Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/hecer/yoke/workflownpx skills add HECer/yoke --skill workflowgit clone --depth 1 https://github.com/HECer/yokeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00028 | $0.00323 |
| Opus 5 | $0.00014 | $0.00161 |
| Sonnet 5 | $0.00006 | $0.00065 |
| Haiku 4.5 | $0.00003 | $0.00032 |
Grade A, and why
workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Workflow — the default order of operations
For any non-trivial change, move through these phases in order (skip only what genuinely does not apply):
When .yoke/config.yaml exists and the user wants Yoke to own planning plus autonomous
execution, use yoke-workflow as the entrypoint. It adds the approved-plan → PRD → loop
handoff and the configured critical-decision behavior to the phases below.
- Brainstorm the idea into a clear design — see
brainstorming. - Plan a concrete, testable implementation — see
writing-plans. - Understand the code — map the blast radius with the code-graph before changing anything.
- Implement test-first — RED → GREEN → REFACTOR, smallest steps — see
tddandminimal-code. - Verify — run the real tests and exercise the change; never trust "it should work" — see
verification-before-completion. - Review — get an independent review of the diff before landing — see
review/requesting-code-review. - Ship — bump version, update changelog and docs, open the PR — see
ship/document-release.
Stop-the-Line applies throughout: no implementation before acceptance criteria exist. Always prefer the least code that solves the task (minimal-code).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 23 lines · 28 tokens per session scan A 3fbddb012ab1
workflow is a skill published in the GitHub repository HECer/yoke (2 stars, last pushed 11d ago), licensed MIT. It adds 28 tokens to every session and 323 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
add-new-agent-support
Add a new agent (tool) support to agent-command-sync following the registry pattern.
with-config
A Codex skill with openai.yaml configuration.
standard-skill
A standard test skill for Gemini.
test-skill
A test skill for chimera.
basic-skill
A basic test skill for Claude.
qmd
Search the vault using QMD semantic search. Use PROACTIVELY before reading files. Preference order: (1) MCP tools — mcpqmdquery, mcpqmdget, mcpqmdmultiget, mcpqmdstatus — if they appear in your tool menu, use them first; (2) CLI qmd --index ... as fallback; (3) Grep/Glob only when QMD is not installed. Trigger…