Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add iampawan/Manifest --skill contract-promotegit clone --depth 1 https://github.com/iampawan/ManifestWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/iampawan/manifest/contract-promote)<a href="https://agentmods.dev/skills/iampawan/manifest/contract-promote"><img src="https://agentmods.dev/badge/skills/iampawan/manifest/contract-promote/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/iampawan/manifest/contract-promote"><img src="https://agentmods.dev/badge/skills/iampawan/manifest/contract-promote.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00063 | $0.02062 |
| Opus 5 | $0.00032 | $0.01031 |
| Sonnet 5 | $0.00013 | $0.00412 |
| Haiku 4.5 | $0.00006 | $0.00206 |
Grade C, and why
contract-promote scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Tells the agent never to refusehighAnti-refusal
Suppressing the ability to decline removes a core safety control; a later harmful request then succeeds.
2. **If Large, route to decomposition — don't refuse.** A Large How it starts
The opening of the file, as written. The whole thing — 165 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Contract promoter
Promote freezes a verified contract into a revision and starts the
build phase. The hard gate is blockers, not warnings: promote any
contract that is promotable (zero open blockers). Warnings and info
are advisory — they don't block promotion, so a dev is never stuck
chasing run-to-run-variable warnings to zero. Surface the open warnings
so the human is choosing knowingly; they can fix or acknowledge them,
but they don't have to.
Precondition: verify required scopes BEFORE making changes
Before doing ANYTHING that writes, check the scopes this skill needs
(declared in frontmatter requiredScopes). If a required scope is
missing, STOP and tell the user exactly which scope is missing and
which step it would have broken — do NOT proceed and let a later step
fail silently.
Specifically:
github:issues:writeis REQUIRED — the tracking issue is core. If the GitHub token lacks it, refuse the whole promote with: "Cannot promote: GitHub token lacksissues:write, needed to open the tracking issue. Grant it (or re-auth) and retry."github:contents:writeis REQUIRED — to commit the revision file.atlassian:writeandslack:chat:writeare OPTIONAL — if missing, proceed but SKIP those steps and tell the user they were skipped (e.g., "Promoted; skipped JIRA epic — Atlassian not connected."). Never silently skip; always report what didn't happen and why.
Run /setup (setup-check skill) to introspect granted scopes. If
scope introspection isn't available in the runtime, attempt the
write and treat a permission error as a hard, reported failure — not
a silent pass.
Precondition: require a valid Ready Check (the PM gate)
"No code, no grooming." /contract pickup already verifies the PM's
Ready Check code automatically and records it as readyCheck: RC-… in
the frontmatter. Promote just confirms that stamp is present:
readyCheck: RC-…present → proceed.- Missing → refuse: "This contract hasn't cleared the PM Ready Check. Run
/ready-check <source>first — grooming shouldn't start on an unready PRD." (Seereference/READY-CHECK-RUBRIC.md.) - Only re-verify (
ready-check.mjs --verify) if the contract's own requirement text changed since pickup — aSTALEresult means re-run/ready-checkfor a fresh code. - Teams piloting Ready Check may set
conventions.requireReadyCheck: falseinrepos.ymlto warn instead of block during rollout. Default is to block once the team has adopted it.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 165 lines · 63 tokens per session scan C e803d2d7db1a
contract-promote is a skill published in the GitHub repository iampawan/Manifest (5 stars, last pushed 7d ago), licensed MIT. It adds 63 tokens to every session and 2,062 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it C with 1 finding (tells the agent never to refuse). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
release-announcement
Write a release announcement — changelog, blog post, in-app note, or social post — that leads with user impact, names the audience, and includes upgrade/migration steps without filler.
multi-agent-release-manager
Cleans up the workspace, formats code, runs presubmit checks, and uploads CLs to Gerrit.
release-notes
Generate user-facing release notes from tickets, PRDs, or changelogs. Creates clear, engaging summaries organized by category (new features, improvements, fixes). Use when writing release notes, creating changelogs, announcing product updates, or summarizing what shipped.
pack-submit
Package one of this agent's own skills as a standalone community pack and submit it to the aeon registry as a PR.
updater_guide
Guidance for checking for and installing Row-Bot updates.
nvca-chart-release
Release NVCA Operator chart changes from the native monorepo source to the vendored Helm chart. Use when updating the vendored NVCA Operator chart, changing NVCA image refs, publishing helm-nvca-operator, or validating the chart against a self-managed control plane.