Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/jarroslav/agentic-os/gate-runnernpx skills add Jarroslav/agentic-os --skill gate-runnergit clone --depth 1 https://github.com/Jarroslav/agentic-osWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jarroslav/agentic-os/gate-runner)<a href="https://agentmods.dev/skills/jarroslav/agentic-os/gate-runner"><img src="https://agentmods.dev/badge/skills/jarroslav/agentic-os/gate-runner.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00187 | $0.02595 |
| Opus 5 | $0.00093 | $0.01298 |
| Sonnet 5 | $0.00037 | $0.00519 |
| Haiku 4.5 | $0.00019 | $0.00260 |
Grade A, and why
gate-runner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 254 lines — stays where its author put it; the contents beside it link to each section on GitHub.
gate-runner
Execute the host project's quality gates in a fixed sequence and emit a
structured report the caller uses to decide merge readiness. You detect the
project's runner, resolve a gate plan, run the gates, and return a verdict.
You never create a merge request or pull request, and you never supply
functional browser evidence — that belongs to acceptance-check.
Blast radius: R0 (read-only detection, diff, manifest inspection) plus
R1 (writes only under <run_dir> and standard test output paths). Never
write repo files outside those locations. Run user-provided plan commands
exactly — no rewriting.
Inputs
| Input | Meaning | Default |
|---|---|---|
branch |
branch under test | required |
merge_base |
base ref for the diff | origin/main |
repo_path |
repository root | required |
run_dir |
directory for cache + report writes | required |
Compute the change set once with:
git diff --name-only <merge_base>...HEAD
Gate order (fixed)
lintbuildunitaffected(changed-file-aware tests)ui(conditional — only when the diff touches a UI surface)
Step 1 — Resolve the gate plan
Two resolution modes. Prefer the guide.
Guide-first. If a rendered gate registry file exists, read it and run exactly the gates it lists, in the order it lists them. Guide file paths, top-level preferred over the standards subpath:
.agentic/guides/quality-gates.md.agentic/guides/standards/quality-gates.md
When both exist, the top-level path wins. Do not invent, swap in, or auto-detect any gate ahead of what this file specifies.
Fallback auto-detection. Fall back to runner auto-detection only when the guide file does not exist and the caller is not inside a foundation-required full run. A foundation-required run expects the guide to be present.
Runner detection (first match wins; npm is never assumed by default)
| Manifest | Runner | lint / build / test / ui |
|---|---|---|
package.json + pnpm-lock.yaml |
pnpm | pnpm lint / pnpm build / pnpm test / pnpm test:ui |
package.json + yarn.lock |
yarn | yarn lint / yarn build / yarn test / yarn test:ui |
package.json (other/no lock) |
npm | npm run lint / npm run build / npm test / npm run test:ui |
Cargo.toml |
cargo | cargo clippy -- -D warnings / cargo build / cargo test / (no UI) |
pyproject.toml [tool.poetry] |
poetry | poetry run ruff check / poetry run python -m compileall . / poetry run pytest |
pyproject.toml [tool.uv] or uv.lock |
uv | uv run ruff check / uv run python -m compileall . / uv run pytest |
pyproject.toml (other) |
python | ruff check / python -m compileall . / pytest |
go.mod |
go | go vet ./... / go build ./... / go test ./... / (no UI) |
| none | unknown | ask user once |
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 254 lines · 187 tokens per session scan A 5338041b12d5
gate-runner is a skill published in the GitHub repository Jarroslav/agentic-os (0 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 187 tokens to every session and 2,595 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
designing-tests
Designs and implements testing strategies for any codebase. Use when adding tests, improving coverage, setting up testing infrastructure, debugging test failures, or when asked about unit tests, integration tests, or E2E testing.
prd-auto-test-loop
PRD 驱动的自动化测试编排技能。用于把每版 PRD 的测试计划、AI 自测与自修复、测试报告标准化落地;适用于按验收标准拆分 Unit/Integration/E2E、划分自动化与人工边界、生成版本化 TESTPLAN/TESTREPORT 的场景。.
pact-testing-strategies
Testing strategies, test pyramid guidance, and quality assurance patterns for PACT Test phase. Use when: designing test suites, implementing unit tests, integration tests, E2E tests, performance testing, security testing, or determining test coverage priorities. Triggers on: test design, unit testing, integration…
test-writer
Skill "test-writer" from miniidealab/openlogos, covering skill: test writer, 触发条件, 前置依赖, 核心能力 and 执行步骤.
test-automator
Test automation framework expert for creating and maintaining automated tests. Use when user asks to write tests, automate testing, or improve test coverage.
nest-test
Creates NestJS backend tests with Vitest — unit specs with stubbed repositories, and Supertest end-to-end specs that boot the application against a real PostgreSQL database in Testcontainers. Use when the user asks to "write backend tests", "test the API", "write an e2e test", "test the endpoint", or mentions…