create-dotfile

A tool for writing DOT graph files, which describe connected steps and routes in a workflow. It is designed for Kilroy Attractor pipelines, where nodes represent tasks and edges define what happens next.

In plain words
What is it for?
Use it to create or repair a runnable Kilroy Attractor graph, define its steps and routes, assign models, and validate the graph against the expected format.
Why use it?
It turns requirements into a validated workflow structure and applies routing and model-selection rules, reducing errors that can stop a pipeline from running correctly.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/danshapiro/kilroy/create-dotfile
Any agent
npx skills add danshapiro/kilroy --skill create-dotfile
Clone the repo
git clone --depth 1 https://github.com/danshapiro/kilroy

Made for: Claude Code, Codex.

Per session 33 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 5,779 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00033 $0.05779
Opus 5 $0.00016 $0.02890
Sonnet 5 $0.00007 $0.01156
Haiku 4.5 $0.00003 $0.00578

Measured 2d ago against content hash 4f502f29e2c4, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

create-dotfile scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

The scan reads SKILL.md. This mod also ships 2 executable files (hooks/validate-dot.sh, hooks/validate-dot.test.sh), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/create-dotfile/SKILL.md · 267 lines

How it starts

The opening of the file, as written. The whole thing — 267 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Create Dotfile

Scope

This skill owns DOT graph authoring and repair for Attractor pipelines.

In scope:

  • Turning requirements/spec/DoD into a runnable .dot graph.
  • Defining topology, node prompts, routing, model assignments, and validation behavior.
  • Enforcing DOT-specific guardrails and validator compatibility.

Out of scope:

  • Run config (run.yaml / run.json) authoring and backend policy details. Use create-runfile for that.

Overview

Core principle:

  • Prefer validated template topology over ad-hoc graph design.
  • Compose prompt text from project evidence; do not copy stale boilerplate.
  • Optimize for reliable execution and recoverability, not novelty.

Default topology source:

  • skills/create-dotfile/reference_template.dot

Model defaults source:

  • skills/create-dotfile/preferences.yaml

Workflow

  1. Fetch the current model list (required before writing any model_stylesheet).

Run: kilroy attractor modeldb suggest

Capture the output. Use ONLY the model IDs listed in the output. Do not use model IDs from memory — they go stale. If the command is unavailable, default to: claude-sonnet-4.6 (anthropic), gemini-3-flash-preview (google), gpt-4.1 (openai).

  1. Determine mode and hard constraints.
  • If non-interactive/programmatic, do not ask follow-up questions.
  • Extract explicit constraints (no fanout, model/provider requirements, deliverable paths).
  1. Gather repo evidence.
  • Read the authoritative spec/DoD sources if provided.
  • Use repo docs and files to resolve ambiguity before making assumptions.
  1. Choose topology from template first.
  • Start from reference_template.dot for node shapes, routing, and loop structure.
  • If user says no fanout or single path, remove fan-out/fan-in branch families.
  • Fan-in semantics are shape-dependent:
    • shape=tripleoctagon (parallel.fan_in) uses FanInHandler winner selection/fast-forward semantics.
    • Converging branches into a shape=box node is a manual merge handoff: branch worktrees are passed to the LLM in that box node, and the prompt must instruct the node to manually inspect and merge branch outputs (including git-based workflows such as git diff, commit inspection, and merge/cherry-pick by branch head_sha when appropriate).
  • graph-level retry_target: Set graph-level retry_target to the earliest node that preserves already-completed work on re-entry. For pipelines with an analysis or planning phase, point to plan_work or debate_consolidate so re-entry can reuse completed design docs and implementation files. Pointing retry_target at a specific implement_* node skips all sibling workers' output.

Read the full file on GitHub · 267 lines

Files

What ships with it

4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 267 lines · 33 tokens per session scan A 4f502f29e2c4

Subscribe to this mod's changes

create-dotfile is a skill published in the GitHub repository danshapiro/kilroy (218 stars, last pushed 4mo ago), licensed MIT. It adds 33 tokens to every session and 5,779 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

brainstorming

You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.

obra/superpowers · 37 tokens

chat-pet-sprite-creation

Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.

microsoft/vscode · 53 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

agent-host-chat-contributions

Build and review cross-cutting agent-host chat behavior through lifecycle contributions. Use when adding turn lifecycle side effects, prompt or context injection, restored-history transformation, protocol-action observation, or when reviewing changes that add code to AgentSideEffects or AgentService.

microsoft/vscode · 56 tokens

auto-perf-optimize

Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.

microsoft/vscode · 62 tokens