Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/cjcsecurity/claude-tabletop/tabletop-exercisenpx skills add cjcsecurity/claude-tabletop --skill tabletop-exercisegit clone --depth 1 https://github.com/cjcsecurity/claude-tabletopWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cjcsecurity/claude-tabletop/tabletop-exercise)<a href="https://agentmods.dev/skills/cjcsecurity/claude-tabletop/tabletop-exercise"><img src="https://agentmods.dev/badge/skills/cjcsecurity/claude-tabletop/tabletop-exercise.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00147 | $0.04109 |
| Opus 5 | $0.00073 | $0.02055 |
| Sonnet 5 | $0.00029 | $0.00822 |
| Haiku 4.5 | $0.00015 | $0.00411 |
Grade A, and why
tabletop-exercise scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 209 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/tabletop — generate a tabletop exercise runbook
You produce a complete tabletop exercise (TTX) package tailored to the project in the current working directory. Output is a folder of artifacts the user can run a real exercise from, plus an interactive HTML version for live facilitation.
Inputs
The skill is interactive: after a fast project recon (Step 1) it asks one round of setup questions (Step 1.5), then runs scenario triage (Step 2). Every input also accepts a flag, and passing a flag skips the matching prompt — so the same skill works flagless for first-timers and fully-flagged for scripted / repeat use. If all interactive inputs are supplied as flags, Step 1.5 is skipped entirely.
Asked interactively (with flag fast-paths)
| Input | Flag | Values | Default |
|---|---|---|---|
| Duration | --duration <len> |
30m, 60m, 90m, half-day, full-day |
90m |
| Audience / departments | --audience <who> |
eng, eng+leadership, cross-functional, board |
eng+leadership |
| Difficulty | --difficulty <lvl> |
basic, intermediate, advanced |
intermediate |
| Headcount | --headcount <range> |
2-4, 5-8, 9-15, 16+ |
5-8 |
| Scenario (Step 2 triage) | --scenario <slug> |
any slug from references/scenario-library.md |
(triage picks from 3) |
Flag-only (not surfaced interactively)
| Flag | Values | Default | Why flag-only |
|---|---|---|---|
--domain <name> |
cybersec, prodsec, devops, privacy, data-ml, platform, mobile, ai-safety |
(inferred from recon) | Recon usually picks the right domain; manual override is rare. |
--frameworks <list> |
comma-sep: NIST-CSF, SOC2, PCI, ISO27001, HIPAA, GDPR, MITRE-ATTACK |
(off) | Most exercises don't tag controls; opt-in keeps the prompt round focused. |
--no-html |
(presence) | (HTML on) | Default-on; opting out is rare. Useful for smoke tests. |
--campaign <name> |
string | none | Multi-session linked exercises — advanced / niche. |
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 209 lines · 147 tokens per session scan A ca887d8ba013
tabletop-exercise is a skill published in the GitHub repository cjcsecurity/claude-tabletop (0 stars, last pushed 3mo ago), licensed Apache-2.0. It adds 147 tokens to every session and 4,109 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
hue
Meta-skill that generates new design language skills. Works on Claude Code and Codex. Use when the user says 'create a design skill', 'generate design language', 'new design system skill', 'design skill inspired by X', 'design skill from this screenshot', '/hue', or 'use hue'. Also triggers for 'remix my design skill'…
thesis-figure-skill
生成学术论文配图:LaTeX/TikZ 代码(结构化图表,直接嵌入论文)或 draw.io XML (技术路线图、汇报配图)。自动按论文领域风格设计,编译验证后交付。 Use when the user asks for: 论文配图、画架构图、画流程图、TikZ 图、draw.io 学术图、复刻论文图、tikz/latex diagram。.
tikz-figure-code
写出高质量、一次过编译、编辑安全的 TikZ/LaTeX 配图代码的工程基础技能。 教 agent 用「按构造布局」(positioning/fit/chains/anchor) 而非「手填绝对坐标」, 附 8 条硬约束、canonical 箭头、before/after 范例、一个静态检查入口 (lint.sh)。 Use when: 写/审 TikZ 或 LaTeX 图代码、修图的排版/对齐/溢出/箭头问题、 tikz layout、latex figure code、tikz 编译报错、CJK 中文图渲染成色块。.
kling-ai
Write and improve prompts for Kling AI video generation, and pick the right Kling model for the job. Covers image-to-video, text-to-video, multi-shot storyboards, talking avatars from one photo plus audio, motion transfer, video editing of an existing clip, Element Reference for character consistency, Voice Control…
FlowForge
TRIGGER when: user asks to draw, illustrate, or visualize any process, structure, or concept — "画个流程图", "draw an architecture diagram", "帮我画个对比图", "visualize this process", "make a diagram for this doc", or mentions 流程图/架构图/示意图/对比图/时序图/泳道图/时间线. Also trigger when user provides a document/article and asks for…
kimchi
Turn a raw product idea into build-ready docs — one doc per EPIC with locked decisions, exact API contracts, a story-by-story priority plan, and an execute.md handoff Claude can build from across sessions. Gets the clarity by interrogating the user through a roster of expert personas that grill, counter, and refuse to…