Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add DanWahlin/ai-agent-board --skill ralph-two-pass-scangit clone --depth 1 https://github.com/DanWahlin/ai-agent-boardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/danwahlin/ai-agent-board/ralph-two-pass-scan)<a href="https://agentmods.dev/skills/danwahlin/ai-agent-board/ralph-two-pass-scan"><img src="https://agentmods.dev/badge/skills/danwahlin/ai-agent-board/ralph-two-pass-scan/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/danwahlin/ai-agent-board/ralph-two-pass-scan"><img src="https://agentmods.dev/badge/skills/danwahlin/ai-agent-board/ralph-two-pass-scan.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00298 |
| Opus 5 | $0.00000 | $0.00149 |
| Sonnet 5 | $0.00000 | $0.00060 |
| Haiku 4.5 | $0.00000 | $0.00030 |
Grade A, and why
ralph-two-pass-scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to ralph-two-pass-scan — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
Skill: Ralph — Two-Pass Issue Scanning
Confidence: high Domain: work-monitoring Last validated: 2026-03-24
Context
Cuts GitHub API calls from N+1 to ~7 per round (~72% reduction) by separating list scanning from full hydration. Addresses the scanning inefficiency described in issue #596.
Pattern
Pass 1 — Lightweight Scan
gh issue list --state open --json number,title,labels,assignees --limit 100
Skip hydration if ANY of these match:
| Condition | Skip reason |
|---|---|
assignees non-empty AND no status:needs-review |
Already owned |
Labels contain status:blocked or status:waiting-external |
Externally gated |
Labels contain status:done or status:postponed |
Closed loop |
Title matches stale/noisy pattern ([chore], [auto]) |
Low-signal |
Pass 2 — Selective Hydration
For each issue surviving Pass 1:
gh issue view <number> --json number,title,body,labels,assignees,comments,state
Then apply normal Ralph triage logic. Rule of thumb: hydrate ≤ 30% of scanned list. If more than 30% survive Pass 1, tighten filter rules.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 36 lines · 0 tokens per session scan A 9acc41abe110
ralph-two-pass-scan is a skill published in the GitHub repository DanWahlin/ai-agent-board (58 stars, last pushed 16d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 298 tokens. A static security scan graded it A with 0 findings. It is 100% identical to ralph-two-pass-scan, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
pipeline-conductor
Operating procedure for the kirocrew-pipeline-conductor agent - run one issue/PR pipeline on one repository as a supervised fleet. Auto-pick items, preflight every candidate to one deterministic claim verdict, stand up one worker session per item in a dedicated folder, probe them each cycle with one script call…
github
Drive GitHub via the official gh CLI — repos, issues, pull requests, releases, gists, Actions runs, and raw REST through gh api. Use when the user asks to inspect or manage GitHub.
gh
GitHub CLI skill for interacting with GitHub via the gh command line tool. Use when Bub needs to (1) Create, view, or manage GitHub repositories, (2) Work with issues and pull requests, (3) Create and manage releases, (4) Run and monitor GitHub Actions workflows, (5) Create and manage gists, or (6) Perform any GitHub…
create-milestone
Create a GitHub milestone for an upcoming release. Suggests the next version based on the latest release, gathers all merged PRs and closed issues since that release, presents a draft with two tables (Issues and PRs) for user approval, then creates the milestone and assigns all approved items.
github-monitor
Watch your GitHub repos across four views - a combined urgency monitor (stale PRs, new issues, releases), a new-issue triage queue, a release upgrade digest, or your own opened-PR tracker.
shiplog
Recap of everything shipped since the last run - cross-repo PRs, security fixes, star deltas, and X traction, synthesized into a digest article and a ready-to-post shiplog in your voice.