Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add kimgoetzke/coding-agent-configs --skill update-skillsgit clone --depth 1 https://github.com/kimgoetzke/coding-agent-configsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/kimgoetzke/coding-agent-configs/update-skills)<a href="https://agentmods.dev/skills/kimgoetzke/coding-agent-configs/update-skills"><img src="https://agentmods.dev/badge/skills/kimgoetzke/coding-agent-configs/update-skills.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00050 | $0.00672 |
| Opus 5 | $0.00025 | $0.00336 |
| Sonnet 5 | $0.00010 | $0.00134 |
| Haiku 4.5 | $0.00005 | $0.00067 |
Grade A, and why
update-skills scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 86 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Update Skills
Check for updates to locally installed skills by fetching the latest from kimgoetzke/coding-agent-configs on GitHub and comparing against the local skills directory.
Configuration
- Remote repo:
https://github.com/kimgoetzke/coding-agent-configs.git - Scripts location: Bundled in this skill's
scripts/directory
Target directory by tool
| Tool | Default target directory |
|---|---|
| Claude Code | ~/.claude/skills |
| Copilot | ~/.copilot/skills |
| Pi | ~/.pi/agent/skills |
If you cannot determine which tool you are, ask the user.
Workflow
1. Determine target directory
Set the target directory based on the table above. Use the variable TARGET_DIR in subsequent steps.
Also resolve SKILL_DIR to the absolute path of this locally installed skill directory. Typical values:
- Claude Code:
~/.claude/skills/update-skills - Copilot:
~/.copilot/skills/update-skills - Pi:
~/.pi/agent/skills/update-skills
2. Check for updates
Run the check script:
bash "$SKILL_DIR/scripts/check-updates.sh" "$TARGET_DIR"
3. Parse the output
The script outputs one line per skill with a status prefix:
| Prefix | Meaning |
|---|---|
UP_TO_DATE:<name> |
No changes |
CHANGED:<name> |
Files differ — diff follows until END_DIFF line |
MISSING_LOCALLY:<name> |
Exists in repo but missing locally |
ALL_UP_TO_DATE |
No updates available at all |
Skills that exist locally but not in the remote repo are ignored.
4. Present results to the user
- If
ALL_UP_TO_DATE: tell the user all skills are up to date and stop - Otherwise, FOR EACH
CHANGEDorMISSING_LOCALLYskill:- List the skill name and summarise what changed (files added/removed/modified)
- Show the diff in a code block
- Ask the user if they want to apply this update
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 86 lines · 50 tokens per session scan A 6ecdc54667f6
update-skills is a skill published in the GitHub repository kimgoetzke/coding-agent-configs (2 stars, last pushed 18d ago), licensed MIT. It adds 50 tokens to every session and 672 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
codebase-memory
Use the codebase knowledge graph for structural code queries. Triggers on: explore the codebase, understand the architecture, what functions exist, show me the structure, who calls this function, what does X call, trace the call chain, find callers of, show dependencies, impact analysis, dead code, unused functions…
using-pi-subagents
Operate pi-subagents jobs safely, including direct-work decisions, least-privilege tool selection, thinking-level selection, delegation, bidirectional messaging, parallel starts, timeout selection, waiting, cancellation, result handling, verification, and writer isolation.
configuring-pi-starship
Configure @narumitw/pi-starship and answer questions about its pi-starship.toml settings. Use when the user asks to create, edit, repair, migrate, or understand pi-starship.toml, or asks which pi-starship module, variable, option, style, palette, preset, or runtime behavior to use. Do not use for generic TOML, shell…
skill-creator
Create or update Agent Skills (SKILL.md plus optional scripts, references, or assets). Use when someone asks to design a new Agent Skill, refine an existing one, or structure skills for Pi discovery, packaging, or other Agent Skills-compatible clients.
pi-ralph-wiggum
Long-running iterative development loops with pacing control and verifiable progress. Use when tasks require multiple iterations, many discrete steps, or periodic reflection with clear checkpoints; avoid for simple one-shot tasks or quick fixes.
surf
Control Chrome browser via CLI for testing, automation, and debugging. Use when the user needs browser automation, screenshots, form filling, page inspection, network/CPU emulation, DevTools streaming, or AI queries via ChatGPT/Gemini/Perplexity/Grok/AI Studio.