Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add jcwleo/oh-no-harness --skill ralplangit clone --depth 1 https://github.com/jcwleo/oh-no-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jcwleo/oh-no-harness/ralplan)<a href="https://agentmods.dev/skills/jcwleo/oh-no-harness/ralplan"><img src="https://agentmods.dev/badge/skills/jcwleo/oh-no-harness/ralplan/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/jcwleo/oh-no-harness/ralplan"><img src="https://agentmods.dev/badge/skills/jcwleo/oh-no-harness/ralplan.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00047 | $0.07836 |
| Opus 5 | $0.00023 | $0.03918 |
| Sonnet 5 | $0.00009 | $0.01567 |
| Haiku 4.5 | $0.00005 | $0.00784 |
Grade A, and why
ralplan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 664 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Ralplan for Claude Code
This generated file is the Claude Code-facing runtime skill document. Claude Code slash commands should read this file directly; maintainers edit the source documents listed below instead.
Generated Runtime Composition
Source order:
../../docs/skill-core/ralplan.md../../docs/platforms/claude-code-ralplan.md
The sections below are already composed for this platform. Do not ask the runtime model to load another platform's runtime document or invocation syntax.
Source: docs/skill-core/ralplan.md
Ralplan
Ralplan converts approved requirements plus repository evidence into one
reviewed plan and Ralph execution profile. It never implements production
code and writes only under .oh-no/. Plan-Reviewer depth and instance count
are selected by the execution risk, not applied as an unconditional tax.
Invariants
R1. Requirements direction is user-owned. A role proposal that changes the
Direction Contract is `requested-direction-change: yes` and needs explicit
user approval; do not incorporate a requested direction change without
explicit approval. An approved change starts a new planning run.
R2. The plan body is Planner-owned. Plan-Reviewer reviews and blocks; it MUST
NOT produce a replacement plan.
R3. Plan-Reviewer reviews the exact Planner draft (id + body), not a recap:
architecture pass, then quality-gate pass, in one dispatch.
R4. APPROVE freezes the exact reviewed Planner draft. Non-blocking findings
are optional follow-ups and cause no mutation or dispatch; a body change
required before approval is blocking and yields ITERATE.
R5. On ITERATE, Planner classifies every blocker before mutating the draft or
assigning a new draft id (disposition-before-mutation).
R6. Review runs exactly once (Review v1) per planning run. REJECT escalates
immediately. An all-accepted ITERATE yields exactly one final Planner
revision v2 with no further review.
R8. Every blocker names a basis, exact draft pointer, material consequence,
and smallest sufficient correction. Preference, future-proofing, and
optional stronger proof are non-blocking.
R9. Roles are sequential — Analyst -> Planner -> Plan-Reviewer. Review
topology is risk-selected: STANDARD and ordinary THOROUGH each dispatch ONE
required full-role Plan-Reviewer. Only the named THOROUGH paired-review
trigger selects one perspective-diverse pair and the platform's escalated
diversity (cross-host on Codex); THOROUGH alone never does.
R10. Active semantic risk selects mode and cost; category words and host
capability alone never escalate.
R15. The Active plan contract is compiled once before Planner draft v1, and
the identical block goes to Planner and every reviewer instance.
Reviewer missing-field blocking is limited to its active rows.
R16. Recorded snapshot state authorizes transitions; unrecorded in-memory
conclusions do not.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 664 lines · 47 tokens per session scan A a31378eabde0
ralplan is a skill published in the GitHub repository jcwleo/oh-no-harness (11 stars, last pushed 1mo ago), licensed MIT. It adds 47 tokens to every session and 7,836 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…