Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add k1lgor/virtual-company --skill 25-legacy-archaeologistgit clone --depth 1 https://github.com/k1lgor/virtual-companyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/k1lgor/virtual-company/25-legacy-archaeologist)<a href="https://agentmods.dev/skills/k1lgor/virtual-company/25-legacy-archaeologist"><img src="https://agentmods.dev/badge/skills/k1lgor/virtual-company/25-legacy-archaeologist/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/k1lgor/virtual-company/25-legacy-archaeologist"><img src="https://agentmods.dev/badge/skills/k1lgor/virtual-company/25-legacy-archaeologist.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00034 | $0.03358 |
| Opus 5 | $0.00017 | $0.01679 |
| Sonnet 5 | $0.00007 | $0.00672 |
| Haiku 4.5 | $0.00003 | $0.00336 |
Grade A, and why
legacy-archaeologist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 334 lines — stays where its author put it; the contents beside it link to each section on GitHub.
🏛️ Legacy Archaeologist
You explore the "ruins" of old codebases to recover valuable business logic and identify dangerous technical debt.
🛑 The Iron Law
NO REFACTORING WITHOUT UNDERSTANDING THE EXISTING SYSTEM FIRST
You cannot refactor what you don't understand. Read before you change. Map before you move. Every "cleanup" that breaks production was done without understanding.
🛠️ Tool Guidance
- Exploration: Use
Glob(recursive) to map the entry points of unknown systems. - Tracing: Use
Grepto find where "magic variables" or deprecated APIs are used. - Documentation: Use
Readto extract logic for reverse-engineering docs. - Verification: Use
Bashto run existing tests or scripts.
📍 When to Apply
- "Figure out how this old monolith works."
- "Document this legacy project before we migrate it."
- "Find where the payment logic is hidden in this mess."
- "Plan an incremental refactor for this Python 2 app."
Decision Tree: Legacy Exploration
graph TD
A[Legacy Codebase] --> B[Map entry points: main, routes, cron]
B --> C[Trace data flow: input → processing → output]
C --> D{Found hot spots?}
D -->|Yes| E[Document: which modules are depended on most]
D -->|No| F[Search deeper: grep for function calls, imports]
F --> D
E --> G[Catalog dead code: never-imported, never-called]
G --> H[Identify security holes: SQL injection, hardcoded secrets]
H --> I{Tests exist?}
I -->|No| J[Write characterization tests for critical paths FIRST]
I -->|Yes| K[Verify tests pass (establish baseline)]
J --> L[Plan Strangler Fig refactoring]
K --> L
L --> M[Incremental changes: one module at a time]
M --> N{Tests still pass?}
N -->|No| O[Revert change, understand why]
O --> M
N -->|Yes| P[✅ Refactoring step complete]
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 334 lines · 34 tokens per session scan A 9990e3a08cda
legacy-archaeologist is a skill published in the GitHub repository k1lgor/virtual-company (4 stars, last pushed 2mo ago), licensed MIT. It adds 34 tokens to every session and 3,358 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
health-check
Runs plugin health checks (venv packages, skill registration, and album slug collisions). Use when the user asks to check plugin health, verify setup, or troubleshoot missing skills.
session-profiler
Profile and debug Hermes sessions from their JSONL transcripts. Find a session and its subagents, build a queryable event table, summarize the work as a hierarchical table of contents, break down wall time, inference, tools, tokens, and estimated cost per agent, identify errors and improvement opportunities, and…
bug-fix
Investigate, reproduce, and safely fix a bug with regression protection. Composes context, diagnosis, architecture, code quality, and testing guardrails into a reproduce-first repair workflow. Use when the user says 'fix this bug', 'debug this', 'investigate this failure', 'patch this regression', 'repair this issue'…
refactor-safely
Restructure existing code safely without changing externally observable behavior. Composes context, design, architecture, code quality, and testing guardrails into a characterization-first refactoring workflow. Use when the user says 'refactor this', 'clean this up', 'untangle this module', 'move this to the right…
playwright-debugging
Use when Playwright scripts fail, tests are flaky, selectors stop working, or timeouts occur - provides systematic debugging approach for browser automation issues.
perf-code-paths
Use when mapping code paths, entrypoints, and likely hot files before profiling.