Borrowing it
Nothing to install: this file belongs to engasnm111/lnwjud. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/engasnm111/lnwjud/main/.agents/skills/ponytail-debt/SKILL.mdgit clone --depth 1 https://github.com/engasnm111/lnwjudWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/engasnm111/lnwjud/ponytail-debt)<a href="https://agentmods.dev/skills/engasnm111/lnwjud/ponytail-debt"><img src="https://agentmods.dev/badge/skills/engasnm111/lnwjud/ponytail-debt/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/engasnm111/lnwjud/ponytail-debt"><img src="https://agentmods.dev/badge/skills/engasnm111/lnwjud/ponytail-debt.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00099 | $0.00440 |
| Opus 5 | $0.00049 | $0.00220 |
| Sonnet 5 | $0.00020 | $0.00088 |
| Haiku 4.5 | $0.00010 | $0.00044 |
Grade A, and why
ponytail-debt scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
8 near-identical copies found in the catalogue:
- ponytail-debt — 100% identical, 0 lines differ
- ponytail-debt — 100% identical, 0 lines differ
- ponytail-debt — 100% identical, 0 lines differ
- ponytail-debt — 100% identical, 0 lines differ
- ponytail-debt — 100% identical, 0 lines differ
- ponytail-debt — 100% identical, 0 lines differ
- ponytail-debt — 100% identical, 0 lines differ
- ponytail-debt — 97% identical, 5 lines differ
What it actually says
Every deliberate ponytail shortcut is marked with a ponytail: comment naming
its ceiling and upgrade path. This collects them into one ledger so a deferral
can't quietly become permanent.
Scan
Grep the repo for comment markers, skipping node_modules, .git, and build
output:
grep -rnE '(#|//) ?ponytail:' . (add other comment prefixes if your stack uses them)
Each hit is one ledger row. The comment prefix keeps prose that merely mentions the convention out of the ledger.
Output
One row per marker, grouped by file:
<file>:<line>, <what was simplified>. ceiling: <the limit named>. upgrade: <the trigger to revisit>.
The convention is ponytail: <ceiling>, <upgrade path>, so pull the ceiling
and the trigger straight from the comment. Want an owner per row too? add
git blame -L<line>,<line>.
Flag the rot risk: any ponytail: comment that names no upgrade path or
trigger gets a no-trigger tag, those are the ones that silently rot.
End with <N> markers, <M> with no trigger. Nothing found: No ponytail: debt. Clean ledger.
Boundaries
Reads and reports only, changes nothing. To persist it, ask and it writes the
ledger to a file (e.g. PONYTAIL-DEBT.md). One-shot. "stop ponytail-debt" or
"normal mode" to revert.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 45 lines · 99 tokens per session scan A c84fba75f0ca
ponytail-debt is a skill published in the GitHub repository engasnm111/lnwjud (153 stars, last pushed today), licensed MIT. It adds 99 tokens to every session and 440 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-11.
Other skills, from other repositories
contextual-commit
Write contextual commits that capture intent, decisions, and constraints alongside code changes. Use when committing code, finishing a task, or when the user asks to commit. Extends Conventional Commits with structured action lines in the commit body that preserve WHY code was written, not just WHAT changed.
gh-issues
Fetch GitHub issues, spawn sub-agents to implement fixes and open PRs, then monitor and address PR review comments. Usage: /gh-issues [owner/repo] [--label bug] [--limit 5] [--milestone v1.0] [--assignee @me] [--fork user/repo] [--watch] [--interval 5] [--reviews-only] [--cron] [--dry-run] [--model glm-5]…
split-and-ship
Execute an approved split plan, shipping each change group separately as its own branch and PR or as sequential commits on the current branch. Use when the user asks to "split and ship", "ship the split plan", "create separate PRs", or "split changes into branches".
do
Work an increment task by task through the ledger: task next, claim, implement, commit, task done with evidence. Use when saying "implement", "start working", or "continue increment".
cross-repo-cache
Check if cross-repo coordinator results can be reused, avoiding redundant Sonnet agent launches. Compares peer repo git hashes against stored hashes from last coordinator run. Triggers on: entering Phase 1.4.1, checking cross-repo cache, before discovering peers. Returns CROSSREPOCACHEHIT with cached status or…
creating-issues-and-pull-requests
Use when creating GitHub pull requests or issues with template compliance. Triggers: 'create a PR', 'open a pull request', 'file an issue', 'create issue'. Also invoked by finishing-a-development-branch. NOT for: deciding whether to merge or PR (use finishing-a-development-branch).