Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/dinhanhthi/coding-friend/cf-sys-debugnpx skills add dinhanhthi/coding-friend --skill cf-sys-debuggit clone --depth 1 https://github.com/dinhanhthi/coding-friendWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00128 | $0.02448 |
| Opus 5 | $0.00064 | $0.01224 |
| Sonnet 5 | $0.00026 | $0.00490 |
| Haiku 4.5 | $0.00013 | $0.00245 |
Grade A, and why
cf-sys-debug scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 270 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Systematic Debugging
CLI Requirement: OPTIONAL — Uses the memory MCP from
coding-friend-clifor fast indexed search and storage. Without the CLI: falls back to grep overdocs/memory/and direct file writes. Full functionality preserved, slower memory recall. See CLI requirements.
Custom Guide
bash "<plugin-root>/lib/load-custom-guide.sh" cf-sys-debug
If output is not empty: ## Before → before first step, ## Rules → throughout, ## After → after final step.
Core Constraint
Do not touch code until you can state the root cause in one sentence:
"I believe the root cause is [X] because [evidence]."
Name a specific file, function, and line. Vague labels are not testable. If you cannot be that specific, you do not have a hypothesis yet.
Same symptom after a fix = hard stop. Recurrence or "let me just try this" means the hypothesis is unfinished. Re-read the execution path from scratch before touching code again.
After 3 failed hypotheses, stop. Use the Handoff Format below. Ask how to proceed.
Rationalization Watch
Stop and re-examine when these surface:
| Thought | Rule |
|---|---|
| "I'll just try this one thing" | Write the hypothesis first |
| "I'm confident it's X" | Confidence is not evidence — instrument it |
| "Probably the same issue as before" | Re-read the execution path from scratch |
| "It works on my machine" | Environment difference IS the bug — enumerate every env difference |
| "One more restart should fix it" | Read the last error verbatim. Max two restarts without new evidence |
Progress Signals
Diagnosis is moving when:
- A log line matches the hypothesis → find one more independent piece of evidence
- You can predict the next error → run the prediction
- Cause is in A, symptoms in B → confirm each link in the A→B chain
- You can write a test that would fail on the old code → write it before the fix
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 270 lines · 128 tokens per session scan A f7d85ce1f4f7
cf-sys-debug is a skill published in the GitHub repository dinhanhthi/coding-friend (3 stars, last pushed 3d ago), licensed MIT. It adds 128 tokens to every session and 2,448 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
terraform-skill
Use when working with Terraform or OpenTofu - creating modules, writing tests (native test framework, Terratest), setting up CI/CD pipelines, reviewing configurations, choosing between testing approaches, debugging state issues, implementing security scanning (trivy, checkov), or making infrastructure-as-code…
xlsx
当电子表格文件是主要输入或输出时使用此技能。这意味着用户想要:打开、读取、编辑或修复现有的 .xlsx、.xlsm、.csv 或 .tsv 文件(例如添加列、计算公式、格式化、制图、清理混乱数据);从头创建新的电子表格或从其他数据源创建;或在表格文件格式之间进行转换。当用户通过名称或路径引用电子表格文件时特别触发——即使是随意提及(如"我下载目录里的 xlsx")——并且想对其进行操作或从中生成内容。也适用于将混乱的表格数据文件(格式错误的行、错位的表头、垃圾数据)清理或重构为规范的电子表格。交付物必须是电子表格文件。当主要交付物是 Word 文档、HTML 报告、独立 Python 脚本、数据库管道或 Google Sheets…
terraform-cli-setup
Terraform CLI 安装与初始化技能。当用户本地未安装 Terraform 时自动完成安装,确保 terraform 命令可用并能执行 init/validate。不负责 Provider 凭证配置,凭证在实际使用时由 terraform-skill 引导。.
morph-ppt
Use this skill when the user wants a .pptx with smooth cross-slide animation — PowerPoint Morph transitions, Keynote-style continuous motion, shapes that grow / move / rotate as the slide advances. Trigger on: 'morph', 'morph transition', 'smooth transition', 'continuous animation across slides', 'Keynote-style…
officecli-word-form
Use this skill to create fillable Word forms (.docx) with real Content Controls (SDT) + legacy FormField checkboxes + MERGEFIELD mail-merge placeholders + document protection. Trigger on: 'fillable form', 'form fields', 'content controls', 'SDT', 'word form', 'fill in', 'only editable fields', 'protect document'…
oss-upload
Upload local files to Tencent COS (oss.1024code.com CDN) using coscli. Use when user wants to upload a file to CDN/OSS, or deploy static assets.