Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/jamesdsizemore/headcleaner-cli/documentation-governancenpx skills add jamesdsizemore/headcleaner-cli --skill documentation-governancegit clone --depth 1 https://github.com/jamesdsizemore/headcleaner-cliWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jamesdsizemore/headcleaner-cli/documentation-governance)<a href="https://agentmods.dev/skills/jamesdsizemore/headcleaner-cli/documentation-governance"><img src="https://agentmods.dev/badge/skills/jamesdsizemore/headcleaner-cli/documentation-governance.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00026 | $0.00951 |
| Opus 5 | $0.00013 | $0.00476 |
| Sonnet 5 | $0.00005 | $0.00190 |
| Haiku 4.5 | $0.00003 | $0.00095 |
Grade A, and why
documentation-governance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Documentation governance
When to use
- A repository needs documentation to be a verifiable deliverable, not a promise.
- You are starting or closing an implementation phase, preparing a commit, or repairing documentation drift.
- You need the same policy to work for Hermes, Claude Code, Codex, and AGY.
Do not use this as permission to generate boilerplate edits. The audit records an evidence-backed decision for every active document: updated, reviewed, or not-applicable.
Delivery workflow
- Discover before edits. Identify the repository root, test/lint commands, docs roots, archive/research exclusions, existing agent instructions, and Git hooks. Create a local ignored plan first. Completion: scope and non-goals are recorded.
- Bootstrap safely. Run
python <kit>/assets/scripts/bootstrap.py <repo> --phase <phase>. If instructions already exist, inspect and merge deliberately or use--append-instructions; never overwrite repository guidance silently. Completion: root records, hook source, verifier, and anin_progressaudit exist. - Audit every active page. Run
python scripts/verify_docs.py --write-audit-template <phase>only if no audit exists. For everyREADME.md/docs/**/*.mdpage, record a concrete disposition and evidence. Treat archives separately; do not falsify history to make the audit green. Completion: each active page has exactly one supported decision. - Implement and document together. Update the pertinent product, user, developer, operational, API/configuration, safety, troubleshooting, test, and decision records. Maintain backlog/issues/memory/history/dependencies/pins as facts change. Completion: no pertinent family is omitted without evidence.
- Verify phase completion. Run
python scripts/verify_docs.py --phase <phase>plus the repository’s focused and full checks. Do not claim completion on a partial audit, a broken anchor, or unverified test output. Completion: all gates are real and retained. - Commit gate. Install
.githooks/pre-commitviash scripts/install-git-hooks.sh. Before every commit stage the active audit andDEVELOPMENT_HISTORY.md; the hook validates staged evidence. Do not bypass it. Completion:git config --get core.hooksPathreturns.githooksand the hook passes.
What ships with it
27 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- assets/formats/evidence-rubric.md 771 B
- assets/formats/phase-audit.schema.json 829 B
- assets/platforms/agy/INSTALL.md 719 B
- assets/platforms/agy/plugin/plugin.json 143 B
- assets/platforms/agy/plugin/skills/documentation-governance/SKILL.md 432 B
- assets/platforms/claude/INSTALL.md 719 B
- assets/platforms/claude/plugin/.claude-plugin/plugin.json 197 B
- assets/platforms/claude/plugin/skills/documentation-governance/SKILL.md 374 B
- assets/platforms/codex/INSTALL.md 636 B
- assets/platforms/hermes/INSTALL.md 601 B
- assets/README.md 1.3 KB
- assets/scripts/bootstrap.py 5.2 KB runs code
- assets/scripts/install-git-hooks.sh 191 B runs code
- assets/scripts/pre-commit 70 B
- assets/scripts/verify_docs.py 11 KB runs code
- assets/templates/development/DOCUMENTATION_GOVERNANCE.md 745 B
- assets/templates/development/README.md 351 B
- assets/templates/instructions/AGENTS.md.fragment 785 B
- assets/templates/instructions/CLAUDE.md.fragment 560 B
- assets/templates/records/BACKLOG.md 188 B
- assets/templates/records/DEPENDENCIES.md 189 B
- assets/templates/records/DEVELOPMENT_HISTORY.md 193 B
- assets/templates/records/ISSUES.md 183 B
- assets/templates/records/MEMORY.md 212 B
- assets/templates/records/PINS.md 170 B
- assets/tests/test_governance.py 6.4 KB runs code
- README.md 1.9 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 57 lines · 26 tokens per session scan A 5b3ee3a1b422
documentation-governance is a skill published in the GitHub repository jamesdsizemore/headcleaner-cli (0 stars, last pushed 5d ago), licensed Apache-2.0. It adds 26 tokens to every session and 951 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…