Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add getaero-io/gtm-eng-skills --skill deepline-gtmgit clone --depth 1 https://github.com/getaero-io/gtm-eng-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/getaero-io/gtm-eng-skills/deepline-gtm)<a href="https://agentmods.dev/skills/getaero-io/gtm-eng-skills/deepline-gtm"><img src="https://agentmods.dev/badge/skills/getaero-io/gtm-eng-skills/deepline-gtm/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/getaero-io/gtm-eng-skills/deepline-gtm"><img src="https://agentmods.dev/badge/skills/getaero-io/gtm-eng-skills/deepline-gtm.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 15 findings, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Rogue Agent · line 31 Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.Fix: Prevent the skill from modifying its own code, SKILL.md, or configuration files. Treat skill files as read-only at runtime.
- high Rogue Agent · line 163 Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.Fix: Prevent the skill from modifying its own code, SKILL.md, or configuration files. Treat skill files as read-only at runtime.
- high Rogue Agent · line 164 Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.Fix: Prevent the skill from modifying its own code, SKILL.md, or configuration files. Treat skill files as read-only at runtime.
- high Rogue Agent · line 165 Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.Fix: Prevent the skill from modifying its own code, SKILL.md, or configuration files. Treat skill files as read-only at runtime.
- high Rogue Agent · line 166 Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.Fix: Prevent the skill from modifying its own code, SKILL.md, or configuration files. Treat skill files as read-only at runtime.
- medium Excessive Agency · line 65 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
- medium Excessive Agency · line 97 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
- medium Memory Poisoning · line 116 Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.Fix: Implement context-window management that detects and rejects padding or stuffing attempts. Prioritize system instructions over user-injected content.
- medium Prompt Injection · line 116 Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.Fix: Remove the large whitespace padding (blank-line blocks or long space runs) and review any content hidden below or to the right of it. Keep skill files compact and reviewable so no instructions can be
- medium Prompt Injection · line 116 Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.Fix: Remove the large whitespace padding (blank-line blocks or long space runs) and review any content hidden below or to the right of it. Keep skill files compact and reviewable so no instructions can be
- medium Prompt Injection · line 118 Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.Fix: Remove the large whitespace padding (blank-line blocks or long space runs) and review any content hidden below or to the right of it. Keep skill files compact and reviewable so no instructions can be
- medium Prompt Injection · line 118 Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.Fix: Remove the large whitespace padding (blank-line blocks or long space runs) and review any content hidden below or to the right of it. Keep skill files compact and reviewable so no instructions can be
- medium Prompt Injection · line 120 Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.Fix: Remove the large whitespace padding (blank-line blocks or long space runs) and review any content hidden below or to the right of it. Keep skill files compact and reviewable so no instructions can be
- medium Prompt Injection · line 121 Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.Fix: Remove the large whitespace padding (blank-line blocks or long space runs) and review any content hidden below or to the right of it. Keep skill files compact and reviewable so no instructions can be
- medium Prompt Injection · line 131 Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.Fix: Remove the large whitespace padding (blank-line blocks or long space runs) and review any content hidden below or to the right of it. Keep skill files compact and reviewable so no instructions can be
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00333 | $0.09364 |
| Opus 5 | $0.00167 | $0.04682 |
| Sonnet 5 | $0.00067 | $0.01873 |
| Haiku 4.5 | $0.00033 | $0.00936 |
Grade A, and why
deepline-gtm scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
**Sites requiring auth:** Don't use Apify. Tell the user to use Claude in Chrome or guide them through Inspect Element to get a curl command with headers (user is non-technical). How it starts
The opening of the file, as written. The whole thing — 455 lines — stays where its author put it; the contents beside it link to each section on GitHub.
GTM Meta Skill
Quick Start
npm install -g deepline
# Fallback for secure sandboxes: mkdir -p "$HOME/.local" && npm config set prefix "$HOME/.local" && export PATH="$HOME/.local/bin:$PATH" && npm install -g deepline --registry https://code.deepline.com/api/v2/npm/
deepline auth register --wait auto
deepline auth wait --timeout 120 # completes Cowork/browser approval; no-op if already connected
deepline auth status
deepline -h
CLI resolution
Run deepline commands bare — no pipes, redirection, 2>&1, command chaining, or backgrounding around them. The CLI already formats, truncates, and prints what you need; deepline billing usage | head reads as parsing and loses output.
Run deepline when it is available. If the shell reports that command is missing, use <workspace-root>/.deepline/runtime/bin/deepline (or the npm-created .cmd shim on Windows). If neither exists, follow https://code.deepline.com/INSTALL.md to set up Deepline.
Before the first Deepline fanout in a task, run deepline preflight --json as
one standalone command and wait for it to finish. Never submit preflight beside
another Deepline command. It combines health, authentication, and balance in
one process and gives any automatic CLI update a serial boundary.
After preflight succeeds, prefix every Deepline command that may run
concurrently with DEEPLINE_SKIP_SELF_UPDATE=1. This environment prefix is the
only exception to the bare-command rule above. Serial commands may stay bare;
the opt-out is required for every member of a parallel batch.
Debug every Play run first. Start a new run with
deepline plays run <play> --input '<json>' --debug; for an existing run save
the complete retained stream with deepline runs logs <run-id> --out run.log --json, then use
deepline runs get <run-id> --full --json. This preserves the durable trail
instead of spending on a duplicate run. A caught non-2xx ctx.fetch records a
customer-safe diagnostic with its call key, method, destination origin, and
HTTP status. Generic HTTP is a separate provider surface: inspect the full run
package before treating its provider-level error status as the upstream HTTP
status or its error body as a safe customer-facing explanation.
What ships with it
60 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- .recipe-template 2.0 KB
- agents/execution-plan-creator.md 1.8 KB
- agents/list-builder.md 2.0 KB
- claude-deepline-statusline.mjs 25 KB runs code
- enriching-and-researching.md 32 KB
- finding-companies-and-contacts.md 44 KB
- prompts.json 298 KB
- provider-playbooks/adyntel.md 1000 B
- provider-playbooks/affinity.md 825 B
- provider-playbooks/ai_ark.md 8.0 KB
- provider-playbooks/akta.md 1.1 KB
- provider-playbooks/allegrow.md 3.2 KB
- provider-playbooks/amplemarket.md 4.5 KB
- provider-playbooks/apify.md 3.4 KB
- provider-playbooks/attention.md 449 B
- provider-playbooks/attio.md 5.0 KB
- provider-playbooks/aviato.md 797 B
- provider-playbooks/bettercontact.md 1.5 KB
- provider-playbooks/bigquery.md 1019 B
- provider-playbooks/bloomberry.md 935 B
- provider-playbooks/bluesky.md 139 B
- provider-playbooks/bounceban.md 773 B
- provider-playbooks/browserbase.md 1.0 KB
- provider-playbooks/builtwith.md 1.0 KB
- provider-playbooks/clay.md 875 B
- provider-playbooks/clickhouse.md 1.1 KB
- provider-playbooks/cloudflare.md 2.3 KB
- provider-playbooks/contactout.md 7.0 KB
- provider-playbooks/contextdev.md 582 B
- provider-playbooks/crustdata-v2.md 680 B
- provider-playbooks/crustdata-v3.md 5.3 KB
- provider-playbooks/crustdata.md 4.0 KB
- provider-playbooks/databricks.md 3.5 KB
- provider-playbooks/dataforseo.md 950 B
- provider-playbooks/datagma.md 4.4 KB
- provider-playbooks/deepline_ip_to_company.md 400 B
- provider-playbooks/deepline_native.md 9.2 KB
- provider-playbooks/deeplineagent.md 1.2 KB
- provider-playbooks/discolike.md 3.6 KB
- provider-playbooks/dropleads.md 8.7 KB
- provider-playbooks/emailbison.md 634 B
- provider-playbooks/emailguard.md 243 B
- provider-playbooks/enformion.md 9.3 KB
- provider-playbooks/enigma.md 1.7 KB
- provider-playbooks/exa.md 1.2 KB
- provider-playbooks/findymail.md 880 B
- provider-playbooks/firecrawl.md 2.4 KB
- provider-playbooks/fireflies.md 988 B
- provider-playbooks/forager.md 2.4 KB
- provider-playbooks/fullenrich.md 1.6 KB
- provider-playbooks/generic_http.md 348 B
- provider-playbooks/gong.md 488 B
- provider-playbooks/google_ads_audiences.md 2.0 KB
- provider-playbooks/govfiles.md 1.8 KB
- provider-playbooks/grain.md 1.0 KB
- provider-playbooks/hackernews.md 208 B
- provider-playbooks/harvestapi.md 1.8 KB
- provider-playbooks/heyreach.md 823 B
- provider-playbooks/hubspot.md 2.6 KB
- provider-playbooks/hunter.md 849 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +1 tokens per session 056950f306b4
- 2d ago Changed b25cc6ef555a
- 5d ago Changed · -3 lines 7876acd82abb
- 7d ago Changed · +7 tokens per session 9391f37f299f
- 8d ago Changed · -2 tokens per session 5cc6f1b468d8
- 9d ago Changed · +10 lines · -6 tokens per session d5a1e183edb8
- 13d ago First seen · 448 lines · 333 tokens per session scan A 38e472761eaf
deepline-gtm is a skill published in the GitHub repository getaero-io/gtm-eng-skills (58 stars, last pushed yesterday), licensed MIT. It adds 333 tokens to every session and 9,364 once invoked, about $0.0017 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
inbound-lead-enrichment
Fills in missing data for inbound leads — researches the company, identifies the person's role and seniority, finds other stakeholders at the company, checks for existing CRM relationships, and updates the lead record. Produces enriched lead data ready for qualification or outreach. Tool-agnostic.
inbound-lead-qualification
Qualifies inbound leads against full ICP criteria — company size, industry, use case fit, role/seniority of the person. Checks CRM and existing customer base for duplicates and existing relationships. Outputs a scored CSV with qualification status, reasoning, and pipeline overlap flags. Tool-agnostic — works with any…
inbound-lead-triage
Triages all inbound leads from a given period — demo requests, free trial signups, content downloads, webinar registrations, chatbot conversations. Classifies by urgency, qualifies against ICP, enriches with context, and produces a prioritized action queue with recommended response for each lead. Tool-agnostic — works…
company-contact-finder
Find decision-makers at a specific company using Apollo, Crustdata, Fiber, and PDL people search via Gooseworks MCP. Given a company name and target titles, returns a list of contacts with name, title, LinkedIn URL, and location.
job-scraper
Search for job postings across LinkedIn and Indeed. Use when users want to find open roles, monitor hiring signals, identify companies hiring for specific positions, or research competitor hiring activity. Returns job title, company, location, salary, description, seniority level, and direct apply URLs. No login or…
apollo-lead-finder
Two-phase Apollo.io prospecting: free People Search to discover ICP-matching leads, then selective enrichment to reveal emails/phones (credits per contact). Creates Apollo lists. Deduplicates against existing contacts by LinkedIn URL.