Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add cosmix/loom --skill loom-background-jobsgit clone --depth 1 https://github.com/cosmix/loomWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cosmix/loom/loom-background-jobs)<a href="https://agentmods.dev/skills/cosmix/loom/loom-background-jobs"><img src="https://agentmods.dev/badge/skills/cosmix/loom/loom-background-jobs/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/cosmix/loom/loom-background-jobs"><img src="https://agentmods.dev/badge/skills/cosmix/loom/loom-background-jobs.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00026 | $0.05504 |
| Opus 5 | $0.00013 | $0.02752 |
| Sonnet 5 | $0.00005 | $0.01101 |
| Haiku 4.5 | $0.00003 | $0.00550 |
Grade A, and why
loom-background-jobs scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 348 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Background Jobs
Overview
Reliable async task execution: enqueue work, process it in workers decoupled from the request cycle, and survive crashes/retries without corrupting state. This file covers job queues, retries/backoff, DLQs, scheduling, worker pools, and delivery guarantees.
For pub/sub, event sourcing, CQRS, sagas, and streaming brokers (Kafka/Pulsar), see loom-event-driven — don't reimplement those here.
The two invariants everything hangs off
- At-least-once is the default. Design every handler to be idempotent. Redis-backed queues (Sidekiq, BullMQ, Celery+Redis), SQS standard, and a queue retrying after a crash can deliver work more than once. FIFO producer deduplication does not make a consumer's external side effect exactly once. The achievable goal is exactly-once effect = durable idempotency at the sink plus retry-safe handling.
- Ack after success, never before. The job must stay owned by the worker until the side effect is durably committed. Ack-then-process = at-most-once = silent data loss on crash. Process-then-ack = at-least-once = duplicates you dedup away. Always choose the latter.
Idempotency: the non-negotiable pattern
Derive a stable key from the job's business identity (not a random UUID per enqueue), and make the durable sink reject duplicates. A separate “done” flag cannot atomically cover an external side effect and a crash.
def handle(job):
key = job["idempotency_key"] # e.g. f"receipt:{order_id}"
# One transaction: UNIQUE(key) makes duplicate deliveries a successful no-op.
with db.transaction():
inserted = db.execute(
"INSERT INTO receipts (idempotency_key, order_id) VALUES (?, ?) "
"ON CONFLICT (idempotency_key) DO NOTHING",
[key, job["order_id"]],
).rowcount == 1
if inserted:
db.execute(
"INSERT INTO outbox (idempotency_key, kind, aggregate_id) "
"VALUES (?, 'send-receipt', ?)",
[key, job["order_id"]],
)
# The outbox makes the intent durable; the email sender must deduplicate by key too.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago Changed · -22 tokens per session c2bbf9bf84a9
- 11d ago First seen · 348 lines · 48 tokens per session scan A 6b24640e13fd
loom-background-jobs is a skill published in the GitHub repository cosmix/loom (54 stars, last pushed today), licensed MIT. It adds 26 tokens to every session and 5,504 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
API Discoverability for Agents
Making self-hosted services agent-discoverable — bake in a machine-readable API description (OpenAPI spec or a minimal API.md) when building, and discover-first (spec paths, repo search) before probing when integrating.
sandbox-stable
Build or maintain Cloudflare Sandbox apps on the stable @cloudflare/sandbox package. Use sandbox-next for preview apps and sandbox-migrate-to-next for stable-to-preview migrations.
durable-objects
Build, debug, or review Cloudflare Durable Objects code for persistent state and coordination.
sandbox-next
Build or maintain Cloudflare Sandbox apps on @cloudflare/sandbox@next (SDK 1.0 preview). Use sandbox-migrate-to-next when porting a stable app.
cloudflare
Discover and choose Cloudflare products for apps, APIs, AI agents, storage, networking, and security. Use for architecture and product selection, including when the user describes a need without naming a Cloudflare product; then find the relevant skill or documentation.
cloudflare-email-service
Implement or troubleshoot Cloudflare Email Sending and Email Routing integrations and their delivery configuration.