github.com/ccheney/robust-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ccheney/robust-skills/bazel)<a href="https://agentmods.dev/skills/ccheney/robust-skills/bazel"><img src="https://agentmods.dev/badge/skills/ccheney/robust-skills/bazel.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00130 | $0.05055 |
| Opus 5 | $0.00065 | $0.02527 |
| Sonnet 5 | $0.00026 | $0.01011 |
| Haiku 4.5 | $0.00013 | $0.00505 |
Grade A, and why
bazel scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 379 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Bazel Monorepos
Bazel is a graph-based build and test system for large, multi-language repositories. Treat the target graph—not folders, shell scripts, or CI job order—as the source of truth. A healthy repository has explicit dependency edges, narrow public interfaces, hermetic actions, reproducible external dependencies, and one configuration model from laptop through CI.
This skill is grounded in Bazel 9.2.0 documentation. Bazel 9 changed two fundamentals:
- Bzlmod fully replaced
WORKSPACE. Bazel 9 removed the legacyWORKSPACEimplementation. New Bazel 9 code must useMODULE.bazel, module extensions, and repository rules exposed through Bzlmod. - Language rules are external modules. Previously built-in language rules—including C++—must be declared as modules and explicitly loaded. Do not assume
cc_*,java_*,py_*, or other language rules exist natively.
For an existing repository, its checked-in .bazelversion, module versions, and compatibility constraints outrank this baseline. Do not silently upgrade them as part of an unrelated change.
First Inspection
Before proposing or editing Bazel configuration:
- Read
.bazelversion,MODULE.bazel,MODULE.bazel.lock,.bazelrc,.bazelignore, and anyREPO.bazelorVENDOR.bazelfiles that exist. - Find
BUILD,BUILD.bazel, and.bzlfiles in the affected tree. A nearerBUILDfile creates a subpackage boundary. - Inspect the specific ruleset versions and their own documentation. Bazel core version and language-rules version are independent.
- Check existing repository conventions: package granularity, visibility groups, macros, platforms, toolchain registration, CI configs, remote execution, code generation, and BUILD-file generation.
- Use graph tools before guessing. Choose
query,cquery,aquery, ormodbased on the layer being investigated. - Make the smallest graph-preserving change, format it, and validate the narrowest affected targets before widening to
//....
What ships with it
10 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- agents/openai.yaml 192 B
- references/ADOPTION.md 16 KB
- references/BUILD-GRAPH.md 15 KB
- references/BZLMOD.md 19 KB
- references/CHEATSHEET.md 15 KB
- references/CI-PERFORMANCE.md 19 KB
- references/CONFIGURATION.md 16 KB
- references/HERMETICITY-CACHING.md 19 KB
- references/QUERIES-DEBUGGING.md 18 KB
- references/STARLARK.md 18 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 379 lines · 130 tokens per session scan A 41ffc29b6427
bazel is a skill published in the GitHub repository ccheney/robust-skills (57 stars, last pushed 9d ago), licensed MIT. It adds 130 tokens to every session and 5,055 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
clean-code
Use when writing, editing, reviewing, testing, or refactoring code in any language or framework; when creating files or deciding where code belongs; when designing or changing module boundaries, layers, and dependencies; when starting a new project; or when auditing or cleaning up an existing one. Covers naming…
workflow-branch-sync
Sync the current branch with the default branch via rimba or git, then resolve conflicts file by file with a per-hunk rationale and a keep-mine / keep-main / manual recommendation before staging. Push only happens after explicit confirmation — never automatic.
workflow-pr-review
Use when reviewing a remote GitHub PR — a first-pass peer review, or a followup re-check after the owner has addressed feedback. Fetches into an ephemeral worktree, runs the reviewer agent against the updated diff with a Review Decision footer instruction, deduplicates findings against existing review threads (±5-line…
workflow-address-feedback
Use when a PR owner wants to address review feedback — fetches outstanding threads and general comments, presents a per-item triage (ADDRESSED / CLARIFIED / DEFERRED), applies fixes via the Edit tool, commits via workflow-commit-and-pr, resolves review threads via GraphQL resolveReviewThread (those without a thread…
workflow-commit-and-pr
Use when the user wants to commit staged changes or create a PR — enforces trigger-phrase discipline (preview vs commit vs ship), the [type] commit format, branch-naming check, draft-vs-ready PR prompt, and PR template detection. Pre-merge counterpart to workflow-cleanup-merged.
workflow-development
Development workflow — full lifecycle from Branch → Implement → Verify → Review → Deliver. Activated by /swe-workbench:implement, /swe-workbench:design, /swe-workbench:refactor, /swe-workbench:debug, /swe-workbench:test, /swe-workbench:architect, /swe-workbench:migrate, and /swe-workbench:document when the plan being…