Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/iamk77/skill/touchstonenpx skills add IamK77/Skill --skill touchstonegit clone --depth 1 https://github.com/IamK77/SkillWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00207 | $0.05522 |
| Opus 5 | $0.00103 | $0.02761 |
| Sonnet 5 | $0.00041 | $0.01104 |
| Haiku 4.5 | $0.00021 | $0.00552 |
Grade A, and why
touchstone scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 167 lines — stays where its author put it; the contents beside it link to each section on GitHub.
touchstone
!checklist init ${CLAUDE_SKILL_DIR} --force
A touchstone is the dark stone a jeweler rubs gold against to tell real metal from a convincing fake. touchstone is what you rub a repository against to tell genuine quality from the things that merely look like it — before you stake an afternoon, a dependency, or a production system on it. It is the second skill of the quarry suite: it owns evaluation — the fast, deliberate scan that turns a candidate into a verdict. It audits (and guides you to run) a gated pipeline, and it will not advance past a GATE until the checklist tool clears it. That gate enforces order — each glance before the next — not the substance of the judgment inside it; the tool structures the discipline, it does not supply it, so the calibration is yours.
The one mental shift everything hangs on — weight the signals that can't be faked, not the ones that can. The goal is not to read the project; it is to scan a handful of dashboards and form a fast "worth more of my time?" judgment. An agent is superb at this mechanically — it can pull the commit history, release cadence, issue timeline and contributor graph for fifty repos in seconds. But its instinct is to rank them by the star count and the README, and those are precisely the two signals that are cheapest to manufacture: stars can be farmed, and in 2026 a fluent, feature-rich README sitting on top of a thin or incoherent commit history is the signature of AI-generated slop. So touchstone inverts the convenience-ordering a tired human falls into: down-weight stars and README polish to suspect-until-corroborated, and up-weight the expensive-to-fake signals — whether the commits are real changes or padding, whether the maintainer actually responds in issues, the bus factor, the real downstream "Used by", and the presence of tests and CI. The verdict is built from what is hard to fake.
The agent is the means, not the oracle. Here it has two jobs: the dashboard reader (pull the real signals fast, from the actual repo) and the adversary (actively look for the tells that this is dead, abandoned, or slop). It is not the judge of whether the repo is right for you. Its gradient points at a confident, tidy verdict, and it will reach one by trusting the surface and filling gaps with plausible facts — asserting "actively maintained" from a high star count, or inventing a contributor statistic it never pulled. So one discipline is absolute: every claim traces to the actual repo. A number is read from the repo's data or it is not stated; "well-maintained" names the last-commit date and the issue-response pattern behind it, or it is not claimed; when a signal can't be determined, the verdict says unknown, never a guess dressed as a finding.
What you cannot delegate — the calibration. The agent can score the axes; only you can say what the score means for your situation, because the bar moves with the use. The same repo — a clever, fast, single-maintainer tool, last touched eight months ago — is a fine pick to try out for a weekend, a reasonable base to read and learn from, and a bad bet to make a load-bearing production dependency. Low activity is not automatically bad: a small, focused, Unix-style library can be "finished" and correctly sit untouched for years. The agent reports the signals; you decide whether they clear the bar your context sets. Hand it the calibration and you have automated a context-free verdict onto a context-dependent decision.
What "done" looks like — a calibrated verdict with its evidence, not a star-ranked list. The checkup is over when each target has a three-axis read (alive / healthy / well-built), each axis backed by the specific signals behind it, a slop-risk call, and a verdict calibrated to your use-context — deep-dive, try it, don't-bet-in-production, or skip — with every claim traceable to the repo. For a batch, that is a ranked, justified shortlist; for one repo, a go/no-go with reasons. The terminus is the judgment plus its evidence, not "the one with the most stars".
What ships with it
7 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 167 lines · 207 tokens per session scan A 917f3aa0a979
touchstone is a skill published in the GitHub repository IamK77/Skill (2 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 207 tokens to every session and 5,522 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
agent-platform-model-registry
Agent Platform Model Registry Management. Use when you need to upload, list, describe, update, or delete machine learning models (and their versions) in the Agent Platform Model Registry. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform models.
bigquery-ai-ml
Leverages BigQuery's built-in machine learning and GenAI capabilities for advanced data analytics. Use when you need to write SQL queries that perform time-series forecasting, predict values, detect outliers or anomalies, find key drivers, perform semantic search or vector search, classify text, calculate similarity…
edge-to-edge
Use this skill to migrate your Jetpack Compose app to add adaptive edge-to-edge support and troubleshoot common issues. Use this skill to fix UI components (like buttons or lists) that are obscured by or overlapping with the navigation bar or status bar, fix IME insets, and fix system bar legibility.
twitter-reader
Read Twitter/X for financial research using opencli (read-only). Use this skill whenever the user wants to read their Twitter feed, search for financial tweets, view bookmarks, look up user profiles, or gather market sentiment from Twitter/X. Triggers include: "check my feed", "search Twitter for", "show my…
referral-program
When the user wants to design, launch, or optimize an in-app referral / invite / share-to-earn program — including reward structure, mechanics, fraud prevention, deep link setup, and viral coefficient measurement. Use when the user mentions "referral program", "invite a friend", "refer and earn", "share to earn"…
apple-search-ads
When the user wants to set up, optimize, or scale Apple Search Ads (ASA) campaigns — including keyword bidding, match types, campaign structure, Creative Product Sets, CPP routing, and ROAS optimization. Use when the user mentions "Apple Search Ads", "ASA", "Search Ads", "Search tab ads", "Today tab ads", "CPT"…