Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/gowtham012/claude-plugins/savenpx skills add gowtham012/Claude-plugins --skill savegit clone --depth 1 https://github.com/gowtham012/Claude-pluginsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00037 | $0.00973 |
| Opus 5 | $0.00018 | $0.00487 |
| Sonnet 5 | $0.00007 | $0.00195 |
| Haiku 4.5 | $0.00004 | $0.00097 |
Grade A, and why
save scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 120 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Live project snapshot (auto-injected before you start)
Current branch & recent commits:
!`git log --oneline -10 2>/dev/null || echo "(no git history)"`
Files changed since last 5 commits:
!`git diff --name-only HEAD~5 2>/dev/null || echo "(none)"`
Uncommitted changes:
!`git status --short 2>/dev/null || echo "(no git repo)"`
Focus area (if provided)
$ARGUMENTS
If $ARGUMENTS is non-empty, bias the summary toward that area. Still capture everything else, but lead with it.
Step 1 — Read existing context
Call mcp__carry-forward__read_context with cwd = current working directory.
Use it as a baseline — carry forward decisions and open questions that are still active. Update stale entries. Don't delete history, refine it.
Step 2 — Write the updated context
Use the git snapshot above plus the conversation history to fill in the template. The git diff is your ground truth for which files were actually touched — don't guess.
Quality rules (strictly enforced):
| Bad (vague, useless) | Good (specific, actionable) |
|---|---|
| "worked on auth" | "Built JWT login/logout in src/hooks/useAuth.ts; token is stored in httpOnly cookie" |
| "fixed a bug" | "Fixed exp field parsed as string not int in src/middleware/auth.py:L42" |
| "next: finish auth" | "Next: implement silent token refresh — undecided between axios interceptor vs. React context effect" |
| "blocked on design" | "Blocked: token refresh strategy (silent vs. re-login) — trade-offs not resolved" |
Template:
---
last_saved: (leave blank — server updates this)
project: <project directory name>
---
## Current Task
<1–3 sentences: what is actively being built, fixed, or investigated.
Be specific: name the feature, the bug, the refactor. Not "working on auth" — "implementing JWT refresh flow in useAuth.ts">
## Files Being Worked On
<Use the git diff above as ground truth. Add a note on WHY each file matters.>
- `path/to/file.ext` — what changed and why it matters
## Key Decisions
<Include the WHY and what was ruled out. Future Claude needs the reasoning, not just the choice.>
- Decision made — why this over the alternative
## Patterns & Conventions Discovered
<Codebase-specific things worth remembering: naming conventions, surprising behaviour, non-obvious architecture.>
- Pattern — where it applies
## Next Steps
<Most urgent first. Specific enough that step 1 can be acted on immediately without re-reading code.>
1. Concrete next action (e.g. "Add `refresh_token` field to auth state in `useAuth.ts`")
2. Follow-up
## Blockers
<What is genuinely blocking progress. If none, write "None".>
- Specific blocker, or "None"
## Open Questions
<Unresolved questions that need a decision before work can proceed.>
- Question / uncertainty
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 120 lines · 37 tokens per session scan A 2ca8675ea707
save is a skill published in the GitHub repository gowtham012/Claude-plugins (5 stars, last pushed 5mo ago), licensed MIT. It adds 37 tokens to every session and 973 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
review-pr
Review a Dograh pull request, branch diff, or pasted patch for repo-specific security and correctness risks that are not obvious from generic FastAPI, Next.js, or Python conventions. Use when the user asks to review a PR, audit a diff, check whether changes are safe to merge, review their own changes, or asks what to…
review-agents-md
Audit Dograh AGENTS.md files for drift against the live repo and for bad scope boundaries between parent and child docs. Use when the user asks to review existing AGENTS files, identify stale guidance, decide whether a subtree needs its own AGENTS.md, or update the AGENTS.md hierarchy under the repo root, api/, or ui/.
merge-pipecat-upstream
Merge the latest upstream pipecat-ai/pipecat tag into the pipecat submodule fork (dograh-hq/pipecat) and bump the dograh repo to it. Use whenever the user asks to bump, upgrade, sync, or merge pipecat, resolve pipecat merge conflicts, audit whether upstream changes break or supersede Dograh's in-fork patches, or…
cli-commands
MUST use when using the CLI, including debugging job failures and inspecting run history via wmill job.
write-script-bun
MUST use when writing TypeScript scripts. Bun is the default and preferred TypeScript runtime — pick it for TypeScript unless the script specifically needs Deno.
write-script-bunnative
MUST use when writing Bun Native scripts. The script must start with //native to run on the native worker.