Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/justomsharma/github-resume-assistant/plan-firstnpx skills add justomsharma/github-resume-assistant --skill plan-firstgit clone --depth 1 https://github.com/justomsharma/github-resume-assistantWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00064 | $0.00501 |
| Opus 5 | $0.00032 | $0.00251 |
| Sonnet 5 | $0.00013 | $0.00100 |
| Haiku 4.5 | $0.00006 | $0.00050 |
Grade A, and why
plan-first scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
plan-first
The rule this project lives by: never code before the approach is validated.
When the user asks for anything that would change code, do NOT start editing. Run this sequence first.
Step 1 — Understand the request
Restate what the user is asking for in one sentence. If it's ambiguous, ask a clarifying question before going further.
Step 2 — Read the existing code FIRST
- Read
docs/PRODUCT.md,docs/ROADMAP.md, anddocs/ARCHITECTURE.mdto ground yourself in what we're building and where code belongs. - Use Glob/Grep/Read to find the files this change touches. Read them.
- Identify existing patterns, utilities, and models you should reuse instead of reinventing. Note where the new code belongs per ARCHITECTURE.md.
Step 3 — Check it against the roadmap
- Which ROADMAP.md item is this? If it's not on the roadmap, flag it: is this scope creep, or should the roadmap be updated first?
- Confirm we're building versions in order (don't pull v2 work into v1).
Step 4 — Form 1–2 approaches
For the chosen work, write a short approach:
- What files change / get created (mapped to ARCHITECTURE.md layout).
- Key decisions (data shapes, where logic lives,
core/vsserver/vsclients/). - Edge cases to handle (especially the empty-GitHub case).
- What tests will prove it works (per TESTING.md).
If there's a real fork in the road, present 2 approaches with tradeoffs.
Step 5 — Validate with the user (STOP here)
Present the approach and wait for approval. Use AskUserQuestion if there's a real choice. Do not write code until the user confirms the approach.
Handoff
Once the user approves the approach → hand off to /implement.
Pass along: the approved approach, the files to touch, and the test plan.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 51 lines · 64 tokens per session scan A 79fde2504ef2
plan-first is a skill published in the GitHub repository justomsharma/github-resume-assistant (0 stars, last pushed 1mo ago), licensed MIT. It adds 64 tokens to every session and 501 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
opik-diagnose
Surface the Opik traces worth a developer's attention, ranked by signal — errors, failed tool calls, latency, regressions, and low online-eval scores — plus Diagnostics issues. Reads live/production traces via the SDK (searchtraces and agentinsights) and works with no MCP; uses the MCP issue entity when connected.…
client-scripts
Write ServiceNow client scripts (onLoad/onChange/onSubmit/onCellEdit) using gform, guser, GlideAjax, field visibility/mandatory toggles, and validation with debounced server calls.
agoragentic-transaction-assurance
Prepare, evaluate, and reconcile autonomous agent transactions without self-granting payment or owner authority. Use when an agent must bind principal authority, seller terms, payment evidence, execution, delivered outcome, and reconciliation; handle paid retries safely; or prepare an authority request for owner…
linkding
Manage bookmarks with Linkding. Use when the user asks to "save a bookmark", "add link", "search bookmarks", "list my bookmarks", "find saved links", "tag a bookmark", "archive bookmark", "check if URL is saved", "list tags", "create bundle", or mentions Linkding bookmark management.
maya-shot-export
Pipeline stage — shot-level export: frame ranges, cameras, FBX / Alembic packaging for editorial. Use when packaging shot data for downstream departments. Not for full pipeline publish (maya-pipeline) or scene assembly (maya-scene-assembly).
knowledge
Unified cross-store knowledge query. Searches MEMORY.md, Thoughtbox knowledge graph, git history, and assumption registry in parallel, returning results with provenance.