Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/codesigils/python-project-workflow-skill/python-project-workflownpx skills add CodeSigils/python-project-workflow-skill --skill python-project-workflowgit clone --depth 1 https://github.com/CodeSigils/python-project-workflow-skillWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00090 | $0.01839 |
| Opus 5 | $0.00045 | $0.00920 |
| Sonnet 5 | $0.00018 | $0.00368 |
| Haiku 4.5 | $0.00009 | $0.00184 |
Grade A, and why
python-project-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 194 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Python Project Workflow
Apply a preservation-first workflow to Python project setup, tooling, CI, packaging, compatibility, and repository-wide verification.
Framework-specific project conventions are out of scope. For Django, FastAPI, Flask, and similar frameworks, use dedicated framework guidance or preserve the project's established workflow. Do not present this generic baseline as framework-complete guidance.
Workflow
- Inspect repository instructions, version-control state, and project-native configuration before recommending or making changes.
- Classify the repository and the requested operation.
- Load only the references relevant to that classification.
- Preserve coherent local conventions unless the user explicitly requests modernization.
- Verify with project-native gates and report actual results.
Repository Classification
Apply Existing and Automation before considering Greenfield. Missing packaging metadata or tests does not make a repository greenfield when meaningful source, scripts, documentation, or history already exist.
| Signal | Classification | Guidance |
|---|---|---|
| Empty directory or explicit new-scaffold request | Greenfield | Load references/pyproject-template.md |
| Packaging metadata and coherent tooling | Existing project | Orient first, then load task-specific guidance |
| Python used for repository checkers or governance | Mature automation | Load references/mature-repo-preservation.md |
| Eval or benchmark runners | Automation with benchmarks | Also load references/eval-benchmark-hardening.md |
For isolated support scripts that fall outside this skill's trigger, use repository-native instructions and focused checks. Do not infer correctness from classification alone.
Operation Modes
- Inspect or advise: use read-only discovery. Do not install dependencies, synchronize environments, generate files, or edit configuration.
- Implement: make only changes authorized by the user and preserve unrelated worktree changes.
- Verify: run already-available project-native gates first. Treat setup or dependency installation as a separate step when it is required.
- Bootstrap: create or replace project structure only for an explicit greenfield or modernization request.
What ships with it
8 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/core-footguns.md 4.2 KB
- references/drift-classes.md 8.2 KB
- references/eval-benchmark-hardening.md 2.8 KB
- references/lint-format-typing-testing.md 5.1 KB
- references/mature-repo-preservation.md 2.4 KB
- references/pyproject-template.md 5.5 KB
- references/safe-editing.md 2.9 KB
- references/security-and-gitignore.md 2.9 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 194 lines · 90 tokens per session scan A caa2ad7e8381
python-project-workflow is a skill published in the GitHub repository CodeSigils/python-project-workflow-skill (1 stars, last pushed 9d ago), licensed MIT. It adds 90 tokens to every session and 1,839 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
load-github-action-thread
Download retained Codex GitHub Action thread artifacts and load their rollout history into the local Codex app. Use when asked to open, load, import, resume, or inspect a Codex automation thread from a GitHub Actions run or a related GitHub issue or pull request.
software-certificate-skill
面向普通用户,从真实软件项目全自动生成中国软件著作权申请资料:一次收集登记事实,自动分析业务、选择可追溯源码、取得真实界面证据,生成申请表信息、规范黑白灰操作手册、代码前后30页或全部材料及真实 DOCX/PDF;内部验证、渲染、哈希与备份只进入系统临时运行区,项目最终仅保留正式资料。适配 Codex、Claude Code、Cursor、OpenCode、WorkBuddy、QoderWork、TraeWork 及支持 Agent Skills 或 AGENTS.md 的平台。用户提到软件著作权、软著申请资料、申请表、代码材料、操作手册或软著审查时使用。.
aos-fatos
Skill para buscar e comentar as checagens de fatos mais recentes do portal Aos Fatos (aosfatos.org), filtrando por selo de veracidade (verdadeiro, falso, não é bem assim), formato de conteúdo, ano e/ou canal temático — combináveis entre si (ex: formato + ano + selo) — ou a partir da descrição livre de algo que a…
eeat-audit
Audita textos ou URLs de posts publicados segundo os parâmetros de E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness) do Google e atribui uma nota de 0 a 5 a cada pilar, com nota global ponderada. Use esta skill SEMPRE que a pessoa usuária pedir para auditar, avaliar, analisar ou revisar um texto ou…
gerador-soul
Gera um arquivo SOUL.md completo e estruturado para qualquer agente ou assistente de IA. Use esta skill SEMPRE que a pessoa usuária quiser criar um SOUL.md, definir a identidade de um agente, descrever a "alma" de um assistente, ou usar os gatilhos "/soul", "/soul.md" ou "gerar soul". Ative também quando a pessoa…
craque-neto
Faz análise de risco de projetos gritando a real, sem bajulação, no tom de voz do ex-jogador José Ferreira Neto, o 'Craque Neto', apresentador do 'Donos da Bola' (Band) e da 'Rádio Craque Neto'. A resposta é só a bronca do Neto: texto corrido de até 200 palavras, primeira pessoa, linguagem do povo, palavrão pesado…