Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/jpicklyk/task-orchestrator/configure-servernpx skills add jpicklyk/task-orchestrator --skill configure-servergit clone --depth 1 https://github.com/jpicklyk/task-orchestratorWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jpicklyk/task-orchestrator/configure-server)<a href="https://agentmods.dev/skills/jpicklyk/task-orchestrator/configure-server"><img src="https://agentmods.dev/badge/skills/jpicklyk/task-orchestrator/configure-server.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00131 | $0.02469 |
| Opus 5 | $0.00066 | $0.01234 |
| Sonnet 5 | $0.00026 | $0.00494 |
| Haiku 4.5 | $0.00013 | $0.00247 |
Grade A, and why
configure-server scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
4. If REST is enabled, sanity-check it: `curl http://localhost:3001/api/v1/health` should return `200`. How it starts
The opening of the file, as written. The whole thing — 213 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Configure Server — Runtime & Transport Setup
Decides how the MCP Task Orchestrator container is launched and reached: transport, REST API mode,
port publishing, config mount, and config-sync. This is a runtime/deployment concern, distinct from
quick-start (first-time onboarding narrative) and manage-schemas (workflow gates/traits/
resources:/actor_authentication content inside .taskorchestrator/config.yaml). If the user wants
schema or gate changes — including resource-lease declarations — redirect to /manage-schemas instead
of proceeding here.
One operator escape hatch worth knowing when launching the container: RESOURCE_LEASES_ENFORCED=false
(env, default true) disables resource-lease gate enforcement server-wide — a kill switch for lease
contention incidents, same gate-policy category as DEGRADED_MODE_POLICY. Configuring which resources
exist and which traits declare them stays in /manage-schemas; this skill only knows the switch.
The full fragment catalog (exact env tuples, loopback caveat, Windows/MSYS caveat, .mcp.json shapes)
lives in references/runtime-config.md — this skill's job is the decision flow and rendering,
not re-deriving that catalog. Read it before rendering any command.
Step 1 — Offer the recommended default first
Before walking the full decision tree, offer the one-tap recommended path via AskUserQuestion:
AskUserQuestion(questions: [{
question: "How do you want to run the server?",
header: "Server setup",
multiSelect: false,
options: [
{ label: "Recommended default", description: "HTTP + REST API enabled, unauthenticated, loopback-bound (127.0.0.1). Enables config-sync out of the box. Best for a single developer working across multiple projects." },
{ label: "Customize", description: "Walk through transport, REST mode, config mount, and debug logging one at a time." }
]
}])
Recommended default → skip straight to Step 5 (Render — HTTP) with: REST = unauthenticated, config mount = none, debug = off. Customize → Step 2.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 213 lines · 131 tokens per session scan A 66a63182d994
configure-server is a skill published in the GitHub repository jpicklyk/task-orchestrator (206 stars, last pushed 1mo ago), licensed MIT. It adds 131 tokens to every session and 2,469 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
pneuma-project
Project-context awareness — multi-session workflows around one topic, shared materials and preferences, and cross-mode handoffs as a high-value user path.
vc-generate-phase-program
Generate kickoff artifacts for a multi-phase program: umbrella plan, Program Goal Charter, session-goal block, per-phase plan stubs, and the 7-step per-phase inner loop reference.
vc-intent-clarify
Clarify intent before RIPER-5 phase delegation. Scores ambiguity (4 signals); generates structured multi-choice questions for Tier 2. Two-mode: SIMPLE and DEEP.
vc-agent-browser
AI-optimized browser automation CLI with context-efficient snapshots. Use for long autonomous sessions, self-verifying workflows, video recording, and cloud browser testing (Browserbase).
vc-scenario
Generate comprehensive edge cases and test scenarios by decomposing features across 12 dimensions. Use before implementation or testing to catch issues early.
vc-security
STRIDE + OWASP-based security audit with optional auto-fix. Scans code for vulnerabilities, categorizes by severity, and can iteratively fix findings using vc-autoresearch pattern.