Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/docxology/codomyrmex/desloppifynpx skills add docxology/codomyrmex --skill desloppifygit clone --depth 1 https://github.com/docxology/codomyrmexWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/docxology/codomyrmex/desloppify)<a href="https://agentmods.dev/skills/docxology/codomyrmex/desloppify"><img src="https://agentmods.dev/badge/skills/docxology/codomyrmex/desloppify.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00068 | $0.00996 |
| Opus 5 | $0.00034 | $0.00498 |
| Sonnet 5 | $0.00014 | $0.00199 |
| Haiku 4.5 | $0.00007 | $0.00100 |
Grade A, and why
desloppify scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 104 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Desloppify
Goal: raise the strict score. The scoring resists gaming; improvements require real code quality work.
1. Install (Python 3.11+)
Upstream install:
pip install --upgrade "desloppify[full]"
Codomyrmex: prefer uv — after uv sync, in the project environment:
uv pip install "desloppify[full]"
For a global CLI, use uv tool install with the same extra if you want desloppify available outside the project venv.
2. Workflow guide for your IDE
Install the bundled workflow instructions for the user’s stack:
desloppify update-skill claude # or: cursor, codex, copilot, droid, windsurf, gemini
Default to cursor when the session is Cursor; otherwise match the user’s stated tool.
3. Local state and git
Keep .desloppify/ out of version control (local scan state). This repo already ignores .desloppify/ in .gitignore; do not commit that directory.
4. Excludes before scan
Before the first meaningful scan, identify paths that should not be analyzed (vendor trees, build output, generated code, git worktrees, huge submodules, caches).
- Run
desloppify exclude <path>for obvious noise. - Pause and ask the human before excluding anything ambiguous.
Codomyrmex-oriented examples (exclude when appropriate, not blindly): node_modules/, htmlcov/, .gitnexus/, __pycache__/, .venv/, venv/, submodule checkouts, src/codomyrmex/agents/hermes/evolution/ (special dependency layout per CLAUDE.md), vendored or generated trees already listed in .gitignore.
5. Scan
desloppify scan --path .
Use . for the whole repo, or a subtree (e.g. src/). Rescan periodically after batch fixes.
6. Main loop — next is the queue
desloppify next is the living execution queue, not the full backlog. It names what to fix now, which file, and the resolve command to run when done.
Repeat until clear:
- Run
desloppify next. - Implement the fix properly (large refactors and small fixes deserve the same care).
- Run the exact resolve command from the output.
- Go to step 1.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 104 lines · 68 tokens per session scan A 381184c07f38
desloppify is a skill published in the GitHub repository docxology/codomyrmex (11 stars, last pushed today), licensed MIT. It adds 68 tokens to every session and 996 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
mcporter
List, auth, and call MCP servers/tools from the terminal.
article-writing
Write articles, guides, blog posts, tutorials, newsletter issues, and other long-form content in a distinctive voice derived from supplied examples or brand guidance. Use when the user wants polished written content longer than a paragraph, especially when voice consistency, structure, and credibility matter.
mem0-oss-to-platform
Plan and then execute a migration of a project from the mem0 open-source / self-hosted SDK (the local Memory class) to the mem0 Platform / hosted / managed SDK (the MemoryClient class). Use this whenever a developer wants to move, switch, or migrate their mem0 usage off OSS/self-hosted to the hosted API — e.g.…
complete-partial-pr
Evaluate and complete an issue or PR where the submitted patch fixes only a narrow symptom of the reported pain point. Use when a contribution may miss adjacent integration surfaces, provider/spec semantics, roundtrip behavior, tests, docs, or historical maintainer decisions.
deploy-docker-compose
Run the Omnigent server as a Docker compose stack (server + Postgres) on any Docker host — your laptop, a VPS, EC2 by hand, or as the base layer of any container-platform deploy. Invoke when the user wants to build the image, bring up the compose stack, debug the stack on a host they already have, or extend the stack…
mapping-to-snomed
Maps clinical concept spans extracted by OpenMed to SNOMED CT concepts through a USER-SUPPLIED terminology server (the user's own Ontoserver, Snowstorm, or UMLS/UTS), never a bundled vocabulary. Use when the user wants to code findings, disorders, procedures, body structures, or substances to SNOMED CT, run an ECL…