Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/echoo19/hearth/hearth-codenpx skills add echoo19/hearth --skill hearth-codegit clone --depth 1 https://github.com/echoo19/hearthWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00088 | $0.02603 |
| Opus 5 | $0.00044 | $0.01301 |
| Sonnet 5 | $0.00018 | $0.00521 |
| Haiku 4.5 | $0.00009 | $0.00260 |
Grade A, and why
hearth-code scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 249 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Scripting Hearth: the ctx stdlib
This skill covers making things happen — behavior scripts and the ctx API.
What entities/components exist in the world is the hearth-build skill;
game-feel recipes that use these APIs live in hearth-feel; the operating
loop (validate, playtest, screenshot, snapshot) is the core hearth skill.
hearth inspect api --json is the canonical, always-current ctx reference —
every member with signature, docs, and a Lua + JS example. Read it when
scripting instead of trusting memory.
Scripts and lifecycle hooks
Behavior lives in scripts/. Lua is the default (hearth create script
emits .lua); JS is equally supported (--language js). Both get the identical
ctx API and run the same in editor preview, headless playtests, and export.
hearth create script coin-spin # Lua
hearth create script boss-ai --language js
hearth create script noise --dir lib # scripts/lib/noise.lua helper
hearth attach script "Level 1" Coin scripts/coin-spin.lua
A Lua script returns a table of lifecycle hooks; JS export defaults an object
with the same hooks: onStart(ctx), onUpdate(ctx, dt),
onCollision(ctx, other), onUiEvent(ctx, event), onEvent(ctx, name, data).
Script modules
Share helpers with load-time require from the top of the file:
local noise = require("lib/noise") -- scripts/lib/noise.lua
const noise = require('lib/noise'); // scripts/lib/noise.js
A library is just a script that returns a table (Lua) or exports an object
(JS), usually with no lifecycle hooks. No new asset type. Rules that matter:
same-language only (.lua requires .lua, .js requires .js), resolution
cannot escape scripts/, cycles are errors, and require is load-time only.
Call it at the top of the file, not inside onUpdate or another hook.
Hot reload recompiles dependents when a library changes. If any compile fails,
the old graph keeps running. Module top-level state resets on successful reload,
so put state that must survive in ctx.vars.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 249 lines · 88 tokens per session scan A 9efabc1df21c
hearth-code is a skill published in the GitHub repository echoo19/hearth (63 stars, last pushed 27d ago), licensed MIT. It adds 88 tokens to every session and 2,603 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
self-evolve
Capture reusable patterns from a finished project and lift them into framework-level priors (contracts, modules, skeletons) that future projects inherit. Run only when the user explicitly requests self-evolution; the orchestrator executes the workflow.
artist-self-evolve
Distill stable art-generation patterns from a completed project, so future projects produce comparable assets without re-discovering the prompts. Lead-dispatched only — orchestrator invokes this skill from its self-evolve flow with a game-slug message; do not self-trigger.
vibegame-build
Run VibeGame's standard end-to-end game development workflow with reviewer gates. Use when the user wants to create a game from zero or evolve an existing game across multiple stages.
vibegame-start
Resume a VibeGame orchestrator session after vibegame start. Use at the beginning of a Claude or Codex session to inspect team runtime state, repair missing persistent members, load goal and GDD context, inspect tasks, and ask the user what to do next.
design-npc
Use when the user wants to design an enemy, NPC, boss, companion, civilian, or wave-spawned mob's behavior. Walks perception, personality knobs, intent layer, action state machine, telegraphs, defeat handling, and group emergence — outputs a state-machine GDScript stub plus the recommended node tree. Trigger on…
fps-controller
Use when building an FPS, first-person movement, or a 3D character that walks, jumps, and reacts to external forces — production-quality first-person controller with WASD, mouse look, jump, coyote time, jump buffering, air control, and external-velocity handling. Trigger on "FPS", "first-person", "WASD", "character…