Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fmind/dotfiles/lefthooknpx skills add fmind/dotfiles --skill lefthookgit clone --depth 1 https://github.com/fmind/dotfilesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00048 | $0.01059 |
| Opus 5 | $0.00024 | $0.00530 |
| Sonnet 5 | $0.00010 | $0.00212 |
| Haiku 4.5 | $0.00005 | $0.00106 |
Grade A, and why
lefthook scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 72 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Lefthook Git Hooks Standard
Canonical git-hooks setup using lefthook. Keep hooks thin by delegating every command to a mise run task, so local hooks and CI run the exact same checks. Lefthook decides when to run; mise owns what each command does.
Principles
- pre-commit (fast): format staged files, then run the static checks and secret scan.
- pre-push (slower): the test suite.
- post-commit (optional): repair state the commit itself invalidated — for a repo that deploys a binary built from its own sources, rebuild and redeploy it here, guarded so it only fires when the commit touched a real build input. Git ignores this hook's exit status, so it reports without ever blocking a commit.
- Delegate, don't duplicate: every command is a thin
mise run <task>; the command name mirrors the task (format:go→mise run format:go). Tasks are owned by the language stack (go-stack, python-stack) — see the mise skill. - Staged formatters, whole-tree checks: formatters take
{staged_files}and restage their fixes (stage_fixed: true);check/testtake no files so they always run on the whole tree — "run everything before commit/push". - Clean output: suppress version headers and successful commands to keep commits quiet and distraction-free.
Setup
- Add lefthook using mise (Go: go-stack; Python: python-stack).
- Create
lefthook.ymlat the repo root (template below). - Install the hooks:
lefthook install(wired intomise run install).
Template
pre-commit:
parallel: false
commands:
format:dprint:
glob: "*.{json,md,toml,yaml,yml}"
priority: 10
run: mise run format:dprint {staged_files}
stage_fixed: true
format:<lang>: # one per language: format:go / format:python / format:templ ...
glob: "*.<ext>"
priority: 10
run: mise run format:<lang> {staged_files}
stage_fixed: true
check:leaks: # staged secret scan — history-mode gitleaks in `check` can't gate the incoming commit
priority: 20
run: mise run check:leaks --staged
check:
priority: 30
run: mise run check
pre-push:
commands:
test:
run: mise run test
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 72 lines · 48 tokens per session scan A 05da562fa067
lefthook is a skill published in the GitHub repository fmind/dotfiles (4 stars, last pushed 2d ago), licensed MIT. It adds 48 tokens to every session and 1,059 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
dotfiles-bootstrap
Bootstrap a workstation with the dotfiles framework. Takes a GitHub user / owner+repo / explicit clone URL and runs dot init (which shells out to chezmoi) with the right safety prompts. Honors the active agent profile (ask / plan / apply / audit) so it defaults to dry-run in safer modes and full apply in apply.
vibe
Delegate a coding task to a cheap AI model (Mistral Vibe by default, but any provider Vibe knows about — DeepSeek, Gemini Flash, etc.) and supervise the result via git diff. Claude orchestrates, the cheap model codes. Claude consumes 500-1500 tokens per delegation regardless of how many file reads the delegate does…
aiq-research
Use when asked to run deep research or AI-Q research through a reachable NVIDIA AI-Q Blueprint backend.
obsidian-bases
Obsidian Bases database feature for YAML-based interactive note views. Use when creating .base files, writing filter queries, building formulas, configuring table/card views, or working with Obsidian properties and frontmatter databases.
telegram
Send notifications, interactive questions, or multiple-choice polls to the user via Telegram. Use when the user asks to be notified ("ping me", "notify me on Telegram", "ask me when..."), when a long-running task finishes and the user is likely away, when an irreversible action needs out-of-band confirmation, or when…
chezmoi-expert
Comprehensive chezmoi dotfiles management expertise including templates, cross-platform configuration, file naming conventions, and troubleshooting. Covers source directory management, reproducible environment setup, and chezmoi templating with Go templates. Use when user mentions chezmoi, dotfiles, cross-platform…