coding-agent-scaffold

A guide for designing the tools a coding agent uses to inspect and change code. It focuses on a small interface built around a shell command tool and a file-editing tool.

In plain words
What is it for?
Use it when building a coding agent scaffold, defining tool descriptions, or improving how an agent explores, edits, tests, and checks a codebase.
Why use it?
Poorly described tools cause agents to misuse them and make unreliable changes. Clear rules for paths and exact text replacement reduce common mistakes.

Skill for Claude CodeCodex

Part of the agent-stdlib plugin — 14 skills, 2 commands, 1 agent, 2 hooks, 2 MCP servers shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/hoja-solutions/agent-stdlib/coding-agent-scaffold
Any agent
npx skills add Hoja-Solutions/agent-stdlib --skill coding-agent-scaffold
Clone the repo
git clone --depth 1 https://github.com/Hoja-Solutions/agent-stdlib

Made for: Claude Code, Codex.

Or install agent-stdlib, the plugin that ships this one along with the rest of its 14 skills, 2 commands, 1 agent, 2 hooks, 2 MCP servers.

Per session 160 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 912 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00160 $0.00912
Opus 5 $0.00080 $0.00456
Sonnet 5 $0.00032 $0.00182
Haiku 4.5 $0.00016 $0.00091

Measured 2d ago against content hash cd783ceb1dbe, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

coding-agent-scaffold scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/coding-agent-scaffold/SKILL.md · 58 lines

How it starts

The opening of the file, as written. The whole thing — 58 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Coding agent scaffold

Source: Raising the bar on SWE-bench Verified with Claude 3.5 Sonnet. The procedure circulates as tutorials and reference codebases (Thorsten Ball's "How to build an agent" is the canonical one). None ship it as a skill focused on tool-interface design, which is the part that decides reliability.

A strong coding agent does not need elaborate scaffolding. It needs two tools designed with the care you would give a UI, and the freedom to decide its own order of operations. The scaffolding encodes your guesses about what the model cannot do, and those guesses age badly as models improve. Keep it thin.

Give the model control, suggest the order

Do not hard-code a rigid pipeline. In the prompt, suggest a shape and let the model deviate when the task calls for it: explore the code, reproduce the problem, make the fix, verify it, then check edge cases. A suggested sequence guides without boxing in a model that often knows a better route for the specific bug.

Let the agent keep sampling until it finishes or hits the context limit. Expect a high token and turn count on hard tasks; that is the cost of letting the model work the problem.

Tool 1: bash

One parameter, a single command string. No XML wrapping, no escaping scheme the model has to satisfy on top of normal shell quoting.

Write the description the way you would brief a careful new engineer on an unfamiliar machine. Cover the things the model cannot see and will otherwise assume wrong:

  • how shell quoting and escaping work in this environment
  • which packages and interpreters are available
  • whether state persists between calls (does cd or an exported variable survive to the next command)
  • how to run something in the background, and how to read its output later

Steer the model away from commands that dump huge output into the context. A find / or an unbounded log tail wastes the window it needs for the actual task.

Tool 2: file editor

Read the full file on GitHub · 58 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 58 lines · 160 tokens per session scan A cd783ceb1dbe

Subscribe to this mod's changes

coding-agent-scaffold is a skill published in the GitHub repository Hoja-Solutions/agent-stdlib (1 stars, last pushed 1mo ago), licensed MIT. It adds 160 tokens to every session and 912 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.