Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/hoavdc/codexkit/codexkit-status-update-packagernpx skills add hoavdc/CodexKit --skill codexkit-status-update-packagergit clone --depth 1 https://github.com/hoavdc/CodexKitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hoavdc/codexkit/codexkit-status-update-packager)<a href="https://agentmods.dev/skills/hoavdc/codexkit/codexkit-status-update-packager"><img src="https://agentmods.dev/badge/skills/hoavdc/codexkit/codexkit-status-update-packager.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00059 | $0.00582 |
| Opus 5 | $0.00030 | $0.00291 |
| Sonnet 5 | $0.00012 | $0.00116 |
| Haiku 4.5 | $0.00006 | $0.00058 |
Grade A, and why
codexkit-status-update-packager scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 83 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Status Update Packager
Purpose
Produce a readable status update from fragmented project information.
When to use
- many contributors send updates in different formats
- a steering or management status pack must be prepared quickly
- the team repeats the same manual status rewrite every week
When not to use
- the project still lacks basic governance or ownership
- the user needs a new project plan, not a status package
Inputs
- source updates, notes, or issue list
- milestones or commitments
- current risks, blockers, and asks
- desired format if it exists
Procedure
- Separate progress from narrative filler.
- Pull out changed milestones, RAID items, and decisions needed.
- Convert raw notes into concise status language.
- Highlight only the material movement since the last check-in.
- End with next steps and executive attention items.
Output
- status summary
- changed risks or blockers
- decisions or support needed
- next-step commitments
Definition of done
- a sponsor can read it quickly
- the update emphasizes movement and risk, not activity volume
- every escalation or ask is explicit
Examples
- "Turn these team updates into a one-page weekly status report."
- "Package this RAID list and milestone movement for steering review."
Quality Criteria
- Trigger conditions and input requirements are unambiguous
- Each automated step produces a verifiable output
- Error handling and fallback paths are defined
- Manual override points are documented
Verification (4C)
| Check | Question |
|---|---|
| Correctness | Does the workflow produce the expected output for the defined inputs? |
| Completeness | Are all trigger conditions, edge cases, and error paths handled? |
| Context-fit | Is the automation appropriate for the frequency and criticality of this task? |
| Consequence | If this ran unattended and failed silently, what would the downstream impact be? |
Edge Cases
- Input format varies unexpectedly — Add a normalization step at entry. Alert the operator on format mismatches.
- Downstream system is unavailable — Queue the output and retry with exponential backoff. Alert after N failures.
- Partial execution completes — Ensure idempotency — re-running from the start produces the same result without duplication.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 83 lines · 59 tokens per session scan A bdbf4cab092c
codexkit-status-update-packager is a skill published in the GitHub repository hoavdc/CodexKit (21 stars, last pushed 3mo ago), licensed MIT. It adds 59 tokens to every session and 582 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
add-github
Add GitHub channel integration via Chat SDK. PR and issue comment threads as conversations.
add-linear
Add Linear channel integration via Chat SDK. Issue comment threads as conversations.
product-reviews
Help users design and facilitate product reviews that shift from status updates to strategic deep-dives, ensuring high-quality craftsmanship and organizational alignment.
delivering-delegated-linear-issues
当用户明确要求领取、处理、批量清空或定时扫描 Linear 的 Delegated to Agent issue 时使用;按队列状态、领取竞争、交付路径和收尾四个阶段渐进读取。.
github-issues
Create, manage, triage, and close GitHub issues. Search existing issues, add labels, assign people, and link to PRs. Works with gh CLI or falls back to git + GitHub REST API via curl.
analyzing-security
Scans code for security vulnerabilities, detects dangerous patterns, and ensures security decisions are documented. Use when running security scans, auditing code, or checking for OWASP issues, injection risks, or sensitive data leaks. Automatically triggered on new modules, security-related changes, or post-refactor.