Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/kyleve/stuff/todo-triagenpx skills add kyleve/Stuff --skill todo-triagegit clone --depth 1 https://github.com/kyleve/StuffWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/kyleve/stuff/todo-triage)<a href="https://agentmods.dev/skills/kyleve/stuff/todo-triage"><img src="https://agentmods.dev/badge/skills/kyleve/stuff/todo-triage.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00068 | $0.01802 |
| Opus 5 | $0.00034 | $0.00901 |
| Sonnet 5 | $0.00014 | $0.00360 |
| Haiku 4.5 | $0.00007 | $0.00180 |
Grade A, and why
todo-triage scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 134 lines — stays where its author put it; the contents beside it link to each section on GitHub.
The backlog lives in TODOs.md files, one per area. This skill is the procedure
for putting things into them and keeping them honest.
Read the root TODOs.md first. It owns the item format and
the placement rule. This skill assumes both. It is the contract. This file is
only the process.
Never invent structure. If a job here seems to need a new field, section, or
file, change the root TODOs.md and say so. Do not improvise it into one area's
file.
The weekly pass
The weekly automation runs the whole job in one go. The order matters. The backlog is the source of truth, and the report is written from it, so the report comes last.
- Drain
INBOX.md— see below. - Re-verify the open backlog, area file by area file. Close what shipped, correct line numbers that have moved, drop claims that are no longer true. This is the bulk of the work.
- Review the week's new surface — the commits and merged PRs landed since
the last audit's header date — and file what you find, tagged
(audit <date>). - Rewrite
MODULE_AUDIT.mdfrom what the backlog now says — see below. - Update the docs the week invalidated: a module's
README.md/AGENTS.mdwhen its architecture, public API, or a documented behavior changed. The rootAGENTS.mdwhen a global rule, a target, or the build/test flow did. Run./sync-agentsafterwards if anyAGENTS.mdchanged. - Push the branch and open a PR ready-for-review. Follow the
github-workflowskill. Describe the end state: what moved in the backlog, what the audit now says, and what you verified rather than assumed.
An ad-hoc run — someone asking you to triage the inbox or file a finding — is just the relevant section below, not the whole pass.
Draining the inbox
INBOX.md holds raw human notes: terse, uncited, unverified, sometimes already
fixed. Take each entry under # Open in turn.
- Understand what's being claimed. An entry like "Raw data browser (similar to SD browser)" is a feature ask. "why do we delete all the DB entries on logout?" is a question that can or cannot hide a bug. Resolve which before going further.
- Verify it against current source. Find the code. Make sure that the behavior is
really what the note says, and that it hasn't already been fixed or already
been filed. This is the step that earns the promotion. An entry that reaches
a
TODOs.mdunverified is worse than one still sitting in the inbox, because it now reads as established. - Expand it. Write the body the root format asks for: the
File.swift:123sites, why it matters (user-visible consequence, not just tidiness), and a concrete suggested fix. Preserve the human's intent. If the note asks a question you now know the answer to, answer it in the body rather than restating the question. - Route it by the placement rule: the lowest
TODOs.mdspanning every area it touches. Create that area's file if it doesn't exist yet (copy the header shape from a sibling; link to the root format, don't restate it). - Bucket and tag it.
PX/P0/P1/P2, plusquick-winorneeds-design. Tag the origin(human <date the note was written>). Keep the human's date, not today's. The point is to show where the item came from. A new item takes the bucket its severity implies (high →P0, medium →P1, low →P2). An item already in the file keeps the bucket it has. Priority is a decision someone made. A severity opinion from a later pass doesn't get to silently overrule it. Argue for the move in the body instead. - Remove it from
INBOX.md. The origin tag is the trail. Don't leave a copy behind.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 134 lines · 68 tokens per session scan A 41225864e39b
todo-triage is a skill published in the GitHub repository kyleve/Stuff (2 stars, last pushed 4d ago), licensed Apache-2.0. It adds 68 tokens to every session and 1,802 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
wayfinder
Plan a huge chunk of work (more than one agent session can hold) as a shared map of decision tickets on your issue tracker, and resolve them one at a time until the way to the destination is clear.
sap-transport-overview
System-wide inventory of open transport requests — every visible modifiable request, who owns it, how big it is, and supported risk signals such as empty/local requests, explicit locks, and confirmed manifest overlaps. Headers-only and cheap; NO source diffs. Use when asked "what transports are open in the system"…
timeline-creator
Create HTML timelines and project roadmaps with Gantt charts, milestones, phase groupings, and progress indicators. Use when users request timelines, roadmaps, Gantt charts, project schedules, or milestone visualizations.
okx-task-watch
监听任务进展 / 帮我盯着任务 / 任务有动静告诉我 / 历史消息 / 未读消息 / 未决策 / 待决策 / 继续监听 / task watch / user watch / monitor task progress / catch me up on tasks / outstanding decisions — OKX A2A user-session task-notification monitor: live long-poll via okx-a2a user watch (also drains backlog of past/missed/unread events on entry) plus…
pm-all
Skill "pm-all" from wei63w/pm-manager, covering user input, outline and shared workflow (all /pm- commands).
bootstrap-prd
Set up PRD-driven development infrastructure for a new project, including directory structure, templates, and roadmap.