Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/debabsah/fable-method/fable-reviewnpx skills add debabsah/fable-method --skill fable-reviewgit clone --depth 1 https://github.com/debabsah/fable-methodWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00086 | $0.01016 |
| Opus 5 | $0.00043 | $0.00508 |
| Sonnet 5 | $0.00017 | $0.00203 |
| Haiku 4.5 | $0.00009 | $0.00102 |
Grade A, and why
fable-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 25 lines — stays where its author put it; the contents beside it link to each section on GitHub.
fable-review
Don't self-vibe-check. Manufacture blind adversaries — fresh context, none of your rationale — and let them attack the actual work. Uses only the built-in Agent/Task tool — no other plugin required. (For a pure code diff, a dedicated code-review command in your environment may be sharper for that narrow case; this runner needs nothing installed and covers every artifact — designs, plans, analyses, schemas, configs, prose.)
Run it
- Run the deterministic checks first — the acceptance oracle, tests, linters, validators. Don't spend a reviewer on what a tool catches; reviewers are for judgment. Between the two sit different-kind checks — types, property/invariant checks, a reference implementation, a dry run on real data — more independent of your blind spots than another model instance; prefer one where it exists.
- Size the panel to the risk tier (the method skill's table): T2 → one lens, the dominant risk; T3 → 2–5 lenses. The default first lens is the scope block's load-bearing unknowns — attack what changes everything if wrong; generic lenses (correctness/logic, security, data/edge-cases, architecture, requirements-fit, ops) fill the rest. Going past the tier minimum needs a named reason — a specific unresolved risk, not thoroughness for its own sake. One concern per lens; no overlap.
- Dispatch one
fable-lenssubagent per lens, all in a single message (multiple Agent/Task calls in one turn = they run in parallel).fable-lensships with this plugin (agents/fable-lens.md); its toolset is a harness-enforced allowlist (Read, Grep, Glob), so a reviewer cannot edit the artifact under review and cannot dispatch further subagents. That is a boundary, not a request — the difference matters, because "READ-ONLY" addressed to an agent holding Edit/Write/Bash is only a suggestion. Give each dispatch just its lens and the exact scope (files, diff range, or artifact + the plan/requirements it's judged against); the adversary rules live in the agent.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 25 lines · 86 tokens per session scan A d0c488924cc2
fable-review is a skill published in the GitHub repository debabsah/fable-method (1 stars, last pushed 1mo ago), licensed MIT. It adds 86 tokens to every session and 1,016 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
external-context
Invoke parallel document-specialist agents for external web searches and documentation lookup.
security-ownership-map
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for…
moai-ref-ui-polish
UI polish and interface-completion reference: the small visual details — concentric border radius, optical alignment, shadow-vs-border, motion easing, typography smoothing, tabular numbers, icon stroke weight, hit areas — that separate polished interfaces from generic ones. Agent-extending skill that amplifies…
cross-task-learner
Enable agent loops to learn from similar past tasks and share patterns across loops.
ralph-specum-requirements
This skill should be used only when the user explicitly asks to use $ralph-specum-requirements, or explicitly asks Ralph Specum in Codex to run the requirements phase.
devkit-create-command
Create a new slash command with AI-guided behavior definition.