Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/hecer/yoke/codebase-designnpx skills add HECer/yoke --skill codebase-designgit clone --depth 1 https://github.com/HECer/yokeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00054 | $0.00458 |
| Opus 5 | $0.00027 | $0.00229 |
| Sonnet 5 | $0.00011 | $0.00092 |
| Haiku 4.5 | $0.00005 | $0.00046 |
Grade A, and why
codebase-design scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Codebase design
Design deep modules: substantial behavior behind a small interface, placed at a real seam and tested through that interface. Optimize for caller leverage and maintainer locality.
Vocabulary
- Module: anything with one interface and an implementation, from a function to a package.
- Interface: everything a caller must know: types, invariants, ordering, errors, configuration, and relevant performance behavior.
- Implementation: the behavior hidden inside a module.
- Depth: useful behavior per unit of interface a caller must learn.
- Seam: a place where behavior can change without editing the caller at that place.
- Adapter: a concrete implementation that satisfies an interface at a seam.
- Leverage: capability callers gain from a small interface.
- Locality: change, knowledge, bugs, and verification concentrated in one place.
Use these terms consistently. Prefer seam over the overloaded word boundary when discussing replaceable behavior.
Design checks
- Reduce methods and parameters when callers do not need the exposed choice.
- Hide repeated orchestration, invariants, and error handling inside the module.
- Apply the deletion test: deleting a useful module should make its complexity reappear across its callers. A layer whose complexity simply vanishes was probably a pass-through.
- Treat the interface as the test surface. Tests should survive internal refactors.
- Accept dependencies at real seams instead of constructing hard-to-replace externals internally.
- Introduce a seam for demonstrated variation. Production plus a meaningful test adapter can make two real adapters; a single speculative adapter does not.
- Return observable results where practical instead of requiring tests to inspect internal state.
For dependency-specific deepening, read DEEPENING.md. For a consequential interface with several plausible shapes, read DESIGN-IT-TWICE.md.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 40 lines · 54 tokens per session scan A 552dfb87e896
codebase-design is a skill published in the GitHub repository HECer/yoke (2 stars, last pushed 11d ago), licensed MIT. It adds 54 tokens to every session and 458 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
add-new-agent-support
Add a new agent (tool) support to agent-command-sync following the registry pattern.
with-config
A Codex skill with openai.yaml configuration.
standard-skill
A standard test skill for Gemini.
test-skill
A test skill for chimera.
basic-skill
A basic test skill for Claude.
qmd
Search the vault using QMD semantic search. Use PROACTIVELY before reading files. Preference order: (1) MCP tools — mcpqmdquery, mcpqmdget, mcpqmdmultiget, mcpqmdstatus — if they appear in your tool menu, use them first; (2) CLI qmd --index ... as fallback; (3) Grep/Glob only when QMD is not installed. Trigger…