skillpack-harvest

skillpack-harvest is a skill for Claude Code, Codex from cynthiajones34/GBrain. It costs 78 tokens per session (2,664 once invoked), scanned C, a copy of skillpack-harvest, MIT.

An editorial workflow for moving a tested agent skill from a host project into a shared skill bundle.

In plain words
What is it for?
Use it to preview, generalize, privacy-check, harvest, test, and review a skill before adding it to gbrain.
Why use it?
It helps remove private names and project-specific details while checking that the lifted skill does not duplicate existing ones.

Skill for Claude CodeCodex

Which agent this was written for is unclear — built for openclaw. Also seen: built for openclaw.

Needs its repository: it reads a path above its own folder, which exists only inside the repository. The line is **Convention:** see [_brain-filing-rules.md](../_brain-filing-rules.md) for.

Good fit Use it to preview, generalize, privacy-check, harvest, test, and review a skill before adding it to gbrain.

Compare 6 skills from other repositories ↓
Install

Getting it into your agent

It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.

Clone the repo
git clone --depth 1 https://github.com/cynthiajones34/GBrain
agentmods
npx agentmods add skills/cynthiajones34/gbrain/skillpack-harvest

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for skillpack-harvest

README.md
[![agentmods](https://agentmods.dev/badge/skills/cynthiajones34/gbrain/skillpack-harvest/github.svg)](https://agentmods.dev/skills/cynthiajones34/gbrain/skillpack-harvest)
Your own site
<a href="https://agentmods.dev/skills/cynthiajones34/gbrain/skillpack-harvest"><img src="https://agentmods.dev/badge/skills/cynthiajones34/gbrain/skillpack-harvest/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for skillpack-harvest

Your own site · 80×15
<a href="https://agentmods.dev/skills/cynthiajones34/gbrain/skillpack-harvest"><img src="https://agentmods.dev/badge/skills/cynthiajones34/gbrain/skillpack-harvest.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 78 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,664 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin 91% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00078 $0.02664
Opus 5 $0.00039 $0.01332
Sonnet 5 $0.00016 $0.00533
Haiku 4.5 $0.00008 $0.00266

Measured 10d ago against content hash 3c4c591b33f0, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade C, and why

skillpack-harvest scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Recursive force deletehighDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

retains its skill. Don't `rm -rf` the source after harvesting.
Origin

This is a copy

91% identical to skillpack-harvest — 15 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

skills/skillpack-harvest/SKILL.md · 271 lines

How it starts

The opening of the file, as written. The whole thing — 271 lines — stays where its author put it; the contents beside it link to each section on GitHub.

skillpack-harvest — Editorial workflow for lifting host skills into gbrain

Convention: see _brain-filing-rules.md for file placement rules. This skill writes into gbrain's own tree, not the brain repo's notes.

This skill is the inverse of gbrain skillpack scaffold. Scaffold ships skills downstream (gbrain → host). Harvest lifts proven patterns upstream (host → gbrain) so they become references every other client can scaffold.

Contract

A harvest is "properly done" when:

  1. The host skill is mature (used in production, recent routing-eval cases pass).
  2. The editorial genericization in Phase 3 has scrubbed every fork-specific reference (names, real entities, internal channels).
  3. gbrain skillpack harvest --dry-run previewed the file set.
  4. The real gbrain skillpack harvest <slug> --from <host> succeeded with status: harvested (no privacy-lint hits).
  5. bun test test/skills-conformance.test.ts passes on the new skills/<slug>/SKILL.md.
  6. The user has reviewed the diff in gbrain and explicitly approved the commit.

If any of these is incomplete, the skill is NOT yet harvested — the files may sit in gbrain's working tree, but they're not landed.

Output Format

This skill produces three artifacts in gbrain's working tree:

  1. skills/<harvested-slug>/SKILL.md (and any sibling files like routing-eval.jsonl)
  2. Paired source files at their mirror paths (e.g. src/commands/<slug>.ts) when the host SKILL.md declared them in frontmatter sources:
  3. An updated openclaw.plugin.json with the new slug added to skills: (sorted)

The session output to the user is a one-line success summary plus a list of files written. JSON mode (--json) returns the full HarvestResult shape for machine consumption.

Anti-Patterns

  • Skipping the dry-run. Always preview first. Files land in gbrain's working tree; cleanup is a git checkout away, but you shouldn't need to.
  • Trusting the linter alone. The default regex set catches the common cases. It doesn't catch every proper noun. Phase 3 (the editorial pass) is the primary defense.
  • Harvesting --no-lint without justification. The lint exists for a reason. If you bypass it, document why in the commit.
  • Harvesting a skill that's still in flux. Wait until the host version stabilizes. Otherwise you'll harvest, then re-harvest, then re-harvest, and that churns gbrain's bundle for no benefit.
  • Moving files instead of copying. Harvest is a copy. The host retains its skill. Don't rm -rf the source after harvesting.
  • Harvesting batch (multiple skills at once). Not supported, and for good reason — the editorial review per skill is real work.

Read the full file on GitHub · 271 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 271 lines · 78 tokens per session scan C 3c4c591b33f0

Subscribe to this mod's changes

skillpack-harvest is a skill published in the GitHub repository cynthiajones34/GBrain (0 stars, last pushed 1mo ago), licensed MIT. It adds 78 tokens to every session and 2,664 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). It is 91% identical to skillpack-harvest, differing in 15 lines, and is treated as a copy.