Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/comisai/comis/package-deliverynpx skills add comisai/comis --skill package-deliverygit clone --depth 1 https://github.com/comisai/comisWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00057 | $0.00573 |
| Opus 5 | $0.00028 | $0.00287 |
| Sonnet 5 | $0.00011 | $0.00115 |
| Haiku 4.5 | $0.00006 | $0.00057 |
Grade A, and why
depot-courier scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 33 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a courier delivering packages inside an office building. This skill explains how to use the tools — figuring out where the recipient is and the best way to get there is your job.
Your tools (mcp:depot-sim/*)
Look around (read-only):
whereami— your current location, floor, moves used, and the package you're carrying.look— what's at your current spot and which adjacent locations you can move to (your exits).read_directory— read the building directory (only works at the lobby directory desk); it lists which office each employee is in.check_office— read the nameplate at the office door you're standing at (who works there).
Move and deliver (actions):
accept_package { recipient }— pick up the package for a named recipient; starts your trip at the lobby.move { to }— walk to an adjacent location (it must be one of your current exits). Each move counts.take_elevator { floor }— take the elevator to a floor (only from an elevator landing). Counts as a move.deliver { recipient }— hand over the package. This returns the graded result — you must be standing at the recipient's office.
How to make a delivery
accept_packagefor the recipient.- Work out where they are. Two ways: you can read the lobby directory, or you can explore the building (
look,move, andcheck_officeto read nameplates as you go). - Navigate to their office —
movebetween adjacent spots, andtake_elevatorto change floors from an elevator landing. - When you're at their office,
deliver.
Notes
- You can only
moveto a location listed in your currentexits. - To change floors, ride the elevator — but
take_elevatoronly works while you are standing on an elevator landing (a location namedelevator-<floor>). If you're somewhere else (e.g. the lobby or a hallway),moveonto the adjacent landing first, thentake_elevator. - Delivering when you're not at the recipient's office fails. Getting there in fewer moves is better than wandering.
- Keep track of where you've been and what you've found so you don't retrace your steps.
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 33 lines · 57 tokens per session scan A 225a88564442
depot-courier is a skill published in the GitHub repository comisai/comis (5 stars, last pushed 2d ago), licensed Apache-2.0. It adds 57 tokens to every session and 573 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
org-sync
Use when the CEO wants an organization-wide sync across PuPu's agent teams — running each org's internal sync, then a cross-org sync where departments challenge each other, converging into one decision list. Triggers: "跑一次 org sync", "全局同步", "组织盘点", "/org-sync", "各部门现在什么情况", "有什么要我拍板的".
release-feature-audit
Use when a new PuPu feature finishes implementation and needs its consistency audit before its ticket is marked done — "audit #123", "审计这个功能", "这个 feature 过一遍检查" — or when release-close-sprint roll-call finds a new feature that was never audited. Also covers standalone i18n checks ("漏翻了吗", "检查 i18n"), which used to be…
gitnexus-impact-analysis
Use when the user wants to know what will break if they change something, or needs safety analysis before editing code. Examples: "Is it safe to change X?", "What depends on this?", "What will break?".
growth-analyst
Use when analyzing PuPu's open-source growth or health for the founder — GitHub traffic, downloads/installs, releases, community, or contributor activity — or when producing a growth report or weekly COO report. Repo is haoxiang-xu/PuPu. Triggers: "how is PuPu growing?", "are people installing PuPu?", "which release…
test-api
Use when running QA / regression tests against PuPu, when verifying a code change actually works in the running app, or when reading PuPu UI/state without screenshotting manually. Triggers on tasks like "test that PuPu still creates chats correctly", "verify the new model selector works end-to-end", "send a message…
org-court
Use when any org-change proposal needs adjudication - adding/removing/redesigning agents or teams, changing org rules, or evaluating org granularity. Runs PuPu's HR court: a proposal is heard by four dimension assessors (comm efficiency / context cleanliness / signal ratio / routing cost), the judge verifies evidence…