Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fmflurry/settings-opencode/dotnet-copnpx skills add fmflurry/settings-opencode --skill dotnet-copgit clone --depth 1 https://github.com/fmflurry/settings-opencodeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00169 | $0.01811 |
| Opus 5 | $0.00084 | $0.00905 |
| Sonnet 5 | $0.00034 | $0.00362 |
| Haiku 4.5 | $0.00017 | $0.00181 |
Grade A, and why
dotnet-cop scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 126 lines — stays where its author put it; the contents beside it link to each section on GitHub.
dotnet-cop
Pre-merge review. Compares HEAD vs origin/<target>. .NET-aware. Project-aware (reads AGENTS.md). Tooling-aware (runs dotnet build + dotnet format --verify-no-changes).
When to Activate
- Selected by
code-reviewerfor .NET guidance during/cop-review - User runs
/cop-review <target>on a .NET repo - dotnet-cop specialist is explicitly invoked
Inputs
| Arg | Required | Default | Meaning |
|---|---|---|---|
<target> |
yes | — | Target branch (e.g. main, develop, release/x) |
--level |
no | auto | junior (verbose teaching) or senior (terse). Auto = senior. |
--scope |
no | all | Comma list: minimal-api,isolation,ports-adapters,ef-core,csharp,result,ddd + optional cqrs,event-sourcing |
--no-tools |
no | false | Skip dotnet build + format check (static review only) |
Hard Rules
- Read-only. Never patch code. Output report only.
- Diff window:
git merge-base HEAD origin/<target>..HEAD. Never review changes already on target. - Confidence ≥ 80%. Skip uncertain findings. Use
❓ q:instead of speculative🔴 bug:. - Project rules win.
AGENTS.mdoverrides this skill. Re-read on every run; do not cache between sessions. - dotnet-clean-architecture ground truth: load [[dotnet-clean-architecture]] SKILL.md before flagging architecture code. Do not invent APIs or patterns.
- No fluff. No "great work", no restating what the diff already shows.
Pipeline
1. Parse args -> target, level, scope
2. git fetch <remote> <target> (silent; --quiet)
3. base = git merge-base HEAD <remote>/<target>
4. changed = git diff --name-status base..HEAD
5. Load <repo>/AGENTS.md (if exists) -> project rules
6. For each changed file:
- Skim full file (not just hunk) for context
- Apply relevant sub-checklists by path/role:
*Module.cs / *Extensions.cs -> modular-isolation.md
*Endpoint.cs (Minimal API) -> minimal-api.md
Core/Ports/Incoming/*.cs -> ports-adapters.md
Core/Ports/Outgoing/*.cs -> ports-adapters.md
Infrastructure/Adapter/*.cs -> ports-adapters.md
*DbContext.cs / Migrations/** -> ef-core.md
*.cs (any) -> csharp-strict.md
- If --scope includes ddd && Core/ domain code changed: load [[dotnet-ddd]] (review-checklist.md); defer deep CQRS/ES to optional-cqrs.md / optional-event-sourcing.md
- If --scope includes cqrs && module signals use: optional-cqrs.md
- If --scope includes event-sourcing && module signals use: optional-event-sourcing.md
7. If !--no-tools:
- dotnet build --nologo -clp:ErrorsOnly (the solution if one exists, else the relevant project(s) — fail fast)
- dotnet format --verify-no-changes (capture exit code)
8. Aggregate findings -> render via output-format.md
What ships with it
10 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 126 lines · 169 tokens per session scan A fb862a58d9cc
dotnet-cop is a skill published in the GitHub repository fmflurry/settings-opencode (172 stars, last pushed 19d ago), licensed MIT. It adds 169 tokens to every session and 1,811 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…