Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fmind/dotfiles/python-stacknpx skills add fmind/dotfiles --skill python-stackgit clone --depth 1 https://github.com/fmind/dotfilesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00041 | $0.03883 |
| Opus 5 | $0.00020 | $0.01942 |
| Sonnet 5 | $0.00008 | $0.00777 |
| Haiku 4.5 | $0.00004 | $0.00388 |
Grade A, and why
python-stack scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 163 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Python Stack Standard
Canonical guidelines for Python development, scaffolding, CLI scripts, web applications, and AI agents.
1. Core & Quality Stack
- Python: Target latest stable. Use modern syntax (structural pattern matching, PEP 695 type parameters/aliases, parenthesized context managers,
typing.Annotated). - Dependency Management: Use
uvexclusively. Avoid global/manual venvs. Execute tasks viauv run. Always commituv.lockin application repositories; libraries can omit it. - Task Runner: Use
mise.toml(mise.toml) for the canonical tasks:install,format,check,test,build, andwatch. See the mise skill. - Linting & Formatting: Use Ruff (
ruff check --fixandruff format) for Python; enforce zero warnings/errors and ban print statements (T201). Clean config/markup (JSON, Markdown, TOML, YAML) withdprintusing the configuration maintained by the dprint skill. - Type Checking: Use
tywrapper (ty check) for strict static typing. Use modern type annotations (e.g.,list[str],X | Y). Note:tyis pre-1.0 (fast-moving); keep it as a local check and pin a compatible range until it reaches a stable release. - Git Hooks: Use
lefthook(lefthook.yml) for pre-commit (format, check) and pre-push (test). See the lefthook skill. - Testing: Use
pytestintests/withanyioand an 85% branch-coverage gate. Keep the default suite offline; web integration tests opt into a real disposable Postgres via conftest.py and test_integration.py. - Security: Scan dependencies for known vulnerabilities with
pip-audit(uv run pip-audit), wired intomise run checkascheck:vuln. - Validation & Config: Use
Pydantic(v2+) &Pydantic Settings(BaseSettings). Keep configs in typed Python files (e.g.,config.py); restrict YAML to cross-language needs. - Logging: Use
structlog. Local:ConsoleRenderer. Production:JSONRenderer. Route standard library logs (SQLAlchemy, HTTPX) throughstructlogfor uniform JSON outputs.
What ships with it
19 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/AGENTS.md 3.2 KB
- references/conftest.py 534 B runs code
- references/env.example 174 B
- references/gitignore 112 B
- references/init-cli.py 473 B runs code
- references/init-library.py 44 B runs code
- references/init.py 3.9 KB runs code
- references/lefthook.yml 436 B
- references/LICENSE 1.0 KB
- references/main.py 59 B runs code
- references/mise.toml 3.2 KB
- references/pyproject.toml.template 3.5 KB
- references/test_cli.py 641 B runs code
- references/test_integration.py 601 B runs code
- references/test_library.py 87 B runs code
- references/test_smoke.py 173 B runs code
- references/test_web.py 2.0 KB runs code
- scripts/resolve_source_test.py 9.6 KB runs code
- scripts/resolve_source.py 8.2 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 163 lines · 41 tokens per session scan A 03c2fe3c0083
python-stack is a skill published in the GitHub repository fmind/dotfiles (4 stars, last pushed 2d ago), licensed MIT. It adds 41 tokens to every session and 3,883 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
dotfiles-bootstrap
Bootstrap a workstation with the dotfiles framework. Takes a GitHub user / owner+repo / explicit clone URL and runs dot init (which shells out to chezmoi) with the right safety prompts. Honors the active agent profile (ask / plan / apply / audit) so it defaults to dry-run in safer modes and full apply in apply.
vibe
Delegate a coding task to a cheap AI model (Mistral Vibe by default, but any provider Vibe knows about — DeepSeek, Gemini Flash, etc.) and supervise the result via git diff. Claude orchestrates, the cheap model codes. Claude consumes 500-1500 tokens per delegation regardless of how many file reads the delegate does…
aiq-research
Use when asked to run deep research or AI-Q research through a reachable NVIDIA AI-Q Blueprint backend.
obsidian-bases
Obsidian Bases database feature for YAML-based interactive note views. Use when creating .base files, writing filter queries, building formulas, configuring table/card views, or working with Obsidian properties and frontmatter databases.
telegram
Send notifications, interactive questions, or multiple-choice polls to the user via Telegram. Use when the user asks to be notified ("ping me", "notify me on Telegram", "ask me when..."), when a long-running task finishes and the user is likely away, when an irreversible action needs out-of-band confirmation, or when…
chezmoi-expert
Comprehensive chezmoi dotfiles management expertise including templates, cross-platform configuration, file naming conventions, and troubleshooting. Covers source directory management, reproducible environment setup, and chezmoi templating with Go templates. Use when user mentions chezmoi, dotfiles, cross-platform…