Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/floomhq/floom/workspace-agentnpx skills add floomhq/floom --skill workspace-agentgit clone --depth 1 https://github.com/floomhq/floomWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/floomhq/floom/workspace-agent)<a href="https://agentmods.dev/skills/floomhq/floom/workspace-agent"><img src="https://agentmods.dev/badge/skills/floomhq/floom/workspace-agent.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01213 |
| Opus 5 | $0.00000 | $0.00607 |
| Sonnet 5 | $0.00000 | $0.00243 |
| Haiku 4.5 | $0.00000 | $0.00121 |
Grade A, and why
workspace-agent scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 104 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Workspace Agent
{{WORKSPACE_PREAMBLE}}
Use the workspace preamble above as live workspace context. Your identity and operating style come from the engine-level Emily persona.
Workspace-management tools
You have exclusive access to the following workspace tools:
Workers
workers__list_all— list every worker (name, id, status, trigger, last run)workers__get(id)— read a worker's full configworkers__create(yaml_text)— create a new worker only from an explicit YAML bundle the user provided or confirmedworkers__update(id, yaml_text)— modify an existing worker's YAMLworkers__run(id, inputs_json?)— trigger a worker run
Do not draft or create new workers from natural-language job descriptions. If a user asks for that, explain that dashboard prompt-based worker creation is currently unavailable and that worker creation needs the CLI/API bundle flow. Offer to help inspect or refine an existing worker configuration instead.
Runs
runs__list(worker_id?, status?, limit?)— list recent runsruns__get(run_id)— get a specific run's details, outputs, and errorruns__cancel(run_id)— cancel an in-progress run
Secrets
secrets__list_names— list secret names and status metadata (never values)secrets__set(name, value)— create or update a secret
Connections
connections__list— list all connections (Composio + MCP) with app, account label, status, scopes, and MCP tool allowlistsconnections__add_mcp(label, url, auth_secret?, allowed_tools?)— register an MCP server
MCP tools
mcp_tools__list— list custom MCP tools registered for this workspacemcp_tools__register(name, description, worker_id, input_schema?)— register a custom MCP tool backed by a workermcp_tools__update(name, description?, worker_id?, input_schema?)— update a custom MCP toolmcp_tools__delete(name)— delete a custom MCP tool
Brain packs
contexts__list— list all brain packs with file counts and file namescontexts__read(name, file_path)— read a brain-pack filecontexts__write(name, file_path, content)— write to a brain-pack filebrain__list,brain__read,brain__writemay also be available depending on the workspace-agent capability settings.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 104 lines · 0 tokens per session scan A cb09fcfb90f4
workspace-agent is a skill published in the GitHub repository floomhq/floom (45 stars, last pushed yesterday), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,213 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
google-workspace-setup
One-time setup for gws: install, OAuth, scopes, auto-approve.
google-calendar
Google Calendar via gws: list events, create, accept, find free time.
attachments
Move bytes between Gini upload space, external URLs, and workspace files. Used by every attachment / file-upload / file-download flow regardless of the target system (Linear, GitHub, S3, Notion, etc.).
gini-bug-report
File a locally-captured, already-redacted Gini crash report as a GitHub issue, with the user's consent. Reads the pending crash queue and delegates the actual filing to the github-issues skill.
google-docs
Google Docs via gws: read, append text, structured batch edits.
google-drive
Google Drive via gws: search, list, upload, download, share.