Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/extra-org/extra/git-workflownpx skills add extra-org/extra --skill git-workflowgit clone --depth 1 https://github.com/extra-org/extraWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00038 | $0.00748 |
| Opus 5 | $0.00019 | $0.00374 |
| Sonnet 5 | $0.00008 | $0.00150 |
| Haiku 4.5 | $0.00004 | $0.00075 |
Grade A, and why
git-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 89 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill: Git Workflow
Purpose
Work safely with Git: keep changes scoped and reviewable, never overwrite the user's work, and produce clear history.
When to Use This Skill
- Before editing files (inspect current state first).
- Branching, staging, or committing.
- Preparing a change set or pull request for review.
Files to Read First
AGENTS.md(git safety + scope rules).docs/DEVELOPMENT_WORKFLOW.md.- The current diff/status of the repository.
Core Principles
- Inspect before editing. Run
git statusandgit diffto understand uncommitted work; never clobber the user's changes. - Keep changes scoped to one task; avoid massive unrelated diffs.
- Don't reformat or move files outside scope.
- Commit only when asked. Do not auto-commit; never force-push shared branches or skip hooks.
- Clear messages. Use a conventional, scoped commit style.
- No secrets. Never stage
.env, credentials, or large binaries.
Process
- Inspect:
git statusandgit diff(andgit log --oneline -5for message style). Note any pre-existing uncommitted work to preserve. - Scope the change to the current task; keep unrelated edits out.
- Stage deliberately (
git add <paths>) — review what's staged; ensure no secrets or ignored files sneak in. - Commit when asked, using the format below and a HEREDOC for the message.
- Summarize the modified files in your final response.
Commit message format
Use a conventional prefix:
feat:a new feature/capabilityfix:a bug fixrefactor:behavior-preserving restructuringdocs:documentation onlytest:tests onlychore:tooling/config/housekeeping
Example: docs: consolidate agent instructions under .ai/
Checklist Before Finishing
- Inspected
git status/git diffbefore editing; no user work clobbered. - Change is scoped to one task; no unrelated churn.
- No secrets,
.env, or large binaries staged. - Commit message (if committing) uses the conventional format.
- Only committed because the user asked.
- Modified files summarized in the final response.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 89 lines · 38 tokens per session scan A 10ef9f9fc1ab
git-workflow is a skill published in the GitHub repository extra-org/extra (108 stars, last pushed 4d ago), licensed MIT. It adds 38 tokens to every session and 748 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
skill-doc-delivery
Convert markdown to DOCX, PPTX, XLSX, PDF office documents — use when you need exportable deliverables.
peekaboo
Capture and automate macOS UI with the Peekaboo CLI.
powerpoint
Create designed, editable PowerPoint .pptx presentations with PptxGenJS. Use when the user asks to create, generate, update, or inspect a deck, slide deck, presentation, or .pptx file.
oracle
Best practices for using the oracle CLI (prompt + file bundling, engines, sessions, and file attachment patterns).
skill-intent-contract
Use when starting a complex or ambiguous task that risks scope drift.
skill-security-framing
URL validation and content sanitization for untrusted sources — use when handling external input safely.