Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/drmahdikazempour/agent-stack/stack-graph-profilenpx skills add drmahdikazempour/agent-stack --skill stack-graph-profilegit clone --depth 1 https://github.com/drmahdikazempour/agent-stackWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00085 | $0.00374 |
| Opus 5 | $0.00043 | $0.00187 |
| Sonnet 5 | $0.00017 | $0.00075 |
| Haiku 4.5 | $0.00009 | $0.00037 |
Grade A, and why
stack-graph-profile scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
stack-graph-profile
Manage the graph backend and profile bundle.
Profiles
| Profile | Graph | Best for |
|---|---|---|
code |
codegraph | normal code repos (default) |
review |
code-review-graph | PR/review-heavy repos |
multimodal |
graphify | repos with PDFs, video, many images |
spec |
codegraph | spec-kit / cc-spex driven work |
research |
none (context-mode) | large-output sandbox (opt-in, --allow-noncommercial) |
When to use
- Repo focus shifted (more PR review, media added, spec work started).
- Graph queries are returning irrelevant or incomplete context.
What to do
- Show current: read
.agent-stack/installed.json(ornpx @drmahdikazempour/agent-stack profile show). - Switch profile:
npx @drmahdikazempour/agent-stack profile use <name>— swaps the graph + compression + skills and regenerates. - Switch only the graph:
npx @drmahdikazempour/agent-stack graph use <codegraph|code-review-graph|graphify>.
Both operations back up first, regenerate the affected files, and re-run activation verification.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 29 lines · 85 tokens per session scan A 9d4d035d5da7
stack-graph-profile is a skill published in the GitHub repository drmahdikazempour/agent-stack (2 stars, last pushed 3mo ago), licensed MIT. It adds 85 tokens to every session and 374 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
github-secret-hunting
Find leaked API keys, tokens, and credentials in public GitHub repositories.
tokf-filter
This skill should be used when the user asks to "create a filter", "write a tokf filter", "add a filter for ", "how do I filter output", or needs guidance on tokf filter step types, templates, pipes, or placement conventions.
tokf-discover
Find missed token savings in Claude Code sessions and create filters for unfiltered commands.
tokf-discover
Find missed token savings by scanning AI coding session files for commands that ran without tokf filtering.
dingtalk_channel_connect
使用可视浏览器自动完成 CoPaw 的钉钉频道接入。适用于用户提到钉钉、DingTalk、开发者后台、Client ID、Client Secret、机器人、Stream 模式、绑定或配置 channel 的场景;支持遇到登录页时暂停,等待用户登录后继续。.
linggen
Linggen — durable cross-host memory plus browser control, over two local MCP servers: ling-mem for memory, the Linggen engine for browser, X and agents. Memory: three-tier model (core + long-term + episodic staging) of who the user is, not a log of what was done; same ling-mem daemon and store in Claude Code, Codex…