Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add jackfranklin/dotfiles --skill verify-mechanical-changegit clone --depth 1 https://github.com/jackfranklin/dotfilesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jackfranklin/dotfiles/verify-mechanical-change)<a href="https://agentmods.dev/skills/jackfranklin/dotfiles/verify-mechanical-change"><img src="https://agentmods.dev/badge/skills/jackfranklin/dotfiles/verify-mechanical-change.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00040 | $0.00980 |
| Opus 5 | $0.00020 | $0.00490 |
| Sonnet 5 | $0.00008 | $0.00196 |
| Haiku 4.5 | $0.00004 | $0.00098 |
Grade A, and why
verify-mechanical-change scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 80 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Verify Mechanical Change Skill
Use this skill when the user wants to confirm that a change is purely mechanical and contains no changes to behavior, UI, or application logic.
Workflow
-
Retrieve the Git Diff: Identify the diff to analyze. If the user specifies a commit, branch, or PR/CL, use git commands to get that diff. Otherwise, get the unstaged and staged changes in the workspace:
- Get staged changes:
git diff --cached - Get unstaged changes:
git diff - Combine them or ask the user if they want to analyze staged, unstaged, or both.
Save this diff as
DIFF_CONTENT.
If
DIFF_CONTENTis empty, stop and ask the user to provide a diff or commit, or verify if there are any changes to check. - Get staged changes:
-
Invoke Two Parallel Subagents: Invoke two parallel subagents using the
invoke_subagenttool withTypeName: research(to ensure they have read-only tools to explore the codebase for tracing symbol usage/definitions).Pass the identical prompt and
DIFF_CONTENTto both.- Subagent 1 (
MechanicalChangeReviewer1):- Role: Mechanical Change Reviewer A
- Prompt:
You are an expert code reviewer. Your task is to analyze the git diff provided below and determine if it is purely mechanical. A change is "purely mechanical" if and only if it consists entirely of: - Code style formatting (whitespace, indentation, line endings) - Renaming symbols (variables, functions, classes, properties) consistently across files - Modifying imports, exports, or namespace declarations (e.g. moving a file/module) - Adding, updating, or removing comments/documentation (e.g. JSDoc) without modifying implementation - Upgrading/downgrading dependencies/configurations that do not change application logic or UI - Adding or modifying unit/integration/end-to-end tests A change is NOT purely mechanical if it contains: - Logic changes (conditionals, loops, calculations, algorithm modifications) - UI/UX layout or styling changes (HTML, CSS, Component layout/attributes, localization strings) - Data model changes (DB schema, API payloads, config parameters affecting behavior) - Side-effects (network requests, console logs added/removed, state changes) - Any potential change in runtime behavior, error handling, performance characteristics, or user interface. Use any available tools to read files and explore the codebase to trace the definition and usage of renamed symbols or modified functions to confirm that no functional change was introduced. CRITICAL GUIDELINES: - Do NOT run any tests. Assume that all existing tests pass. - If the change is purely mechanical: - State "CONFIRMED: The change is purely mechanical." and explain why. - Look for and recommend opportunities where related or untouched behaviors affected by this change could be tested to increase coverage/confidence. - If the change is NOT purely mechanical: - State "REJECTED: The change contains behavioral or UI modifications." - List all the specific lines/files and logical details that violate the mechanical-only criteria. - Provide recommendations on how these behavioral changes could/should be covered by tests. Diff: <DIFF_CONTENT>
- Subagent 1 (
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 80 lines · 40 tokens per session scan A 59897dd2f0c2
verify-mechanical-change is a skill published in the GitHub repository jackfranklin/dotfiles (254 stars, last pushed 5d ago), licensed MIT. It adds 40 tokens to every session and 980 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
review-implement-phase
Implements triaged review actions, commits focused fixes, and posts Done plus resolves threads. Use when the user wants only the implementation phase of the review-framework workflow.
engram-branch-pr
PR creation workflow for Engram following the issue-first enforcement system. Trigger: When creating a pull request, opening a PR, or preparing changes for review.
verify-behavior
Verify or reproduce visible product behavior by driving the real UI with pi-computer-use's checked tools, requiring verified expect postconditions and durable state evidence for meaningful UI flows. Use when triage needs visual reproduction, implementation needs behavioral proof, review needs interactive confirmation…
github-contributor
End-to-end playbook for shipping high-quality pull requests to open-source projects you don't maintain — discovery, CONTRIBUTING compliance, PR-size check, minimal-diff implementation, PR description with AI-assisted disclosure, conflict resolution, and post-submission maintainer interaction. Use whenever creating…
revdiff
Review diffs, files, and documents with inline annotations in a TUI overlay, or answer questions about revdiff usage, configuration, themes, and keybindings. Opens revdiff in agterm/tmux/zellij/herdr/kitty/wezterm/cmux/ghostty/iterm2/emacs-vterm, captures annotations, and addresses them. Works in git, hg, and jj repos…
write-pr
Reference standards for writing pull request titles and descriptions in the tldraw repository, plus the pre-flight comment sweep over the diff. Use as supporting guidance when another skill or workflow needs PR content standards, not as the user-facing create/update PR workflow.