Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/gleanwork/claude-plugins/code-ownersnpx skills add gleanwork/claude-plugins --skill code-ownersgit clone --depth 1 https://github.com/gleanwork/claude-pluginsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00050 | $0.00894 |
| Opus 5 | $0.00025 | $0.00447 |
| Sonnet 5 | $0.00010 | $0.00179 |
| Haiku 4.5 | $0.00005 | $0.00089 |
Grade A, and why
code-owners scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- code-owners — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 125 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Owners
Identify who owns, maintains, or has expertise in a specific code area.
Determine the component or codebase area from the user's request. If not specified, ask before proceeding.
Core Principles
- Multi-signal identification: Code + docs + org structure = complete picture
- Recency matters: Active maintainers are more useful than historical authors
- Be skeptical: Just having commits doesn't mean they're the right contact
- Quality over quantity: 2-3 right people beats 10 tangential names
Process
Phase 1: Find Recent Contributors
Search for who's been actively working on this code:
code_search "[component] owner:* updated:past_month"
code_search "[component] from:* updated:past_3_months"
Phase 2: Find Historical Authors
Look for original authors and significant contributors:
code_search "[component] owner:* after:2023-01-01"
Phase 3: Find Related Documentation Authors
People who wrote the docs often have deep knowledge:
search "[component] design doc OR architecture owner:*"
search "[component] RFC owner:*"
Phase 4: Cross-Reference with Org Info
Get current roles and contact info:
employee_search "[contributor names]"
Phase 5: Vet Each Candidate
For each person found, evaluate:
| Test | ✅ Active Owner | ⚠️ Consider | ❌ Reject |
|---|---|---|---|
| Ownership | Multiple commits in past 3 months, reviews PRs | Occasional activity, still relevant | Single commit, tangential involvement |
| Relevance | Same team, same area | Changed teams but retains context | Left company, completely different area |
| Knowledge | Wrote design docs, significant PRs, in CODEOWNERS | Regular contributor, knows the code | Minor commits, typo fixes |
| Contact | Owns the code, expects questions | Knowledgeable but busy/senior — suggest alternatives first | Would be surprised to be contacted |
Phase 6: Present Vetted Ownership Map
# Code Ownership: [Component]
## Vetting Summary
| Candidates Found | Active Owners | Historical | Rejected |
|------------------|---------------|------------|----------|
| [X] | [Y] | [Z] | [W] |
## Primary Contacts (Recommended)
### 1. [Name] — [Title]
**Confidence**: High
- **Why**: Most active contributor, [X] commits in past month
- **Good for**: Day-to-day questions, PR reviews
- **Last active**: [date]
- **Contact**: [email]
## Secondary Contacts
| Name | Role | Why Secondary | Contact |
|------|------|---------------|---------|
| [Name] | [Title] | Moved to [team] but retains context | [email] |
## Historical Contributors
| Name | Contribution | Current Role | Last Active |
|------|--------------|--------------|-------------|
| [Name] | Original author | Now on [team] | [date] |
## Team Ownership
- **Team**: [team name]
- **Manager**: [name]
- **Slack channel**: [channel] (may be faster than individual outreach)
## Rejected Candidates
| Name | Reason |
|------|--------|
| [Name] | Single commit — typo fix only |
| [Name] | Left company |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 125 lines · 50 tokens per session scan A 51bd760ceb2f
code-owners is a skill published in the GitHub repository gleanwork/claude-plugins (25 stars, last pushed 12d ago), licensed MIT. It adds 50 tokens to every session and 894 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…