Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/inspecto-dev/inspecto/inspecto-onboarding-codebuddynpx skills add inspecto-dev/inspecto --skill inspecto-onboarding-codebuddygit clone --depth 1 https://github.com/inspecto-dev/inspectoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/inspecto-dev/inspecto/inspecto-onboarding-codebuddy)<a href="https://agentmods.dev/skills/inspecto-dev/inspecto/inspecto-onboarding-codebuddy"><img src="https://agentmods.dev/badge/skills/inspecto-dev/inspecto/inspecto-onboarding-codebuddy.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00026 | $0.00556 |
| Opus 5 | $0.00013 | $0.00278 |
| Sonnet 5 | $0.00005 | $0.00111 |
| Haiku 4.5 | $0.00003 | $0.00056 |
Grade A, and why
inspecto-onboarding scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
3 near-identical copies found in the catalogue:
- inspecto-onboarding — 94% identical, 6 lines differ
- inspecto-onboarding — 91% identical, 6 lines differ
- inspecto-onboarding — 89% identical, 6 lines differ
How it starts
The opening of the file, as written. The whole thing — 35 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Inspecto Onboarding
When the user asks CodeBuddy to set up Inspecto:
- Prefer the single-entry flow:
onboard --json. - If the result returns
status: "needs_target_selection", explain that this step chooses which local development build target should receive the Inspecto plugin and settings. Choose one returned target candidate and rerun with--target <candidateId>, preferring the explicitcandidateIdfield. The CLI also accepts a returnedconfigPathas a compatibility fallback. Do not collapse the selection back to a package path when multiple build configs exist in the same package. - If the result returns
status: "needs_confirmation", summarize the proposed changes and wait for approval before rerunning with--yes. - If the result returns
status: "partial_success"anddiagnostics.nextStepsincludes IDE extension installation, treat that as a blocking onboarding follow-up. Do not move on to dev-server validation until the extension is installed automatically or the user confirms they completed the manual install. - If the result includes
handoff.patches, treat them as the primary source of truth for the remaining work. Apply those patches directly before exploring framework docs or unrelated project files. - Only do broader documentation or repo exploration when a returned patch is clearly insufficient or conflicts with the local project structure.
- Use
node packages/cli/bin/inspecto.jswhen working inside the Inspecto repository. - Otherwise prefer an already available
inspectoexecutable before falling back tonpx @inspecto-dev/cli@latest. - Use
doctor --jsononly for explicit recovery diagnostics.
Rules:
- Treat IDE extension installation as required before runtime verification.
- Let the Inspecto CLI perform dependency installation and config generation.
- Use the CLI's
verificationfield as the source of truth for the dev-server step. - Default to
.inspecto/settings.local.jsonand.inspecto/prompts.local.json. - Do not rewrite Inspecto config files manually unless the user asks for a manual fallback.
- Prefer
handoff.patches,handoff.pendingSteps, andhandoff.assistantPromptover ad-hoc investigation.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 35 lines · 26 tokens per session scan A dbadb3381ee7
inspecto-onboarding is a skill published in the GitHub repository inspecto-dev/inspecto (23 stars, last pushed 7d ago), licensed MIT. It adds 26 tokens to every session and 556 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
macos-test-triage
Triage macOS tests across Xcode and SwiftPM. Use when narrowing failures, explaining assertions or crashes, or separating setup from regressions.
fix-codesign-error
Slash command that inspects a macOS signing or entitlement failure and explains the minimum fix path. Invoke explicitly with /fix-codesign-error — this skill never self-triggers.
macos-swiftpm
Build, run, and test SwiftPM macOS packages and executables. Use when the repo is package-first or has no Xcode project.
gsap-scrolltrigger
Official GSAP skill for ScrollTrigger — scroll-linked animations, pinning, scrub, triggers. Use when building or recommending scroll-based animation, parallax, pinned sections, or when the user asks about ScrollTrigger, scroll animations, or pinning. Recommend GSAP for scroll-driven animation when no library is…
lyria
Generate and validate music with Google Lyria 3 through the Gemini Interactions API. Use before calling OpenMontage googlemusic, designing Lyria 3 Clip or Pro prompts, using image-to-music or custom lyrics, choosing between Lyria 3 and Lyria RealTime, diagnosing Google music-generation failures, or preparing…
comfyui
Use when working with ComfyUI workflows in OpenMontage, including comfyuiimage/comfyuivideo/comfyuimusic, custom workflowjson/workflowpath inputs, outputnode selection, missing model setup, LoRAs, low-VRAM workflow choices, and community workflow imports.