Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/inspecto-dev/inspecto/inspecto-onboarding-cursornpx skills add inspecto-dev/inspecto --skill inspecto-onboarding-cursorgit clone --depth 1 https://github.com/inspecto-dev/inspectoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/inspecto-dev/inspecto/inspecto-onboarding-cursor)<a href="https://agentmods.dev/skills/inspecto-dev/inspecto/inspecto-onboarding-cursor"><img src="https://agentmods.dev/badge/skills/inspecto-dev/inspecto/inspecto-onboarding-cursor.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00023 | $0.00572 |
| Opus 5 | $0.00012 | $0.00286 |
| Sonnet 5 | $0.00005 | $0.00114 |
| Haiku 4.5 | $0.00002 | $0.00057 |
Grade A, and why
inspecto-onboarding scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
89% identical to inspecto-onboarding — 6 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 35 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Inspecto Onboarding
When the user asks Cursor to set up Inspecto:
- Prefer the single-entry flow:
onboard --json. - If the result returns
status: "needs_target_selection", explain that this step chooses which local development build target should receive the Inspecto plugin and settings. Choose one returned target candidate and rerun with--target <candidateId>, preferring the explicitcandidateIdfield. The CLI also accepts a returnedconfigPathas a compatibility fallback. Do not collapse the selection back to a package path when multiple build configs exist in the same package. - If the result returns
status: "needs_confirmation", summarize the proposed changes and wait for approval before rerunning with--yes. - If the result returns
status: "partial_success"anddiagnostics.nextStepsincludes IDE extension installation, treat that as a blocking onboarding follow-up. Do not move on to dev-server validation until the extension is installed automatically or the user confirms they completed the manual install. - If the result includes
handoff.patches, treat them as the primary source of truth for the remaining work. Apply those patches directly before exploring framework docs or unrelated project files. - Only do broader documentation or repo exploration when a returned patch is clearly insufficient or conflicts with the local project structure.
- Use
node packages/cli/bin/inspecto.jswhen working inside the Inspecto repository. - Otherwise prefer an already available
inspectoexecutable before falling back tonpx @inspecto-dev/cli@latest. - Use
doctor --jsononly for explicit recovery diagnostics.
Rules:
- Treat IDE extension installation as required before runtime verification.
- Let the Inspecto CLI perform dependency installation and config generation.
- Use the CLI's
verificationfield as the source of truth for the dev-server step. - Default to
.inspecto/settings.local.jsonand.inspecto/prompts.local.json. - Do not rewrite Inspecto config files manually unless the user asks for a manual fallback.
- Prefer
handoff.patches,handoff.pendingSteps, andhandoff.assistantPromptover ad-hoc investigation. Do not start with Next.js or Nuxt documentation searches when the CLI already returned concrete patch targets.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 35 lines · 23 tokens per session scan A 6f8a98442ba9
inspecto-onboarding is a skill published in the GitHub repository inspecto-dev/inspecto (23 stars, last pushed 2d ago), licensed MIT. It adds 23 tokens to every session and 572 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 89% identical to inspecto-onboarding, differing in 6 lines, and is treated as a copy.
Other skills, from other repositories
sdd-apply
Skill "sdd-apply" from Gentleman-Programming/gentle-ai, covering execution role, language domain contract, purpose, what you receive and execution and persistence contract.
gentle-ai-collab-perfect
Trigger: contributing to Gentleman-Programming/gentle-ai as an external collaborator. Strict issue-first workflow, honest PR bodies, contributor-vs-maintainer scope, chained-PR strategy, verification protocol, docstring coverage. Load whenever the active repo is Gentleman-Programming/gentle-ai and any part of the…
issue-creation
Trigger: issue creation, bug reports, feature requests, or issue approval. Create and triage GitHub issues from repository evidence.
sdd-spec
Write SDD delta specs with requirements and scenarios. Trigger: orchestrator launches spec work for a change.
sdd-tasks
Break an SDD change into implementation tasks. Trigger: orchestrator launches task planning for a change.
sdd-verify
Skill "sdd-verify" from Gentleman-Programming/gentle-ai, covering execution role, language domain contract, activation contract, hard rules and decision gates.