Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add jpoutrin/product-forge --skill mypy-setupgit clone --depth 1 https://github.com/jpoutrin/product-forgeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jpoutrin/product-forge/mypy-setup)<a href="https://agentmods.dev/skills/jpoutrin/product-forge/mypy-setup"><img src="https://agentmods.dev/badge/skills/jpoutrin/product-forge/mypy-setup.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00016 | $0.03613 |
| Opus 5 | $0.00008 | $0.01806 |
| Sonnet 5 | $0.00003 | $0.00723 |
| Haiku 4.5 | $0.00002 | $0.00361 |
Grade A, and why
mypy-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 611 lines — stays where its author put it; the contents beside it link to each section on GitHub.
mypy-setup
Category: Python Development
Usage
/mypy-setup [--strict] [--django] [--format=<ini|toml>] [--install]
Arguments
| Argument | Required | Description |
|---|---|---|
--strict |
No | Use strict type checking configuration |
--django |
No | Add Django-specific configuration and plugin |
--format=<ini|toml> |
No | Config format (default: ini) |
--install |
No | Install Mypy and required plugins |
Purpose
Set up Mypy static type checking in a Python project:
- Create Configuration: Generate mypy.ini or pyproject.toml config
- Install Dependencies: Install Mypy and type stub packages
- Configure IDE: Add Mypy settings for VS Code/PyCharm
- Setup CI/CD: Generate GitHub Actions workflow
- Add Pre-commit: Configure pre-commit hook for Mypy
Execution Instructions for Claude Code
When this command is run, Claude Code should:
1. Parse Arguments
STRICT_MODE = true if --strict specified
DJANGO_MODE = true if --django specified
FORMAT = value after --format= (default: "ini")
INSTALL = true if --install specified
2. Detect Project Type
Scan the project to determine:
# Check for Django
HAS_DJANGO=false
if [ -f "manage.py" ] || grep -q "django" requirements.txt 2>/dev/null; then
HAS_DJANGO=true
echo "✓ Django project detected"
fi
# Check for existing config
HAS_CONFIG=false
if [ -f "mypy.ini" ] || [ -f ".mypy.ini" ] || grep -q "\[tool.mypy\]" pyproject.toml 2>/dev/null; then
HAS_CONFIG=true
echo "⚠ Existing Mypy configuration found"
fi
# Check Python version
PYTHON_VERSION=$(python --version | cut -d' ' -f2 | cut -d'.' -f1,2)
echo "Python version: $PYTHON_VERSION"
3. Install Mypy (if --install)
if [ "$INSTALL" = true ]; then
echo "Installing Mypy..."
# Use uv if available, otherwise pip
if command -v uv &> /dev/null; then
PKG_MANAGER="uv pip install"
else
PKG_MANAGER="pip install"
fi
# Install Mypy
$PKG_MANAGER mypy
# Install Django plugin if needed
if [ "$DJANGO_MODE" = true ] || [ "$HAS_DJANGO" = true ]; then
$PKG_MANAGER django-stubs mypy-django-plugin
fi
# Install common type stubs
$PKG_MANAGER types-requests types-PyYAML types-redis
echo "✓ Mypy installed successfully"
fi
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 611 lines · 0 tokens per session scan A b579a519478c
mypy-setup is a skill published in the GitHub repository jpoutrin/product-forge (15 stars, last pushed 6mo ago), licensed MIT. It adds 16 tokens to every session and 3,613 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
python-testing
Python testing best practices using pytest including fixtures, parametrization, mocking, coverage analysis, async testing, and test organization. Use when writing or improving Python tests.
temporal-python-testing
Test Temporal workflows with pytest, time-skipping, and mocking strategies. Covers unit testing, integration testing, replay testing, and local development setup. Use when implementing Temporal workflow tests or debugging test failures.
test-corpus
The testdocuments submodule is a bucket-fetched fixture corpus that is not committed. This skill covers readtestfixture, missing fixtures, valid A/B controls, and submodule push order. Load before running Rust tests on a fresh clone, setting up an A/B control, adding a fixture-backed test, or diagnosing…
python-providers
Create, modify, test, or package Python provider adapters under python/providers, including framework-specific dependencies, public imports, type inference, and provider metadata. Use for Python provider work only; use python-sdk for core SDK changes.
xberg-typescript-toolchain
Work on Xberg TypeScript or JavaScript packages with the repository's actual poly, pnpm, npm, Vitest, napi-rs, wasm-pack, and integration-package boundaries. Load for TS/JS tooling or package changes, not Rust-only binding generation.
adk-verify-snippets
Checks that every Python code block in a Markdown file actually compiles and runs, by extracting each block to a temporary file, executing it in an isolated subprocess, and writing a pass/fail report with per-snippet coverage. Use when the user asks to verify, test, or validate the code samples in a README, a guide…