Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fledgeling-co/fledgeling-plugins/flagshipnpx skills add fledgeling-co/fledgeling-plugins --skill flagshipgit clone --depth 1 https://github.com/fledgeling-co/fledgeling-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fledgeling-co/fledgeling-plugins/flagship)<a href="https://agentmods.dev/skills/fledgeling-co/fledgeling-plugins/flagship"><img src="https://agentmods.dev/badge/skills/fledgeling-co/fledgeling-plugins/flagship.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00299 | $0.13184 |
| Opus 5 | $0.00150 | $0.06592 |
| Sonnet 5 | $0.00060 | $0.02637 |
| Haiku 4.5 | $0.00030 | $0.01318 |
Grade A, and why
flagship scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 773 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Flagship
A flagship carries the commander and the signals. It does not command the other ships' masters — every vessel is sailed by its own captain, and the flag deck's authority is over the plan, not over the crew.
That is the literal operating model here, and it is the rule this skill exists to encode. You hold the map. You hold no authority over a peer session. Every other rule below is downstream of it.
Running as a Gemini model? Read gemini.md in this directory first, then follow this file with the overrides it names. It converts flagship's categorical scopes into a roster-sized ledger and its prose caps into bounds read back off the messages you actually sent. Other models skip it.
The authority boundary — read this before you send anything
A conducting session is a peer, not a parent. Three things follow, and all three were learned by getting them wrong:
-
You cannot close a peer's channel to its user. Ten sessions were told to route all questions through the conductor and all ten refused, correctly: a peer cannot verify a claim about their own user's wishes, and the claim arrived inside the message asking them to honour it. Ask them to route coordination to you. Their user's axes stay theirs.
-
You cannot relay an authorisation. A grant from the operator to you does not travel through you to a peer. "The operator said you may push" is permission laundering however true it is. Route the request back and let the operator answer in their own channel.
The check is not whether you are trustworthy — it is that the receiving session cannot tell a faithful relay from an unfaithful one. A misreading, a differently-worded question, or an answer meant for one lane and taken as a standing default all look identical from the other side. And the reason this rule keeps getting broken by people who have written it down: everything else a conductor sends travels with its evidence — measurements carry their samples, berth readings carry their occupant lists, findings carry their exit codes. An authorisation is the one class where evidence cannot travel, because the only evidence for it is the person, in their own channel. The conduit works so well for the first kind that it feels like it should work for the second.
What ships with it
21 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- evals/evals.json 3.2 KB
- gemini.md 18 KB
- references/authority.md 4.7 KB
- references/decisions.md 7.3 KB
- references/dispatch.md 7.3 KB
- references/evidence.md 3.6 KB
- references/lanes.md 6.9 KB
- references/propagation.md 231 KB
- references/roster-and-briefs.md 3.1 KB
- references/spawning.md 7.7 KB
- references/tiered-delegation.md 8.2 KB
- scripts/hold_berths.sh 1.9 KB runs code
- scripts/idle_probe.sh 5.6 KB runs code
- scripts/machine_read.py 5.4 KB runs code
- scripts/open_session.sh 3.7 KB runs code
- scripts/roster.py 4.1 KB runs code
- scripts/session_status.sh 1.5 KB runs code
- scripts/set_hold.sh 774 B runs code
- scripts/spawn_session.py 4.9 KB runs code
- scripts/starvation_watch.sh 17 KB runs code
- scripts/sync_script.sh 680 B runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 773 lines · 299 tokens per session scan A 09a58766a6ef
flagship is a skill published in the GitHub repository fledgeling-co/fledgeling-plugins (2 stars, last pushed today), licensed MIT. It adds 299 tokens to every session and 13,184 once invoked, about $0.0015 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
agile-product-owner
../../../product-team/agile-product-owner/skills/agile-product-owner/SKILL.md.
workthreads
SpecStory Workthreads - a weekly work-thread rollup across a team's repos from SpecStory coding histories (any agent - Claude Code, Codex, Cursor, Gemini, and more). It groups the window's sessions into threads of work per project and labels each new / open / recently closed, so a lead sees what shipped, what is still…
story-readiness
Validate that a story file is implementation-ready. Checks for embedded GDD requirements, ADR references, engine notes, clear acceptance criteria, and no open design questions. Produces READY / NEEDS WORK / BLOCKED verdict with specific gaps. Use when user says 'is this story ready', 'can I start on this story', 'is…
subagent-delegation
Canonical protocol for delegating GSD work to native Antigravity subagents — when to delegate, how to invoke, workspace isolation modes, and the inline fallback for older IDE versions.
projects
List all managed projects with status, branch, open PRs, and open issue counts — portfolio-level view.
project-init
Scaffold an unconfigured directory into a configured pi project. Interactive, profile-driven: previews the planned writes, then writes AGENTS.md, .pi/settings.json and prompt files — optionally also a knowledge base, an openspec/ scaffold, and user-global /.pi/agent/settings.json. Use on a bare directory, or when the…