Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add EternallLight/tgc-skills --skill mergedgit clone --depth 1 https://github.com/EternallLight/tgc-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/eternalllight/tgc-skills/merged)<a href="https://agentmods.dev/skills/eternalllight/tgc-skills/merged"><img src="https://agentmods.dev/badge/skills/eternalllight/tgc-skills/merged/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/eternalllight/tgc-skills/merged"><img src="https://agentmods.dev/badge/skills/eternalllight/tgc-skills/merged.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00050 | $0.00862 |
| Opus 5 | $0.00025 | $0.00431 |
| Sonnet 5 | $0.00010 | $0.00172 |
| Haiku 4.5 | $0.00005 | $0.00086 |
Grade A, and why
merged scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 64 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Merged — post-merge cleanup, checks, and (optional) release
The human just merged a PR. Run the tail of the pipeline they otherwise type by hand.
Arguments
- Optional PR URL/number (else detect:
gh pr list --state mergedor the current branch's PR). release— also cut a release after cleanup. Never release unless this word (or an explicit ask) is present — in some repos publishing a release deploys to production.
Steps
- Verify repo and merge. Resolve local
nameWithOwner, then rungh pr view <pr> --json state,mergedAt,mergeCommit,headRefName,headRefOid,url. Require the PR URL repository to match the local repo andstateto beMERGED. Otherwise stop before migration, deploy, release, or local actions. - Migration check (do not skip). Did the merged diff add DB migration files
(
gh pr diff <pr> --name-onlyagainst the repo's migrations dir)? If yes: verify the migration actually ran where the code deploys (deploy workflow run / migrator job logs) and say so explicitly. A shipped PR whose migration silently didn't run is a production incident — this check exists because it happened. - Answer the deploy question preemptively. From
.github/workflows, state what this merge triggers on its own (e.g. "staging auto-deploys on merge to the default branch; prod only on a published release") and link the running workflow if one started. - Local cleanup, limited to this PR.
- Resolve the default branch and locate its worktree plus the PR branch worktree with
git worktree list --porcelain. Before switching or removing anything, rungit status --porcelainin every involved worktree and stop if any is dirty. - Require the local PR branch tip to equal the recorded
headRefOid; otherwise skip deletion and report unpublished or post-merge commits. - Update the default branch in its existing worktree with
git pull --ff-only, or check it out in the primary worktree when free, thengit fetch --prune. Never remove the primary worktree. If the PR branch occupies the primary worktree while the default branch is checked out elsewhere, leave the branch/worktree and report why cleanup was skipped. - Remove only a clean linked worktree belonging to this PR. Try
git branch -dfirst. After a squash/rebase merge, allowgit branch -Donly because the PR is verified merged and the local tip exactly matches its recorded head. Never remove unrelated branches or worktrees. - Run
git worktree pruneto clear stale administrative records. Do not delete untracked files or vaguely named "planning artifacts"; each workflow owns and removes its own temporary files.
- Resolve the default branch and locate its worktree plus the PR branch worktree with
- Release (only if requested). Use the repo's own documented release flow.
- Report. One compact block: merged PR, migration verdict (none / ran / NOT VERIFIED — flag loudly), what auto-deploys, branches/worktrees removed, release link if cut.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 64 lines · 50 tokens per session scan A 85d76b9818eb
merged is a skill published in the GitHub repository EternallLight/tgc-skills (8 stars, last pushed 1mo ago), licensed MIT. It adds 50 tokens to every session and 862 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
prowler-commit
Creates professional git commits following conventional-commits format. Trigger: When creating commits, after completing code changes, when user asks to commit.
gh-auth-isolation
Safely manage multiple GitHub identities (EMU + personal) in agent workflows.
comet-github
A routing guide for Comet-related GitHub work. It directs requests about pull requests, issues, CI failures, ideas, and fixes to the appropriate review or implementation process.
github-skill
Work with GitHub via the gh CLI — clone repositories, create/list/merge pull requests, create/list issues, and run any other gh command (API calls, workflow runs, releases, repo administration). List operations return parsed JSON.
changelog-composer
Generates structured changelogs and release notes from git history and PRs, classifying breaking changes, features, fixes, performance, docs. Triggers on: "generate changelog", "write release notes", "what changed since", "prepare release", "release notes for", "diff since tag".
re0-merge
Review and land an external contribution the way this suite does: gate it against the thesis, land it with the author's credit intact, complete a new skill rather than merging it raw, then approve, credit, and explain before closing. Use when reviewing a pull request, as any collaborator or maintainer, not only the…