readonly

A read-only mode for investigating a question using the codebase and available sources without changing files, configuration, branches, issues, or remote project state. It requires evidence from the repository and traces findings back to their source.

In plain words
What is it for?
Use it by adding /readonly to an investigation or another skill request. It is suited to diagnosing behavior, bugs, designs, and class-level problems when you only want findings.
Why use it?
It prevents investigation from accidentally altering the project. It also replaces guesses with checked facts about code, documentation, tests, history, or related project records.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/checkpickerupper/skills/readonly
Any agent
npx skills add CheckPickerUpper/skills --skill readonly
Clone the repo
git clone --depth 1 https://github.com/CheckPickerUpper/skills

Made for: Claude Code, Codex.

Per session 77 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,115 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00077 $0.01115
Opus 5 $0.00039 $0.00558
Sonnet 5 $0.00015 $0.00223
Haiku 4.5 $0.00008 $0.00112

Measured 2d ago against content hash 3144dfab9f8f, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

readonly scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/engineering/readonly/SKILL.md · 66 lines

How it starts

The opening of the file, as written. The whole thing — 66 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/readonly

Prove, don't guess. Investigate with every read-only source that can answer the question, then stop before changing anything.

This is a user-invoked modifier. Use it when the user explicitly writes /readonly, including beside another skill name.

Core rule

When /readonly is present, treat every other instruction or invoked skill as diagnostic only. Run its reading, tracing, classification, and reasoning steps, but skip any step that edits files, opens issues, changes configuration, creates branches, commits, pushes, posts comments, deploys, installs, regenerates, or otherwise mutates local or remote state.

Procedure

  1. Freeze the state. Record git status --short and the current branch before investigating. Existing dirty files are user state; do not normalize, revert, stage, or explain them away.
  2. Find the answer in the repo first. Read code, docs, tests, scripts, generated descriptors, config, git history, issues, and PRs as needed. Use fast search before narrow reads.
  3. Trace to the owner. If the question is about a bug, behavior, design, or class-level problem, keep following writers, callers, schemas, generators, or specs until the codebase proves where the answer lives.
  4. Plan from evidence. If the question asks what to do next, read the repo state, active branch, recent commits, open PRs or issues when available, failing checks if readable, and local planning docs before recommending work.
  5. Avoid unsupported language. Do not answer with likely, probably, seems, I think, or estimate language for a codebase-answerable fact. Use proved, not found, or unknown after checking.
  6. Ask only after legwork. Do not ask clarifying questions until the available evidence cannot decide between materially different meanings. When asking, state what was checked and what exact missing fact blocks the answer.
  7. Stop before action. Recommendations may be concrete, but do not implement them, create tracking issues, update docs, run generators, or perform cleanup.
  8. Prove no mutation. Before the final answer, run git status --short again. If anything changed during investigation, identify it and do not hide it.

Read the full file on GitHub · 66 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 66 lines · 77 tokens per session scan A 3144dfab9f8f

Subscribe to this mod's changes

readonly is a skill published in the GitHub repository CheckPickerUpper/skills (6 stars, last pushed 4d ago), licensed MIT. It adds 77 tokens to every session and 1,115 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

solana-dev

Use when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "fuzz my Solana program", "deploy to devnet", "send a v1 transaction", "support larger transactions", "fix maxSupportedTransactionVersion", or "explain…

solana-foundation/solana-dev-skill · 250 tokens

canvas-accessibility-auditor

Accessibility audit and remediation for Canvas LMS courses. Scans content for WCAG-oriented issues, generates prioritized reports, guides fixes, and verifies remediation. Use when asked to "audit accessibility", "check WCAG", "fix accessibility issues", or "run accessibility review".

vishalsachdev/canvas-mcp · 60 tokens

canvas-course-builder

Scaffold complete Canvas LMS course structures from specs, templates, or existing courses. Creates modules, pages, assignments, and discussions in bulk. Use when asked to "build a course", "scaffold modules", "create course structure", "set up a new course", or "copy course structure".

vishalsachdev/canvas-mcp · 64 tokens

google-search-console

When the user wants to analyze Google Search Console data, use the GSC API, or interpret search performance. Also use when the user mentions "GSC," "Search Console," "indexing report," "Core Web Vitals," "Enhancements," "Insights report," "search performance," "search queries," "search performance report," "URL…

kostja94/marketing-skills · 137 tokens

brand-visual-generator

When the user wants to define, audit, or apply visual identity (typography, colors, spacing, design tokens, frontend aesthetics). Also use when the user mentions "brand style guide," "visual identity," "design system," "typography," "color palette," "brand guidelines," "AI brand aesthetics," "brand colors," "font…

kostja94/marketing-skills · 124 tokens

breadcrumb-generator

When the user wants to add, optimize, or audit breadcrumb navigation. Also use when the user mentions "breadcrumbs," "breadcrumb trail," "breadcrumb nav," "breadcrumb links," "path navigation," "site breadcrumb," "BreadcrumbList schema," "location-based breadcrumb," "attribute-based breadcrumb," "site hierarchy…

kostja94/marketing-skills · 96 tokens