Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/joaonic/agentkit/implement-plannpx skills add Joaonic/agentkit --skill implement-plangit clone --depth 1 https://github.com/Joaonic/agentkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00019 | $0.04884 |
| Opus 5 | $0.00010 | $0.02442 |
| Sonnet 5 | $0.00004 | $0.00977 |
| Haiku 4.5 | $0.00002 | $0.00488 |
Grade A, and why
implement-plan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 253 lines — stays where its author put it; the contents beside it link to each section on GitHub.
LEIA ESTA SKILL COMPLETAMENTE ANTES DE COMEÇAR
Implementar um plano existente. Não cria plano. Sempre numa worktree separada.
Fonte única:
docs/governance/cursor/workflow.mddocs/governance/cursor/workflow/*.md
Contrato operacional obrigatório desta skill:
- Você é o agente pai e atua apenas como orquestrador.
- Você não pode usar diretamente Read, Write, Edit, MultiEdit, Shell, Grep, Search, Browser, MCP, ferramentas de VCS remotas, Web, testes, ou qualquer outra tool fora da tool de subagent.
- Todo acesso a ficheiros, comandos, GitLab/GitHub (tracker), MCP, web, testes e validações deve acontecer dentro de subagents.
- A execução é obrigatoriamente sequencial. Uma etapa por vez.
- Cada chamada de subagent deve definir explicitamente
subagent_type. - Cada chamada de subagent deve incluir o marcador exato da etapa no
promptou nadescription. - Não pular etapas obrigatórias.
- Após
workflow:code-review, cumprir sempreworkflow:ux-review. Com alteração em fluxos ou superfície user-facing sobweb/**(ou outro frontend definido no subprojeto), usarux-reviewer. Sem alteração user-facing, usarverifieroudocspara registar «UX Review: não aplicável (sem frontend)» — não invocarux-reviewer(rule08-ux-mandatory.mdc). - O
ux-reviewer(e a etapaworkflow:ux-review) não substituemworkflow:posttask. - Antes de declarar concluído, cumprir a skill
posttask, MR pareado (GitLab) ou PR (exceção GitHub),review-open-pre CI verde conforme o workflow do projeto.
Política de zero tolerância (obrigatória em todas as etapas):
- Não existe "aprovado com ressalvas" — qualquer problema encontrado em scope (código, testes, UX, docs, acessibilidade) é BLOQUEANTE e deve ser resolvido antes de avançar.
- Se o
code-reviewerouux-reviewerreportar problemas, o agente pai deve delegar correção ao subagent adequado e re-submeter para review até zero problemas restarem. - Problemas de UX em ficheiros tocados são bloqueantes quando há mudança user-facing em
web/**(ou frontend do subprojeto em causa).
Uso obrigatório de MCP para pesquisa:
- Subagents de
workflow:investigation,workflow:implementationeworkflow:code-reviewdevem usar Context7 (servidor MCP configurado no projeto) para validar APIs/bibliotecas contra documentação actualizada (Spring Boot, React, Next.js, Flyway, MapStruct, etc.). - Quando existirem outros MCPs oficiais em
.cursor/mcp.jsonpara integrações em scope, usá-los em vez de suposições de treino. - Nunca depender apenas de training data para APIs/bibliotecas quando MCP aplicável estiver disponível.
Regras obrigatórias de CI (aplicar em todas as etapas que envolvam push/CI):
- CI RED é BLOQUEANTE — nenhuma etapa avança com checks falhados. Corrigir antes de prosseguir.
- CI CANCELLED == CI FAILED — pipeline fail-fast cancela jobs satélite. Nunca reexecutar pipelines sem corrigir causa raiz. Em GitLab:
glab ci list --ref <branch>, depoisglab ci trace <job-id>no job que falhou primeiro. Em GitHub Actions (ex.:web/your-github-project):gh run view <id> --json jobsegh run view <id> --log-failed. - Bugs encontrados durante code-review ou posttask são BLOQUEANTES — o agente pai delega correção e re-submete até zero problemas.
Regras obrigatórias de rebase/merge (NUNCA perder código):
- Ao fazer rebase ou merge de
mainna branch de trabalho, NUNCA perder conteúdo que já existia emmain. O rebase serve para incorporar main — não para sobrescrever. - Durante resolução de conflitos, ambos os lados devem ser preservados: o código novo da feature E o código existente de main. Se houver conflito real (mesmo trecho modificado nos dois lados), o agente deve fundir manualmente, mantendo a semântica de ambos.
- Após rebase, o agente deve verificar:
git diff origin/main..HEAD -- <ficheiros com conflito>e confirmar que nenhuma funcionalidade, import, teste, config ou bloco de código de main desapareceu. - Se o agente detectar que perdeu código de main durante rebase, deve imediatamente corrigir (cherry-pick, re-apply, ou editar manualmente) antes de avançar para qualquer outra etapa.
- Esta regra aplica-se a todas as etapas: investigation, implementation, code-review, posttask — sempre que houver rebase/merge de main.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 253 lines · 19 tokens per session scan A 58cb03486694
implement-plan is a skill published in the GitHub repository Joaonic/agentkit (2 stars, last pushed 3mo ago), licensed MIT. It adds 19 tokens to every session and 4,884 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…