Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/goldziher/poly/poly-mcpnpx skills add Goldziher/poly --skill poly-mcpgit clone --depth 1 https://github.com/Goldziher/polyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/goldziher/poly/poly-mcp)<a href="https://agentmods.dev/skills/goldziher/poly/poly-mcp"><img src="https://agentmods.dev/badge/skills/goldziher/poly/poly-mcp.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00039 | $0.01437 |
| Opus 5 | $0.00019 | $0.00718 |
| Sonnet 5 | $0.00008 | $0.00287 |
| Haiku 4.5 | $0.00004 | $0.00144 |
Grade A, and why
poly-mcp scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 107 lines — stays where its author put it; the contents beside it link to each section on GitHub.
poly MCP
poly mcp is a stdio MCP server exposing poly's lint/format/cache/rules/config surface as
tools. Prefer it over shelling out to the CLI when working through MCP — every tool returns
typed structured_content (with a declared output schema) plus one text block that mirrors
the CLI's --format json, or the compact TOON encoding when asked.
poly mcp --config <PATH> pins a fallback config file for requests that do not name one.
Tool surface
Eleven tools, no more. Read-only (never touch the tree):
lint— run the linters and return diagnostics. Mirrorspoly lint.format_check— report formatting drift without writing. Mirrorspoly fmt --check.cache_stats— result-cache footprint (entries, bytes, format version) per namespace.rules— list every ast-grep rule a run would apply — poly's built-in pack plus the user rules from[rules] dirs— and optionally run their*-test.ymlsnippets. Mirrorspoly rules list/poly rules test. Each rule carries its language,source(builtin/user),default_severity, theseverityit reports at under the resolved config, andenabled.config_show— the merged effective configuration. Mirrorspoly config show, and is network-free: remoteextendsbases are not fetched.version— which poly binary is serving this session (version, build id, channel, executable, pid, uptime) and whether that executable is still the file on disk. It answers even when the binary has moved, which is what makes it the tool that explains why the others stopped.
Mutating (write to the tree):
lint_fix— apply lint autofixes. Mirrorspoly lint --fix.format_write— format files in place. Mirrorspoly fmt --fix.cache_clean— clear the result cache and report freed bytes.
Whole-project (long-running):
workspace_lint— the whole-project phase in check mode:cargo clippy/cargo-sort/cargo-machete/cargo-denyand configured inline whole-project jobs, over the whole repository (it takes nopaths).workspace_lint_fix— the same phase in fix mode; writes files.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 107 lines · 39 tokens per session scan A eabea30fa00f
poly-mcp is a skill published in the GitHub repository Goldziher/poly (10 stars, last pushed 5d ago), licensed MIT. It adds 39 tokens to every session and 1,437 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
ESLint for Test Quality
Enforce test quality with ESLint - eslint-plugin-jest, eslint-plugin-playwright, and eslint-plugin-testing-library rules in flat config, blocking focused tests, missing assertions, and flaky waits via a CI lint gate.
Biome
Biome 2.x — fast all-in-one web toolchain in Rust. Formats, lints, assists. Replaces Prettier + ESLint.
prettier-docs
Prettier 3.9.5 — opinionated code formatter. CLI, API, config, plugins, editor integration, CI.
lint-and-fix
自动Lint修复技能 - 运行Linter、解析错误、AI自动修复循环.
ruff-docs
Ruff — fast Python linter and formatter in Rust. 900+ rules, Black-compatible formatter, LSP, CI/CD.
ci-formats-review
Review SARIF, CodeClimate, compact, markdown, badge, and other CI-facing output formats for correctness and integrator expectations. Use when changes affect machine-consumed report formats or CI presentation layers.