Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/cloudposse/atmos/lintnpx skills add cloudposse/atmos --skill lintgit clone --depth 1 https://github.com/cloudposse/atmosWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00066 | $0.00960 |
| Opus 5 | $0.00033 | $0.00480 |
| Sonnet 5 | $0.00013 | $0.00192 |
| Haiku 4.5 | $0.00007 | $0.00096 |
Grade A, and why
lint scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 76 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Lint (patch-aware by default)
Runs this repo's real lint gate — the custom golangci-lint binary with the lintroller plugin
(.custom-gcl.yml), the same one .github/workflows/codeql.yml's lint-golangci job runs — and
fixes what it finds.
Default mode: patch-aware
Run:
atmos fix lint
This delegates to the existing atmos lint --changed (.atmos.d/lint.yaml), which builds
go.mod compatibility checks, then builds ./custom-gcl — staleness-guarded: it only
rebuilds when the binary is missing or older than its build inputs (.custom-gcl.yml or the
lintroller plugin sources), so this is cheap in the common case, not a fresh clone-and-compile
every cycle. No separate "is it built" precondition needed; atmos fix lint handles that safely
on its own.
The underlying lint run is scoped to --new-from-rev=origin/main — only findings on lines changed
vs origin/main, exactly matching CI's real gate (.github/workflows/codeql.yml's
lint-golangci job).
Zero findings → one-line no-op summary, done.
Full-repo mode (explicit only)
Only when a human explicitly asks for a full lint (e.g. "run a full lint", "lint the whole repo"
— never inferred, never run from the automated loop). Run the same staleness-guarded build the
patch-aware mode uses (atmos lint custom-gcl — only rebuilds ./custom-gcl when missing or
older than its build inputs) before invoking the binary directly, so a fresh checkout or a stale
binary after .custom-gcl.yml/lintroller changes doesn't fail outright or silently report wrong
findings:
atmos lint custom-gcl
./custom-gcl run --config=.golangci.yml
(no --new-from-rev, so it reports every existing finding, not just new ones — expect this to
surface pre-existing issues unrelated to any current patch).
Fixing findings
Delegate to Agent subagent_type: "lint-fix", passing the raw custom-gcl output. The agent
fixes what it can, re-runs the same lint command to confirm clean, and reports anything it
skipped (with a reason) rather than forcing a fix — e.g. a finding that requires a broader
refactor than patch scope. For a skipped finding when called from the automated loop, invoke the
say skill with a short message like "PR <number> has a lint finding needing your input."
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 76 lines · 66 tokens per session scan A 078c050ceaed
lint is a skill published in the GitHub repository cloudposse/atmos (1,367 stars, last pushed yesterday), licensed Apache-2.0. It adds 66 tokens to every session and 960 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
python-feature-lifecycle
Guidance for package and feature lifecycle in the Agent Framework Python codebase, including stage meanings, feature-stage decorators, feature enums, and how to move APIs from one stage to the next.
python-development
Coding standards, conventions, and patterns for developing Python code in the Agent Framework repository. Use this when writing or modifying Python source files in the python/ directory.
foundry-config-setup
Resolve missing setup caused by a hardcoded Foundry project endpoint or model in a sample. Use when a sample fails because it uses a placeholder/hardcoded projectendpoint (for example "https://your-project.services.ai.azure.com") or a hardcoded model instead of reading them from the environment.
reflect
Review recent work, find repeated workflow patterns, and suggest reusable skills, agents, commands, config changes, or playbooks. Use when the user asks to learn from past sessions, improve recurring workflows, or identify what should be turned into reusable agent instructions.
codemap
Generate comprehensive hierarchical codemaps for UNFAMILIAR repositories. Expensive operation - only use when explicitly asked for codebase documentation or initial repository mapping.
length-converter
Convert between common length units (miles, km, feet, meters) using a multiplication factor.