Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add crenshawdev/cadence/plugin install cadenceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/crenshawdev/cadence/cad-health)<a href="https://agentmods.dev/skills/crenshawdev/cadence/cad-health"><img src="https://agentmods.dev/badge/skills/crenshawdev/cadence/cad-health/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/crenshawdev/cadence/cad-health"><img src="https://agentmods.dev/badge/skills/crenshawdev/cadence/cad-health.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00041 | $0.02199 |
| Opus 5 | $0.00020 | $0.01099 |
| Sonnet 5 | $0.00008 | $0.00440 |
| Haiku 4.5 | $0.00004 | $0.00220 |
Grade A, and why
cad-health scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 149 lines — stays where its author put it; the contents beside it link to each section on GitHub.
-
Presence.
.planning/exists with PROJECT.md, REQUIREMENTS.md, ROADMAP.md, STATE.md. A missing core doc is an issue (if the dir itself is absent, point at /cad-new-project for a blank page and /cad-adopt for a repo that already has code and history).- The run record stays out of git. Run
node "${CLAUDE_PLUGIN_ROOT}/cadence-core/bin/planning.mjs" trace ignore --root . --checkand report an issue whenignoredis false ortrackedis true. Silent when the record is ignored and untracked. A project scaffolded before that seam existed has no line of its own;--checkwrites nothing and this step never edits the user's.gitignore. The two flags are separate facts and take DIFFERENT remedies, so name the one that applies rather than one command for both:ignored:falseis a missing rule, fixed by the same command without--check;tracked:truemeans the record is in the index ALREADY, where no ignore rule reaches it, and the fix isgit rm --cached .planning/trace.jsonl. Both can be true at once, and then both steps are needed - adding the rule alone leaves a tracked file that keeps getting committed. - The capture queue, in two calls - a census of the file's sections, and a
verdict on the walked queue itself:
node "${CLAUDE_PLUGIN_ROOT}/cadence-core/bin/planning.mjs" capture-sectionsnode "${CLAUDE_PLUGIN_ROOT}/cadence-core/bin/planning.mjs" capture-checkFromcapture-sections, print one line per section whosein_walkis false, naming its heading and its bullet count, then what the number MEANS in one clause: those bullets are invisible to /cad-plan's recall. Silent whenexistsis false or every section is in the walk. It is a NAMED NOTE, not an issue, the way step 7's manifest clause is a distinct lower note:## Debt markersis written wholesale bydebt-harvestand is not a queue, so calling every out-of-walk section an issue trains the user to skim past exactly the line this is here to make readable. What is worth their attention is a count that MOVED, which they can only see because the steady-state number is printed too. Fromcapture-check, print three things, and these ARE issues..planning/CAPTURE.mdholds the phase in flight and nothing else, so each one says that stopped being true:substantiveagainstbound, naming the crossing whenover_boundis true. A crossed bound means a filing path stopped filing - the queue is carrying work that belongs on the tracker.- every
annotations[]entry with its section, line and text. An annotation is an item adjudicated the WRONG WAY: an item is resolved by REMOVAL, so re-verifying one in place made the bullet longer instead of making it leave. archive.headingwitharchive.bulletswhenarchive.presentis true. That heading has LEFT this file's contract - moving settled items to a section of the same document changes nothing about the bytes. Print both readings EVERY run, never filtered against a list of sections or items you expect. That allowlist is precisely what would have hidden the incident this check exists for - all five lost bullets sat under## Archive, the section any allowlist would have named first.
- The run record stays out of git. Run
-
STATE cursor. Exactly the 4-line schema (Phase / Status / Next / Updated - references/conventions.md).
Statusis one of the lifecycle values (ready to plan | context gathered | planned | executed | phase complete | paused).Phase: N of Mparses with N <= M (except in the closed-milestone case rule 5 states).Updatedis a date. Flag a 5th line, an unknown status, or an unparseable phase.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 149 lines · 41 tokens per session scan A 2e78d7950171
cad-health is a skill published in the GitHub repository crenshawdev/cadence (5 stars, last pushed today), licensed MIT. It adds 41 tokens to every session and 2,199 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
branch-and-worktree-workflow
Isolates feature work in its own branch or worktree and integrates it cleanly when done. Use this when starting work that should not disturb the current workspace, when several efforts must proceed in parallel on one repository, or when implementation is finished and the change needs merging, rebasing, or splitting…
loop-on-ci
Monitor PR checks and fix failures until green. Uses gh pr checks as the source of truth for PR-attached checks.
git-operations
Git command patterns, branching strategy, and safety protocols. TRIGGER when: managing branches, resolving merge conflicts, or running commit/merge/push operations. SKIP: worktree lifecycle and isolation recovery (use worktree-management); CI automation (use github-actions-template).
dockerized-service-release-deployment-workflow
Create a Dockerized-service release contract with clean GitHub Actions builds, main-anchored tags, immutable digest manifests, published-release deployments, production approval, health checks, and exact-digest rollback.
coordinate-worktrees-and-threads
Assign worktree, branch, write, validation, integration, and cleanup ownership before parallel repository work. Use when a worker will inspect or modify repository state outside the coordinator's worktree.
agile-ledger-workspace
Optional multi-repo orchestrator for Agile-Ledger. Install once at a workspace root to manage many repositories at once: discover new repositories on a GitHub org (including ones nobody told you about), clone and bootstrap them, run a single cross-repo "what changed while I was away" sync, and reconstruct undocumented…