Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add khalilbenaz/claude-skills-collection --skill coding-agent-buildergit clone --depth 1 https://github.com/khalilbenaz/claude-skills-collectionWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/khalilbenaz/claude-skills-collection/coding-agent-builder)<a href="https://agentmods.dev/skills/khalilbenaz/claude-skills-collection/coding-agent-builder"><img src="https://agentmods.dev/badge/skills/khalilbenaz/claude-skills-collection/coding-agent-builder/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/khalilbenaz/claude-skills-collection/coding-agent-builder"><img src="https://agentmods.dev/badge/skills/khalilbenaz/claude-skills-collection/coding-agent-builder.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 2 findings, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Tool Misuse · line 39 Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).Fix: Validate all tool parameters against an allowlist. Reject dangerous parameter values (shell=True, --force, -rf /) and use safe defaults.
- medium MCP Rug Pull · line 52 Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.Fix: Pin the image: image:tag or image@sha256:abc123
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00088 | $0.02207 |
| Opus 5 | $0.00044 | $0.01104 |
| Sonnet 5 | $0.00018 | $0.00441 |
| Haiku 4.5 | $0.00009 | $0.00221 |
Grade A, and why
coding-agent-builder scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Runs shell commandslowCapability
Expected in a hook, worth knowing in a rule or an instructions file.
r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=timeout) How it starts
The opening of the file, as written. The whole thing — 228 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Coding Agent Builder
Quand utiliser ce skill
Conception ou implémentation d'un agent autonome qui interagit avec une base de code : lecture/écriture de fichiers, exécution de commandes, gestion Git, tests automatisés. S'applique à un agent SWE-bench-style, un assistant intégré dans un IDE, ou un pipeline CI/CD.
Critères d'architecture : mono-agent vs multi-agents
| Critère | Mono-agent | Multi-agents (planner + executor + reviewer) |
|---|---|---|
| Tâche simple (<5 fichiers) | ✅ | Surcharge inutile |
| Tâche complexe, multi-modules | ❌ fragile | ✅ |
| Budget tokens serré | ✅ | ❌ |
| Cohérence inter-fichiers critique | ❌ | ✅ |
Workflow en 10 étapes
1. Définir les tools fondamentaux
Chaque tool renvoie un dict structuré (stdout, stderr, exit code). Pas d'exception silencieuse.
import subprocess, pathlib
def read_file(path: str) -> dict:
p = pathlib.Path(path)
return {"content": p.read_text(encoding="utf-8"), "exists": p.exists()}
def write_file(path: str, content: str) -> dict:
pathlib.Path(path).write_text(content, encoding="utf-8")
return {"written": True, "path": path}
def run_command(cmd: str, timeout: int = 30) -> dict:
r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=timeout)
return {"stdout": r.stdout, "stderr": r.stderr, "returncode": r.returncode}
def run_tests(suite: str = ".") -> dict:
return run_command(f"pytest {suite} --tb=short -q")
Outils minimaux requis : read_file, write_file, run_command, search_code, git_diff, run_tests.
2. Sandbox d'exécution (obligatoire en production)
Docker (auto-hébergé) :
docker run --rm \
--network=none \ # pas d'accès réseau
--memory=512m \
--cpus=1 \
--read-only \
-v $(pwd)/workspace:/workspace \
python:3.12-slim \
bash -c "cd /workspace && python agent_task.py"
E2B (sandbox managé, plus simple) :
from e2b_code_interpreter import Sandbox
with Sandbox() as sbx:
result = sbx.run_code("print('hello')")
print(result.text)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 228 lines · 88 tokens per session scan A 9b5995f89d7b
coding-agent-builder is a skill published in the GitHub repository khalilbenaz/claude-skills-collection (22 stars, last pushed 15d ago), licensed MIT. It adds 88 tokens to every session and 2,207 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
explain
Explains code/architecture with Mermaid diagrams and sequence flows. Triggers: what does X do, how does Y work, explain code, sequence diagram.
common-sense-index-investing-bogle
Apply John Bogle index investing rules for low-cost funds, asset allocation, fees, taxes, ETFs, advisers, and buy-hold discipline.
finance-econ-literacy
A Korean-language guide to understanding economic indicators such as interest rates, exchange rates, inflation, GDP, employment, and trade. It explains how these figures can affect loans, savings, investments, and spending.
stock-analysis-lead
Orchestrate a US-stock investment analysis — classify sector archetype, fetch SEC filings, dispatch a tiered fan-out of six vertical equity-research agents (business model, earnings quality, balance sheet, management, industry, peer comparison) over a validated JSON findings contract, then synthesize a buy/hold/sell…
stock-business-review
Review a US-listed company's business model and revenue structure for an equity-research workup. Covers product/service mix, customer concentration, geographic exposure, industry position, revenue-growth decomposition (organic vs acquired vs price vs volume), and information-tier discipline (which numbers are facts vs…
stock-earnings-quality-review
Review a US-listed company's earnings quality, cash-flow integrity, and operating leverage for an equity-research workup. Covers operating cash flow vs net income drift, free cash flow trajectory, capex character (maintenance vs expansion), equity issuance / shareholder-return yield, revenue-quality signals…