Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/goldziher/poly/poly-orchestratornpx skills add Goldziher/poly --skill poly-orchestratorgit clone --depth 1 https://github.com/Goldziher/polyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/goldziher/poly/poly-orchestrator)<a href="https://agentmods.dev/skills/goldziher/poly/poly-orchestrator"><img src="https://agentmods.dev/badge/skills/goldziher/poly/poly-orchestrator.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00043 | $0.00768 |
| Opus 5 | $0.00022 | $0.00384 |
| Sonnet 5 | $0.00009 | $0.00154 |
| Haiku 4.5 | $0.00004 | $0.00077 |
Grade A, and why
poly-orchestrator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 52 lines — stays where its author put it; the contents beside it link to each section on GitHub.
poly as the Orchestrator
Treat poly as the single lint and format gate for the repository. Do not invoke ruff,
oxlint, taplo, rumdl, or the rest directly — poly compiles them in as backends, and covers
everything else via the tree-sitter generic tier, the quality metric tier, and its built-in
ast-grep rule pack, behind one binary, one config, and one report.
Adopt it
- One
poly.toml. Configure every language and rule in a single per-repo file (poly.local.tomlfor local overrides,extendsto share a base). Layering is tool default → poly's opinionated overrides → yourpoly.toml. In a monorepo a nestedpoly.tomldeep-merges on top of its ancestors for the files beneath it. poly migrate— absorb existing tool configs intopoly.tomlinstead of hand-writing it. It imports ruff, typos, taplo, and markdownlint configs; there is no eslint, prettier, or pre-commit importer. The default is a dry-run report — pass--writeto apply,--recursefor a monorepo,--verifyto re-run poly afterwards, and--strip-supersededto also removepyproject.tomlsections for tools ruff replaces.poly hooks install— wire the git-hook shims sopolyruns the configured stages on every commit, replacing a.pre-commit-config.yaml. It installs the hook types yourpoly.tomlconfigures;--hook-typepicks specific ones and--overwritediscards a preserved legacy hook.poly hooks uninstallrestores what was there before.poly config showprints the effective merged config;poly config updatepins a symbolic remoteextendsref intopoly-config.lock.poly doctorreports which poly is running, every poly on PATH, and the config in effect — the first thing to run when two machines disagree.
CI
Goldziher/poly@v0 is a setup action: it installs the poly binary (with optional
caching) and puts it on PATH. It does not run poly for you — invoke the commands yourself
in following steps.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 52 lines · 43 tokens per session scan A 2372831c4a6c
poly-orchestrator is a skill published in the GitHub repository Goldziher/poly (10 stars, last pushed 5d ago), licensed MIT. It adds 43 tokens to every session and 768 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
ESLint for Test Quality
Enforce test quality with ESLint - eslint-plugin-jest, eslint-plugin-playwright, and eslint-plugin-testing-library rules in flat config, blocking focused tests, missing assertions, and flaky waits via a CI lint gate.
Biome
Biome 2.x — fast all-in-one web toolchain in Rust. Formats, lints, assists. Replaces Prettier + ESLint.
prettier-docs
Prettier 3.9.5 — opinionated code formatter. CLI, API, config, plugins, editor integration, CI.
lint-and-fix
自动Lint修复技能 - 运行Linter、解析错误、AI自动修复循环.
ruff-docs
Ruff — fast Python linter and formatter in Rust. 900+ rules, Black-compatible formatter, LSP, CI/CD.
ci-formats-review
Review SARIF, CodeClimate, compact, markdown, badge, and other CI-facing output formats for correctness and integrator expectations. Use when changes affect machine-consumed report formats or CI presentation layers.