Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/congchuanling-dot/cohort/python-runnpx skills add congchuanling-dot/Cohort --skill python-rungit clone --depth 1 https://github.com/congchuanling-dot/CohortWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00056 | $0.00587 |
| Opus 5 | $0.00028 | $0.00293 |
| Sonnet 5 | $0.00011 | $0.00117 |
| Haiku 4.5 | $0.00006 | $0.00059 |
Grade A, and why
python-run scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a Python engineer running scripts with discipline.
Rules
- Check Python version first — always run
python3 --versionbefore anything - Check dependencies — if the script imports packages, verify they're installed via
python3 -c "import ..." - Dry-run lint before execution —
python3 -m py_compile script.pycatches syntax errors - Never run a script as root or with
sudo - Timeout — scripts that run longer than 30s should be flagged, ask user before extending
- Error output — when a script fails, read the traceback and explain it in plain language
- Never modify the script without user approval unless it's a trivial syntax fix
Process
Step 1 — Pre-flight
python3 --version
python3 -m py_compile <script>
If py_compile fails, report the syntax error with line number and stop.
Step 2 — Dependency check
Scan the script for import / from ... import statements. For each top-level import, verify:
python3 -c "import <module>"
List missing modules before the user tries to run.
Step 3 — Execute
python3 <script> [args...]
Capture stdout and stderr. If it succeeds, report the output. If it fails, go to Step 4.
Step 4 — Error analysis
For any traceback:
- Identify the error type (SyntaxError, ImportError, TypeError, etc.)
- Point to the exact line
- Explain why it likely happened
- Propose a fix (but don't apply without asking)
Examples
Simple run:
/run snake_game.py
→ Checks Python, compiles, installs missing deps if needed, runs, reports output.
With arguments:
/run goldbach.py 100
→ Same pre-flight, then python3 goldbach.py 100.
Debug on failure:
/run broken.py
→ TypeError on line 12 — "can't multiply sequence by non-int of type 'str'"
→ Explanation: you're trying to multiply a string by a string on line 12
→ Fix: cast input to int: `int(value) * 2`
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 82 lines · 56 tokens per session scan A c7e352abdbaa
python-run is a skill published in the GitHub repository congchuanling-dot/Cohort (137 stars, last pushed 16d ago), licensed MIT. It adds 56 tokens to every session and 587 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
plan
Plan mode: write markdown plan, no execution.
skill-authoring
Author SKILL.md: frontmatter, structure, writing principles.
systematic-debugging
4-phase root cause debugging: understand bugs before fixing.
github-code-review
Review PRs: diffs, inline comments via gh or REST.
requesting-code-review
Pre-commit review: security scan, quality gates, auto-fix.
simplify-code
Sequential 3-lens cleanup of recent code changes.