Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fmind/dot/releasenpx skills add fmind/dot --skill releasegit clone --depth 1 https://github.com/fmind/dotWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fmind/dot/release)<a href="https://agentmods.dev/skills/fmind/dot/release"><img src="https://agentmods.dev/badge/skills/fmind/dot/release.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00042 | $0.01643 |
| Opus 5 | $0.00021 | $0.00822 |
| Sonnet 5 | $0.00008 | $0.00329 |
| Haiku 4.5 | $0.00004 | $0.00164 |
Grade A, and why
release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 113 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Release
Turn the Conventional Commits since the last tag into a versioned release (CHANGELOG.md from git-cliff, manifest bumps, an annotated tag, a GitHub release), then prove what was published; conventional-commit owns the commit grammar git-cliff parses.
Workflow
-
Check the preconditions:
- Clean working tree on
main, synced withorigin. - The proposed tag is absent locally and remotely; stop if either copy exists and never move a published tag.
- A repository workflow that owns release creation runs from the pushed tag; verify its result instead of publishing a second release from the CLI.
- Clean working tree on
-
Gate: Run the full gate (
mise run all); if the tree carries unrelated changes and the gate write-formats, run it in a temporarygit worktreeor fall back tomise run checkandmise run test(see mise). -
Compute the next version from the commit types since the last tag:
feat→ minor,fixand others → patch,!orBREAKING CHANGE→ major:git-cliff --bumped-version -
Bump manifests that are not VCS-versioned: Python
versioninpyproject.toml(unlesshatch-vcsor similar), Nodenpm version --no-git-tag-version X.Y.Z; Go and OpenTofu need no file change. -
Generate the changelog for that version:
git-cliff --bump -o CHANGELOG.md -
Commit the release; the
chore(release)subject is excluded from the changelog by design:git add CHANGELOG.md # plus the manifest bumped above, if any git commit -m "chore(release): vX.Y.Z" -
Tag and push the exact release commit atomically:
tag=vX.Y.Z release_sha=$(git rev-parse HEAD) git tag -a "$tag" -m "$tag" "$release_sha" git push --atomic origin main "refs/tags/$tag" -
Publish with the latest changelog section as notes, written to a temporary file to stay shell-agnostic:
release_tmp=$(mktemp -d) git-cliff --latest --strip all > "$release_tmp/release-notes.md" gh release create "$tag" --verify-tag --title "$tag" --notes-file "$release_tmp/release-notes.md"
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 113 lines · 42 tokens per session scan A d17d6464b4c6
release is a skill published in the GitHub repository fmind/dot (4 stars, last pushed today), licensed MIT. It adds 42 tokens to every session and 1,643 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
release
Cut or verify a versioned release — bump semver, generate the changelog with git-cliff, tag and publish on GitHub, or reconcile an already-published tag and assets.
dot-release
Prepare, tag, and push a versioned fmind/dotfiles release locally to trigger GitHub Actions CD publication.
go-stack
Build Go projects, libraries, CLIs, TUIs, web apps, or ADK agents with the standard package layout and pinned tooling.
python-stack
Build typed Python projects with uv, Ruff, ty, pytest, Litestar, and Typer. Use for packages, CLIs, web apps, tests, typing, or API verification.
hugo
Canonical Hugo static-site stack with the Hextra docs theme — Hugo Modules, mise tasks, dprint, lefthook, and GitHub Pages deploy. Use for documentation sites, project docs, and static websites.
k8s-local
Create and manage local Kubernetes clusters (k3d or kind) and deploy to them with kubectl, helm, helmfile, and skaffold. Use for local k8s cluster setup, dev loops, and debugging.