Borrowing it
Nothing to install: this file belongs to dereknguyen269/programing-best-practices. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/dereknguyen269/programing-best-practices/master/.kiro/steering/best-practices/SKILL.mdgit clone --depth 1 https://github.com/dereknguyen269/programing-best-practicesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/dereknguyen269/programing-best-practices/best-practices)<a href="https://agentmods.dev/skills/dereknguyen269/programing-best-practices/best-practices"><img src="https://agentmods.dev/badge/skills/dereknguyen269/programing-best-practices/best-practices.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.01337 |
| Opus 5 | $0.00000 | $0.00668 |
| Sonnet 5 | $0.00000 | $0.00267 |
| Haiku 4.5 | $0.00000 | $0.00134 |
Grade A, and why
best-practices scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- best-practices — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 156 lines — stays where its author put it; the contents beside it link to each section on GitHub.
best-practices
Searchable knowledge base of 152+ programming best practices across 30+ languages and frameworks. BM25-powered search over curated resources from industry leaders (Google, Airbnb, Uber, Mozilla, Shopify, OWASP).
Prerequisites
Python 3 must be installed:
python3 --version
How to Use This Workflow
When user asks about coding standards, best practices, style guides, code review, architecture, security, or performance for any language/framework, follow this workflow:
Step 1: Analyze User Requirements
Extract from user request:
- Language/Framework: Python, JavaScript, Go, React, Rails, etc.
- Topic: style guide, design patterns, performance, security, clean code, etc.
- Depth: quick reference vs. deep dive
Step 2: Search Best Practices (REQUIRED)
Always start with --recommend to get comprehensive results (resources + deep content):
python3 .kiro/steering/best-practices/scripts/search.py "<language> <topic>" --recommend
Examples:
python3 .kiro/steering/best-practices/scripts/search.py "python style guide" --recommend
python3 .kiro/steering/best-practices/scripts/search.py "javascript clean code" --recommend
python3 .kiro/steering/best-practices/scripts/search.py "react performance" --recommend
python3 .kiro/steering/best-practices/scripts/search.py "sql optimization" --recommend
python3 .kiro/steering/best-practices/scripts/search.py "api security" --recommend
Step 3: Supplement with Domain Searches (as needed)
# Search all resources (default)
python3 .kiro/steering/best-practices/scripts/search.py "<query>" --domain resource
# Search by language/technology overview
python3 .kiro/steering/best-practices/scripts/search.py "<query>" --domain language
# Search by category
python3 .kiro/steering/best-practices/scripts/search.py "<query>" --domain category
# Deep search within crawled content files
python3 .kiro/steering/best-practices/scripts/search.py "<query>" --content
# Deep search filtered by language
python3 .kiro/steering/best-practices/scripts/search.py "<query>" --content --lang python
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 156 lines · 0 tokens per session scan A bef80b83e771
best-practices is a skill published in the GitHub repository dereknguyen269/programing-best-practices (667 stars, last pushed 7d ago), licensed Unlicense. It costs nothing until one of its globs matches a file; then it loads 1,337 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
retro-learn
Convert delivery findings into skill, eval, workflow, and documentation improvements.
system-design-case-catalog
Answer classic system design problems as constraint-to-solution sketches and coach interview practice: URL shortener, rate limiter, news feed, chat, notification, autocomplete, crawler, unique id. Use for interview practice or naming the closest known shape for a new problem.
frontmcp-guides
Tutorials, end-to-end walkthroughs, and complete reference projects for FrontMCP. Use when you want a getting-started guide, a full worked example, or to learn best practices by following a step-by-step build rather than a single API reference. Includes a beginner weather-API server (tool plus static resource, Zod…
self-assessment
Interactive skill assessment with personalized learning path generation.
talk-stage5-script
Produces a complete 5-act pitch with speaker notes, a slide-by-slide specification, and a ready-to-paste Kimi prompt for AI slide generation. Requires validated angle and title from Stage 4. Use when you have a confirmed talk angle and need the full script, slide spec, and AI-generated presentation prompt.
talk-stage6-revision
Produces revision sheets with quick navigation by act, a master concept-to-URL table, Q&A cheat-sheet with 6-10 anticipated questions, glossary, and external resources list. Use when preparing for a talk with Q&A, creating shareable reference material for attendees, or building a safety-net glossary for live delivery.