Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/danielc000/loom/codescapenpx skills add DanielC000/loom --skill codescapegit clone --depth 1 https://github.com/DanielC000/loomWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00090 | $0.00830 |
| Opus 5 | $0.00045 | $0.00415 |
| Sonnet 5 | $0.00018 | $0.00166 |
| Haiku 4.5 | $0.00009 | $0.00083 |
Grade A, and why
codescape scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 55 lines — stays where its author put it; the contents beside it link to each section on GitHub.
codescape
Codescape is a code-graph MCP — a per-project, ingested snapshot of the repo's structure. When your
project exposes the Codescape MCP tools (overview / list_flows / describe_symbol / what_touches /
trace_flow / boundary_map / render_tree), it is your PRIMARY orientation instrument, not a fallback.
The one thing to internalize: use the graph for structure, coordinates, and reachability, then open files ONLY to read the exact bytes you must verify or edit — at the coordinates the graph gave you. The graph REPLACES orient + locate; reading is only confirm/edit. If you re-derive the map by reading, or grep to LOCATE what the graph already pinpoints, you throw the whole point away — a measured speed / fewer-reads win collapses back into verify-by-reading.
Use the graph for three things
- ORIENT — the shape. What exists and how flows run through the system end to end (frontend + backend,
across parts/services). Reach a correct mental map with FAR fewer reads than opening files. Start here
(
overview/list_flows/trace_flow) before you open anything. - LOCATE — the coordinates. Which
file:lineeach piece lives at.describe_symbol/overview/what_touches/trace_flowreturn citation-gradefile:line— take the exact coordinates FROM the graph; don't grep to find what it already pinpoints. - REACHABILITY — what could happen. "What could render" (components + conditional branches) and "what scenarios are possible." Grep is actively BAD at these; the graph answers questions reading-by-hand can't.
Then read — targeted, at the coordinates
Open Read/grep ONLY for the irreducible step: the actual bytes you must verify or edit, opened DIRECTLY at
the file:line Codescape gave you — never searched for from scratch. A few pinpoint reads, not a re-explore.
Honest boundaries (don't oversell it)
Codescape is complementary, not a replacement — grep/Read still win for:
- Exact-string / literal search — a specific token, error string, config value: grep it.
- Freshest state — the graph is only as fresh as the last ingest; for code that just changed, confirm against the file.
- Non-modeled content — comments, config values, prose, anything that isn't a code symbol: grep.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 55 lines · 90 tokens per session scan A d3803a106399
codescape is a skill published in the GitHub repository DanielC000/loom (7 stars, last pushed 5d ago), licensed MIT. It adds 90 tokens to every session and 830 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
hr-onboarding
A new-hire onboarding plan as a single page — first week schedule, buddy + manager intro, learning track, equipment checklist, and "you're set when…" outcomes. Use when the brief mentions "onboarding", "new hire", "first week plan", or "入职".
html-ppt-taste-brutalist
16:9 HTML deck in tactical-telemetry / CRT-terminal taste. Deactivated-CRT charcoal slides, white-phosphor monospace, hazard-red accent, scanline overlay, ASCII syntax, density over decoration. Distilled from Leonxlnx/taste-skill brutalist-skill (Tactical Telemetry mode).
ligandmpnn
Inverse-fold a backbone with ligand, nucleic-acid, and metal context using LigandMPNN (Dauparas et al. 2023, github.com/dauparas/LigandMPNN). Reach for this skill to redesign the residues lining a binding pocket around a bound small molecule or cofactor, to design metal-coordinating sites where the geometry must be…
evo2
Score, embed, and generate DNA sequences with Evo 2, a long-context genomic foundation model. Use this skill when: (1) Computing per-nucleotide or per-sequence likelihoods for variant effect scoring, (2) Embedding genomic windows for downstream classification, (3) Generating DNA conditioned on a prefix, (4) Scoring…
package-author
当用户要把手头的工具打包/标准化成 pinvou 插件包时使用——包括纯技能(SKILL.md)、纯 MCP 服务或它们的组合包。用户说"打包/做成插件包/标准化这个工具/给我一个能上传的标准包/写 plugin.json/加个图标"等,或给了散乱脚本/目录要整理成可上传 zip 时,用本技能把内容规范成 plugin-protocol 标准包(补 plugin.json、补 mcp/manifest.json、补 SKILL.md、补图标、校验命名)。.
google-meet
Google Meet via gws: create spaces, fetch join links, list recordings.