Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/dwmkerr/claude-toolkit/project-setupnpx skills add dwmkerr/claude-toolkit --skill project-setupgit clone --depth 1 https://github.com/dwmkerr/claude-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/dwmkerr/claude-toolkit/project-setup)<a href="https://agentmods.dev/skills/dwmkerr/claude-toolkit/project-setup"><img src="https://agentmods.dev/badge/skills/dwmkerr/claude-toolkit/project-setup.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00046 | $0.01426 |
| Opus 5 | $0.00023 | $0.00713 |
| Sonnet 5 | $0.00009 | $0.00285 |
| Haiku 4.5 | $0.00005 | $0.00143 |
Grade A, and why
project-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 195 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Project Setup
Create a new GitHub repository with standard dwmkerr project configuration.
What Gets Created
- Private GitHub repo with description
- Branch protection - prevent direct push to main
- Squash merges only for pull requests
- Actions can create PRs enabled
- GitHub Pages enabled (Actions-based deployment)
- MIT License
- Basic README with intro and quickstart
Setup Process
1. Create the Repository
gh repo create <repo-name> \
--private \
--description "<short description>" \
--clone
2. Configure Repository Settings
# Require squash merges only, disable merge commits and rebase
gh api repos/dwmkerr/<repo-name> \
--method PATCH \
--field allow_squash_merge=true \
--field allow_merge_commit=false \
--field allow_rebase_merge=false \
--field delete_branch_on_merge=true
# Allow GitHub Actions to create PRs
gh api repos/dwmkerr/<repo-name> \
--method PATCH \
--field allow_auto_merge=true
# For org repos, workflow write permissions must be enabled at the org level
# first, otherwise the repo-level call below will fail with a 409 Conflict.
# For personal repos this call will 404 harmlessly.
gh api orgs/dwmkerr/actions/permissions/workflow \
--method PUT \
--field can_approve_pull_request_reviews=true \
--field default_workflow_permissions=write 2>/dev/null || true
gh api repos/dwmkerr/<repo-name>/actions/permissions/workflow \
--method PUT \
--field can_approve_pull_request_reviews=true \
--field default_workflow_permissions=write
# Enable GitHub Pages with Actions-based deployment
gh api repos/dwmkerr/<repo-name>/pages \
--method POST \
--field "build_type=workflow"
3. Set Up Branch Protection Ruleset
gh api repos/dwmkerr/<repo-name>/rulesets \
--method POST \
--field name=main \
--field target=branch \
--field enforcement=active \
--field 'conditions[ref_name][include][]=~DEFAULT_BRANCH' \
--field 'rules[][type]=pull_request' \
--field 'rules[][type]=deletion'
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 195 lines · 46 tokens per session scan A 203862c4e77a
project-setup is a skill published in the GitHub repository dwmkerr/claude-toolkit (23 stars, last pushed 10d ago), licensed MIT. It adds 46 tokens to every session and 1,426 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
story-readiness
Validate that a story file is implementation-ready. Checks for embedded GDD requirements, ADR references, engine notes, clear acceptance criteria, and no open design questions. Produces READY / NEEDS WORK / BLOCKED verdict with specific gaps. Use when user says 'is this story ready', 'can I start on this story', 'is…
loop
Full execution protocol for MODE: LOOP — the compound-engineering loop: brainstorm → plan → build → review → improve, iterating under defense-in-depth stop conditions with generator/critic separation, durable resumable state, and mandatory compounding learning capture. Loaded on demand by the architect when the loop…
projects
List all managed projects with status, branch, open PRs, and open issue counts — portfolio-level view.
omd:issue
불만은 채팅에 남으면 사라진다. 이 스킬은 불만을 kwakseongjae/oh-my-design의 GitHub 이슈로 옮겨 처리 가능한 큐로 만들고, 그 큐를 비우는 배치 verb까지 제공한다.
implementation-readiness
Verify BRD-lite, PRD, SRS/FRS, UX, and test prerequisites before implementation starts.
project-init
Scaffold an unconfigured directory into a configured pi project. Interactive, profile-driven: previews the planned writes, then writes AGENTS.md, .pi/settings.json and prompt files — optionally also a knowledge base, an openspec/ scaffold, and user-global /.pi/agent/settings.json. Use on a bare directory, or when the…