Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add hujianbest/harness-flow --skill hf-grillinggit clone --depth 1 https://github.com/hujianbest/harness-flowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hujianbest/harness-flow/hf-grilling)<a href="https://agentmods.dev/skills/hujianbest/harness-flow/hf-grilling"><img src="https://agentmods.dev/badge/skills/hujianbest/harness-flow/hf-grilling/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hujianbest/harness-flow/hf-grilling"><img src="https://agentmods.dev/badge/skills/hujianbest/harness-flow/hf-grilling.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00043 | $0.00451 |
| Opus 5 | $0.00022 | $0.00226 |
| Sonnet 5 | $0.00009 | $0.00090 |
| Haiku 4.5 | $0.00004 | $0.00045 |
Grade A, and why
hf-grilling scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
持续访谈用户,直到达成共享理解。将其绘制为一棵设计树:每项决策都会分支出依赖于它的决策。
按轮次处理这棵树。前沿是所有前置条件已经确定的决策——也就是你现在无需猜测尚未听到的答案便可提出的问题。每轮询问整个前沿:为每个问题编号,并给出你的建议答案。然后等待用户回答,再进入下一轮。
每个问题都应采用以下格式:
❓ **Q1** - **<问题标题>**:<问题正文,可能包含多个段落和多个选项>
➡️ <你的建议答案>
用户每回答一轮,都会重塑这棵树——已经确定的决策会把前沿向外推进,并解除对依赖问题的阻塞。重新计算前沿并发起下一轮。如果某个问题的答案依赖于本轮中另一个仍未解决的问题,它应归入_后续_轮次,而不是本轮。
查明_事实_是你的工作,绝不是用户的工作。当前沿问题需要来自环境(文件系统、工具等)的事实时,派遣一个子 Agent 去查明——任何你能自行查到的信息都不要询问用户。不要因此阻塞:正在进行的探索是一个尚未确定的前置条件,因此只有它下游的问题需要等待子 Agent 汇报——立即询问前沿中的其余问题。_决策_属于用户——逐一交给他们决定并等待答复。
当前沿为空时,会话才算完成:设计树的每个分支都已遍历,不再有任何被默默假定的内容。在用户确认你们已经达成共享理解之前,不要据此采取行动。
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 23 lines · 43 tokens per session scan A 708a0f9ca8e6
hf-grilling is a skill published in the GitHub repository hujianbest/harness-flow (53 stars, last pushed 11d ago), licensed MIT. It adds 43 tokens to every session and 451 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…