Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/hazat/pi-config/workernpx skills add HazAT/pi-config --skill workergit clone --depth 1 https://github.com/HazAT/pi-configWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hazat/pi-config/worker)<a href="https://agentmods.dev/skills/hazat/pi-config/worker"><img src="https://agentmods.dev/badge/skills/hazat/pi-config/worker.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00056 | $0.00569 |
| Opus 5 | $0.00028 | $0.00284 |
| Sonnet 5 | $0.00011 | $0.00114 |
| Haiku 4.5 | $0.00006 | $0.00057 |
Grade A, and why
worker scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 58 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Worker
Implement exactly the assigned todo or review-fix task. Do not redesign the plan, expand scope, launch agents, push, or edit coordinator handover files.
Inputs
The launch prompt must provide:
- available absolute plan, todos, and review paths;
- one task ID and its exact scope;
- the checkout to use;
- any additional acceptance constraints.
Read the supplied handover files directly and treat them as read-only. Inspect repository instructions, git status --short, and every target file before editing. If context is missing or unrelated dirty changes make an isolated commit unsafe, stop and report a blocker rather than guessing.
Implement and Verify
Keep changes limited to the assigned task and preserve unrelated work. Run the smallest meaningful tests, typecheck, build, or smoke checks required by its acceptance criteria. Remove temporary/debugging artifacts.
Run every mutation-capable verification command before the commit. After the final verification, inspect git status --short: include legitimate generated source changes in scope, or restore disposable generated output before reporting. If a post-commit hook or required check changes tracked files, reconcile those files, rerun the affected verification, and amend or create the requested single focused commit. Never report completion with task-owned changes left dirty.
If verification fails, do not commit partial work. Report the command, failure, and blocker.
Commit
After verification passes:
- Read and follow
~/.pi/agent/skills/commit/SKILL.md. - Review the complete diff and stage only this task's files.
- Create exactly one focused commit; do not push.
- Verify it with
git show --stat --oneline HEADand capture the full SHA. - Confirm
git status --shortcontains no uncommitted changes owned by this task.
A no-op task may omit a commit only when the evidence proves no source change was needed.
Final Report
Return a concise final response for the coordinator to collect with sc agent read:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 58 lines · 56 tokens per session scan A f7488756331a
worker is a skill published in the GitHub repository HazAT/pi-config (443 stars, last pushed 9d ago), licensed MIT. It adds 56 tokens to every session and 569 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
contributing
How to contribute to evlog, covering commit and PR conventions, changesets, the Definition of Done, testing rules, and the authored skills that walk through building a new adapter, enricher, framework integration, or map rule. Load this for any question about contributing, opening a PR, or adding something to the…
commit
Git commit workflow with precommit hook handling, lint/type checking, README updates, and API reference updates. Use when the user wants to commit changes. Handles precommit hooks that modify files (formatting, linting) by re-staging and retrying. Runs ruff lint and pyright type checks on staged Python files, and…
git-commit
Creates git commits following Conventional Commits format with type/scope/subject and detailed markdown body. Use when user wants to commit changes, create commit, save work, or stage and commit. Enforces project-specific conventions from CLAUDE.md. Each change type gets its own markdown heading (# emoji + type), with…
commit
Create a signed git commit following Conventional Commits, after running /pre-commit and /changelog when appropriate.
et-git
ET git workflow for preparing commits and reviewing changes. Use when checking git status or diff, filtering unrelated files, staging task-scoped changes, writing Chinese commit messages, or synchronizing with remotes using rebase instead of merge.
commit
Smart commit: bump version, find related issues, commit with Co-authored-by, push. Use when the user says 'commit' or wants to finalize changes.