Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add esneiderbravo/speclaw --skill cortexgit clone --depth 1 https://github.com/esneiderbravo/speclawWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/esneiderbravo/speclaw/cortex)<a href="https://agentmods.dev/skills/esneiderbravo/speclaw/cortex"><img src="https://agentmods.dev/badge/skills/esneiderbravo/speclaw/cortex/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/esneiderbravo/speclaw/cortex"><img src="https://agentmods.dev/badge/skills/esneiderbravo/speclaw/cortex.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00327 |
| Opus 5.5 | $0.00000 | $0.00131 |
| Sonnet 5.5 | $0.00000 | $0.00065 |
| Haiku 4.5 | $0.00000 | $0.00033 |
Grade A, and why
cortex scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Cortex — One brain. Many agents.
One brain does the critical path; mechanical work costs no agent turns.
- Branch
<type>/<slug>(the slug is the change name). - Locate with
compass_find, read withcompass_explore(include: ["source"]), not cat/grep. No LAWS.md, config, or--help. - Public-API or multi-module work:
draftskill first. - Implement the change and its test yourself; ask only when blocked.
- Run the tests once; commit with a body that says why.
- Stop. The
Stophook sizes the change from its diff and lists what its level owes inlawbook/changes/<change>/(why, checked tasks, delta spec, proposal, design). Write just that and stop again: gates run once, level 0 archives. Never run ship or edit its report. Without hooks:speclaw ship <change> --summary "<why>", last.
Never drive the harness by hand or post status updates. Review happens on the PR and never blocks you.
Only when the work splits into three or more large, independent parts, read
steps/01-load-or-start.md (fan-out lane: parallel agents, never a chain).
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · +12 lines 0b02d8fa3ae1
- 7d ago First seen · 14 lines · 0 tokens per session scan A bd3f0a1df103
cortex is a skill published in the GitHub repository esneiderbravo/speclaw (1 stars, last pushed today), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 327 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-02.
Other skills, from other repositories
repo-hygiene
Use when the scheduled repo-hygiene workflow runs from GitHub Actions (or an operator dry-run) to scan the repository for small, certain docs/test/code hygiene issues and fix them as one batched branch.
browser-use
Control the user's Chrome through the existing persistent Node REPL and the Qwen Browser SDK.
find-simplifications
Use for a periodic repo-wide sweep of qwen-code for accumulated excess surface — dead components and files, orphaned locale keys, exports nothing consumes, added-then-removed scaffolding — filing candidates on a tracking issue and landing only what a maintainer has said yes to. Repo-wide and evidence-first; every…
review-copy
Review and fix user-facing copy against termio's voice guide (VOICE.md), scoring each pass and iterating until it holds. Covers UI strings, landing site, docs, release notes, and PR or issue text. Use when the user says 'review this copy', 'does this sound like us', 'check the wording', 'audit the settings text', 'fix…
app-screenshot-debug
Drive the running termio app via AppleScript / System Events to reach a UI state (focus the window, click a sidebar project, a terminal pane, a control), capture a pixel-accurate screenshot of just that window, and read it back for visual analysis — for diagnosing layout / spacing / alignment / 'this looks ugly'…
conventional-commit
Conventional Commit - Generate Conventional Commits 1.0.0 compliant messages. MANDATORY for all git commits. Invoke when user says 'commit', 'commit this', or asks to commit code.