Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/griddynamics/rosetta/merge-mainnpx skills add griddynamics/rosetta --skill merge-maingit clone --depth 1 https://github.com/griddynamics/rosettaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/griddynamics/rosetta/merge-main)<a href="https://agentmods.dev/skills/griddynamics/rosetta/merge-main"><img src="https://agentmods.dev/badge/skills/griddynamics/rosetta/merge-main.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00012 | $0.02069 |
| Opus 5 | $0.00006 | $0.01035 |
| Sonnet 5 | $0.00002 | $0.00414 |
| Haiku 4.5 | $0.00001 | $0.00207 |
Grade A, and why
merge-main scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 42 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a thoughtful and meticulous senior software engineer.
Sync+merge remote origin main into this branch.
On conflicts: understand what both parts did. Use 3 way merge logic. Not just selecting A vs B. Not extremes. Not mechanical.
Automatically resolve if you are 100% sure, otherwise MUST USE HITL.
Workspace root:
pluginsare autogenerated => let user know to regenerate.docs/webis the web site content, which 99% follows original files.instructionsis the actual instructions, use by plugin generator, which are sent to AI coding agents working on separate their own repositories.srccontains MCPs, additional packages, and tools.
If you learned something new which is reusable, there are process efficiency improvements, you can prevent faiures in the future, update ## Lessons learned below for self-improvement.
Lessons learned (self-improvement, keep updating, first line is template, keep template, follow "", high confidence only):
- <key action item, less then 7 words> <concise/terse: what happened, why, root cause, reasoning, less then 25 words>.
- Regeneration is per-profile — the default pass leaves sibling profile trees stale. After resolving generated-file conflicts, running
rosettify-pluginsonce cleaned the 7 standard trees but left all 6core-*-lighttrees carrying pre-merge content, including frontmatter keys the merge had deleted. No conflict, no test failure —scripts/pre_commit.pyruns the generator twice (standard, then--profile lightweight) and only both passes together makeplugins/consistent. Verify withdiff -rq plugins/<t> plugins/<t>-light: anything differing beyond the profile-scoped files and the manifest name/description is stale. - Check whether a doc reference survives the plugin boundary. Plugin output is only
agents/ configure/ hooks/ rules/ skills/ workflows/— nothing underdocs/. A shippedinstructions/file that points atdocs/…dangles for consumer repos, so "concise pointer vs inline contract" is a real HITL decision, not a style preference. - Hunt semantic conflicts after the textual merge; git flags none of them. Three appeared here: main documented paths this branch had deleted, main asserted "no plugin directory yet" for a target this branch added, and main deleted
instructions/rule files whose generated copies survived in a branch-only plugin. Grep the merged tree for paths/claims each side touched, and always run bothsrc/rosettify-pluginsandsrc/hookssuites — a regression test caught the stale path a doc review missed. - When both sides fixed the same stale string, compose the line — don't pick a side. Main and the branch independently corrected
"Rosetta 2.0"in the Codex manifest; git conflicted only on that line while cleanly taking main'sversionbump and the branch's newdefaultPrompt. The resolution is per-field, and the one word neither side can decide (3vs3.0) is the HITL question — not the whole file. - A generated
plugins/**conflict is a shadow of its preserved source.plugins/<t>/…/plugin.jsonis byte-copied fromsrc/rosettify-plugins/plugins/<t>/…, so both conflict identically. Resolve them the same way, then tell the user to regenerate rather than hand-tuning the generated copy. - Version drift survives a clean merge silently. Main bumped every plugin manifest and marketplace to a new patch while the branch had bumped only
src/rosettify-plugins/package.jsonto a new minor. No conflict, no test failure — the two just disagree afterwards. Comparepackage.jsonagainst the manifests post-merge and surface it. - Re-verify main's new content against the branch's generation changes. Main added a workflow plus 8 phase files; this branch had changed how workflows become skills. Nothing conflicted and every test passed, because no fixture covers content that did not exist when the tests were written. Generate and inspect the new artifact.
- Diff each side against the merge-base before merging; the overlap set is tiny.
comm -12ongit diff --name-only <base> origin/mainvs… <base> HEADreduced 717+331 changed files to 15 real overlaps, which made the one genuine judgment call obvious immediately. - Verify any incoming "generated / auto-built" claim against the build config; never trust the doc. Main imported
docs/reviews/DOC-STRUCTURE-PLAN.mdassertingllms-full.txtis "generated by the build pipeline (no manual facts)". It is hand-maintained:.github/workflows/pages.ymlonlycps it todocs/web/, no generator references it, and its history is all feature commits. A false generated-claim is high-damage — it invites treating hand-written content as disposable and skipping updates. Grep*.ts/js/json/sh/ymlfor the filename and checkgit log -- <file>before believing it. - Zero textual overlap does not mean zero semantic conflict, and a dirty tree may be irrelevant. This merge had 0 overlapping files yet still imported a wrong maintenance claim about a file the branch edited. Separately, check
git diff --name-only <base> origin/main | grep ^plugins/first: if the incoming side touches no plugin files, locally modifiedplugins/neither blocks the merge nor needs discussion — the user regenerates it regardless. - Identical independent edits auto-resolve — don't assume a same-file overlap needs HITL. All 6 overlapping files here were plugin copies of one workflow, and both sides had made the byte-identical
check_state→check_moderename (each regenerating plugins to catch up with an instructions source that already hadcheck_modeat the merge-base).git merge --ortmerged them with zero conflict markers. Diff each overlapping file on both sides before assuming a HITL question exists — same-diff overlaps are free. - The repo has multiple independent version tracks — never compare raw numbers across them.
scripts/bump_versions.shis the ground truth: it bumpsplugin.json+marketplace.jsontogether as one group (kept equal to each other), and separately, opt-in, bumpssrc/rosettify/package.json,src/rosettify-plugins/package.json,src/rosettify-prompts/package.json,src/curiocity/package.json, and eachpyproject.toml— with no expectation any of those match each other or the plugin/marketplace group.rosettify-plugins/package.jsonat 3.2.0 next toplugin.jsonat 3.1.8 is not drift, it's two unrelated counters — a genuine "did the user mean to conflate these" moment, corrected after the user pushed back with "solution has individual components with individual versions, you must think." The real post-merge check is per-track: diff each file in the list above at base vs main vs branch vs merged — a track is a problem only if main and branch both bumped the same file to different values, or one side bumped a track's file and the merge silently reverted it. - A clean textual merge can disable a feature when one side adds a closed allow-list and the other adds a new member of the validated set. Main added throw-on-unknown-filename-directive; this branch added the
profile-<name>-onlytoken kind. The two hunks sit in different parts ofdirectives.ts, so git merged both with zero conflict markers — and the build would have hard-failed on all 11 profile-scoped source files. The suites that build from the real instruction tree are what expose this; a unit test on the parser alone would not. After any merge that touches validation, run the generator end-to-end against the real tree and check the exit code, not just the tests. - When both sides independently create the same canonical constant, keep the shape that can DERIVE the other. Main added
spec/target-names.ts(role-keyed object), this branch had put the same seven literals intypes.ts(array + type + guard).Object.valuesrecovers the list from the roles, but no expression recovers a role from a name string — so the role-keyed object is the literal home and the list/type/guard hang off it. Picking the other direction leaves the literals duplicated and free to drift. - "Did the incoming side specify its new behavior?" is a merge check. Main shipped a build-aborting validation while touching only
docs/hooks-verify.mdunderdocs/— no requirement unit at all, and the branch's shape-exemption was equally unspecified.git diff --name-only <base> origin/main | grep ^docs/requirements/in one line tells you whether incoming behavior arrived with its spec. - Reword a corrected claim across every doc surface, and watch the letter case. "the closing fence yields an empty, inert token" lived in 8 places: two FR-ARCH statements AND their two criteria, FR-PROF notes AND an AC, GLOSSARY, and ASSUMPTIONS twice. A criterion can be half-right — these already said the token set is
{overwrite}yet still appended the inert clause — so grep the claim, don't reason about where it "should" be. One instance began "The" rather than "the" and silently survived a case-sensitive replace.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 42 lines · 12 tokens per session scan A 8a4411aa25c0
merge-main is a skill published in the GitHub repository griddynamics/rosetta (342 stars, last pushed today), licensed Apache-2.0. It adds 12 tokens to every session and 2,069 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
azure-devops-rest-api
Guide for working with Azure DevOps REST APIs and OpenAPI specifications. Use this skill when implementing new Azure DevOps API integrations, exploring API capabilities, understanding request/response formats, or referencing the official OpenAPI specifications from the vsts-rest-api-specs repository.
decision-mapping
Turn a loose idea into a sequenced map of investigation tickets, then drive them to resolution one at a time.
memorix-memory
Use when prior workspace context, past decisions, solved bugs, handoff state, or durable project knowledge would help a coding task.
memorix
Use when Claude Code needs Memorix shared memory, reasoning, Git Memory, mini-skills, session handoff, orchestration coordination, or integration troubleshooting.
memorix-mini-skills
Use when durable project knowledge, gotchas, workflows, or repeated fixes should become reusable agent guidance instead of ordinary memory.
memorix-orchestrate
Use when a main agent needs Memorix to coordinate explicit subagent work through tasks, handoffs, messages, file locks, or the orchestrate CLI.