Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add iblai/government-agents --skill workday-governmentgit clone --depth 1 https://github.com/iblai/government-agentsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/iblai/government-agents/workday-government)<a href="https://agentmods.dev/skills/iblai/government-agents/workday-government"><img src="https://agentmods.dev/badge/skills/iblai/government-agents/workday-government/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/iblai/government-agents/workday-government"><img src="https://agentmods.dev/badge/skills/iblai/government-agents/workday-government.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00034 | $0.00721 |
| Opus 5 | $0.00017 | $0.00360 |
| Sonnet 5 | $0.00007 | $0.00144 |
| Haiku 4.5 | $0.00003 | $0.00072 |
Grade A, and why
workday-government scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 41 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Workday Government
What it is
Workday Government is a FedRAMP-authorized cloud Human Resource Information System (HRIS) used by federal agencies and large state/local governments for HR, payroll, and talent management. It consolidates personnel records, position management, leave tracking, payroll, and performance planning in a single system of record, replacing legacy systems like PeopleSoft and NFC for many agencies.
When to use this skill
- Retrieving an employee's position details (title, series, grade, duty station, appointment type)
- Checking leave balances (annual, sick, FMLA, LWOP, comp time) for a specific employee
- Reviewing the status of a personnel action request (PAR / SF-52) through the approval chain
- Looking up supervisor assignments, org hierarchy, or FTE counts for an organizational unit
- Accessing SF-50 history, performance ratings, and training completions for a personnel record
Credentials
This skill authenticates using variables from the OpenClaw daemon env file ~/.openclaw/.env (template: .env.example). Required variables:
WORKDAY_BASE_URL- agency Workday tenant URL (e.g.,https://wd2.myworkday.com/agency)WORKDAY_CLIENT_ID- OAuth 2.0 client ID for the registered API clientWORKDAY_CLIENT_SECRET- OAuth 2.0 client secretWORKDAY_REFRESH_TOKEN- long-lived refresh token for non-interactive API accessWORKDAY_RAAS_ENDPOINT- Report-as-a-Service (RaaS) URL for custom worker data reports
Key operations
POST /ccx/oauth2/{tenant}/token— exchange refresh token for a short-lived access tokenGET /api/v1/{tenant}/workers/{id}— retrieve worker profile including position and job detailsGET /api/v1/{tenant}/workers/{id}/timeOff/balances— query leave balances by leave typeGET /api/v1/{tenant}/businessProcesses?type=staffing— list open personnel action workflows and approval statusGET {RAAS_ENDPOINT}?format=json— run a pre-built Report-as-a-Service for bulk org or payroll dataGET /api/v1/{tenant}/organizations/{id}/workers— list workers in an organizational unit
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 41 lines · 34 tokens per session scan A 24805769b1d0
workday-government is a skill published in the GitHub repository iblai/government-agents (10 stars, last pushed 3mo ago), licensed MIT. It adds 34 tokens to every session and 721 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
nft-standards
Implement NFT standards (ERC-721, ERC-1155) with proper metadata handling, minting strategies, and marketplace integration. Use when creating NFT contracts, building NFT marketplaces, or implementing digital asset systems.
istio-traffic-management
Configure Istio traffic management including routing, load balancing, circuit breakers, and canary deployments. Use when implementing service mesh traffic policies, progressive delivery, or resilience patterns.
postgresql-table-design
Use this skill when designing or reviewing a PostgreSQL-specific schema. Covers best-practices, data types, indexing, constraints, performance patterns, and advanced features.
event-store-design
Design and implement event stores for event-sourced systems. Use when building event sourcing infrastructure, choosing event store technologies, or implementing event persistence patterns.
projection-patterns
Build read models and projections from event streams. Use when implementing CQRS read sides, building materialized views, or optimizing query performance in event-sourced systems.
workflow-orchestration-patterns
Design durable workflows with Temporal for distributed systems. Covers workflow vs activity separation, saga patterns, state management, and determinism constraints. Use when building long-running processes, distributed transactions, or microservice orchestration.