Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add jmagly/aiwg --skill package-plugingit clone --depth 1 https://github.com/jmagly/aiwgWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jmagly/aiwg/package-plugin)<a href="https://agentmods.dev/skills/jmagly/aiwg/package-plugin"><img src="https://agentmods.dev/badge/skills/jmagly/aiwg/package-plugin/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/jmagly/aiwg/package-plugin"><img src="https://agentmods.dev/badge/skills/jmagly/aiwg/package-plugin.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Excessive Agency · line 93 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00018 | $0.01313 |
| Opus 5 | $0.00009 | $0.00656 |
| Sonnet 5 | $0.00004 | $0.00263 |
| Haiku 4.5 | $0.00002 | $0.00131 |
Grade A, and why
package-plugin scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 179 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Package Plugin
You validate and package either a built-in marketplace wrapper or a standalone
project-local wrapper. Standalone wrappers are auto-discovered under
.aiwg/plugins/<name>/ and emitted as deterministic provider archives.
Triggers
Alternate expressions and non-obvious activations (primary phrases are matched automatically from the skill description):
- "bundle the voice plugin for release" → package voice plugin
- "prepare the SDLC plugin for distribution" → package sdlc plugin
- "create the plugin wrapper" → package the generated provider wrapper
- "publish project-local plugin" → validate and package the repository-local wrapper
- "standalone plugin repository" → use the community/team repository workflow
Trigger Patterns Reference
| Pattern | Example | Action |
|---|---|---|
| Package plugin | "package plugin sdlc" | Run aiwg package-plugin sdlc |
| Bundle plugin | "bundle plugin voice" | Run aiwg package-plugin voice |
| Create package | "create plugin package utils" | Run aiwg package-plugin utils |
| Dry run | "validate sdlc plugin before packaging" | Run aiwg package-plugin sdlc --dry-run |
| Standalone wrapper | "package project-local plugin team-tools" | Run aiwg package-plugin team-tools --dry-run |
| Explicit source | "package wrapper from wrappers/team-tools" | Run aiwg package-plugin team-tools --source wrappers/team-tools |
Behavior
When triggered:
-
Extract intent:
- Which delivery wrapper is being packaged?
- Which provider wrapper is needed?
- Should existing generated output be cleaned first?
- Is this a validation dry run?
-
Run the appropriate command:
# Package a marketplace wrapper (creates archive, no publish) aiwg package-plugin sdlc aiwg package-plugin voice aiwg package-plugin marketing # Validate only — no archive created aiwg package-plugin sdlc --dry-run # Build one provider-specific wrapper aiwg package-plugin sdlc --provider codex # Clean generated output before rebuilding aiwg package-plugin sdlc --clean # Standalone/project-local wrapper (auto-discovered) aiwg package-plugin team-tools --provider all --output dist/plugins # Explicit in-repository source aiwg package-plugin team-tools --source wrappers/team-tools --provider codex
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 179 lines · 18 tokens per session scan A bab32f91f19b
package-plugin is a skill published in the GitHub repository jmagly/aiwg (211 stars, last pushed yesterday), licensed MIT. It adds 18 tokens to every session and 1,313 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
surge
Use when a user provides a PRD, spec, or detailed requirements document and needs a full project delivered through iterative expert orchestration — multi-round analyze/research/design/implement/QA cycles with convergence detection. NOT for: single-file edits, quick prototypes, simple Q&A, or tasks without a written…
goal-writer
Drafts a goal+rider document pair that briefs an autonomous coding agent on one round of work — a goal file under 4,000 characters (sized to fit the /goal command in both Claude Code and Codex) plus an unbounded rider with phased plans and named depth tests. Use when the user says "draft a goal", "write a goal+rider"…
horizon
Run a durable Horizon workflow for a multi-feature goal with bounded autonomous retries and an audit trail.
check-in
Record a Parallax protocol checkpoint with concrete evidence before gated implementation work.
debug
Perform an evidence-based Parallax diagnosis or post-build audit and verify the repair.
hyperplan
Harden a non-trivial plan through a three-round adversarial critique and evidence-based synthesis.