Borrowing it
Nothing to install: this file belongs to GeoloeG-IsT/agents-reverse-engineer. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/GeoloeG-IsT/agents-reverse-engineer/main/.claude/skills/are-discover/SKILL.mdgit clone --depth 1 https://github.com/GeoloeG-IsT/agents-reverse-engineerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/geoloeg-ist/agents-reverse-engineer/are-discover)<a href="https://agentmods.dev/skills/geoloeg-ist/agents-reverse-engineer/are-discover"><img src="https://agentmods.dev/badge/skills/geoloeg-ist/agents-reverse-engineer/are-discover/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/geoloeg-ist/agents-reverse-engineer/are-discover"><img src="https://agentmods.dev/badge/skills/geoloeg-ist/agents-reverse-engineer/are-discover.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00009 | $0.00832 |
| Opus 5 | $0.00005 | $0.00416 |
| Sonnet 5 | $0.00002 | $0.00166 |
| Haiku 4.5 | $0.00001 | $0.00083 |
Grade A, and why
are-discover scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 52 lines — stays where its author put it; the contents beside it link to each section on GitHub.
List files that would be analyzed for documentation.
- Run ONLY this exact command:
npx agents-reverse-engineer@$VERSION discover $ARGUMENTS - DO NOT add ANY flags the user did not explicitly type
- If user typed nothing after
/are-discover, run with ZERO flags
Steps
-
Read version: Read
.claude/ARE-VERSION→ store as$VERSION. Show the user:agents-reverse-engineer v$VERSION -
Run the discover command in the background using
run_in_background: true:npx agents-reverse-engineer@$VERSION discover $ARGUMENTS -
Monitor progress by polling the latest progress log:
- Wait ~10 seconds (use
sleep 10in Bash), then use Glob to find the latest.agents-reverse-engineer/progress-*.logfile, and Read it (use theoffsetparameter to read only the last ~20 lines for long files) - Show the user a brief progress update
- Check whether the background task has completed using
TaskOutputwithblock: false - Repeat until the background task finishes
- Important: Keep polling even if no progress log exists yet (the command takes a few seconds to start writing)
- Wait ~10 seconds (use
-
On completion, read the full background task output and report number of files found.
-
Review plan and suggest exclusions:
- Read
.agents-reverse-engineer/GENERATION-PLAN.mdand.agents-reverse-engineer/config.yaml - Scan the Phase 1 file list and classify files into these categories:
- Test/spec files: matches like
*.test.*,*.spec.*,__tests__/**,__mocks__/**,*.stories.*,*.story.* - CI/CD configs:
.github/workflows/*.yml,.gitlab-ci.yml,Jenkinsfile,.circleci/**,.travis.yml - Tool configs:
.eslintrc*,.prettierrc*,jest.config.*,.editorconfig,babel.config.*,webpack.config.*,vite.config.*,rollup.config.*,tsconfig*.json,.lintstagedrc*,.huskyrc*,.stylelintrc*,commitlint.config.* - Migration files: paths containing
migrations/or matching*.migration.* - Fixture/snapshot files:
__snapshots__/**,*.fixture.*,fixtures/**,test-data/**,testdata/** - Type declarations:
*.d.ts(not source code, auto-generated or ambient) - Docker/infra:
Dockerfile*,docker-compose*,*.Dockerfile,k8s/**,terraform/**,helm/**
- Test/spec files: matches like
- For each category, count how many files from the plan match and list up to 3 example filenames
- Skip categories with zero matches — only present categories that have files in the plan
- Also skip patterns that are already in the current
config.yamlexclude list - Present the findings in a summary table showing category, file count, example files, and proposed glob patterns
- Ask the user which categories to exclude using
AskUserQuestionwithmultiSelect: true - For accepted categories, use the Edit tool to append the corresponding glob patterns to the
exclude.patternsarray in.agents-reverse-engineer/config.yaml - After editing, briefly confirm what was added
- Read
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 52 lines · 9 tokens per session scan A 5b55bcbbffc5
are-discover is a skill published in the GitHub repository GeoloeG-IsT/agents-reverse-engineer (20 stars, last pushed 1mo ago), licensed MIT. It adds 9 tokens to every session and 832 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
wttr-weather
Weather via wttr.in GET (no key). Use for weather/forecast; prefer os.http.request.
jk
Manage Jenkins controllers with jk, including jobs, runs, logs, artifacts, credentials, nodes, queues, and plugins.
repo-health-check
Use when auditing a repo before changes to find the smallest safe PR, quality risks, stale docs, missing tests, ignored-file gaps, or agent setup issues. Best first skill for unfamiliar codebases.
architecture-review
Use for clean architecture, modular monoliths, hexagonal boundaries, service boundaries, data flow, dependency direction, ADRs, or large feature planning.
performance-optimizer
Use for slow endpoints, p95/p99 latency, database query issues, frontend bundle/render performance, memory leaks, caching, profiling, or performance regressions.
hatch3r-qa-path
Produces a human-run manual QA test path from a PR, branch diff, or uncommitted working tree — a risk-ordered table of steps, expected results, and automated-coverage references plus a shippability sign-off. Rows are auto-proven via delegated verification sub-agents before emission, so the human walks only what…