Borrowing it
Nothing to install: this file belongs to liuyingxuvka/FlowGuard. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/liuyingxuvka/FlowGuard/main/.agents/skills/flowguard-existing-model-preflight/SKILL.mdgit clone --depth 1 https://github.com/liuyingxuvka/FlowGuardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/liuyingxuvka/flowguard/flowguard-existing-model-preflight)<a href="https://agentmods.dev/skills/liuyingxuvka/flowguard/flowguard-existing-model-preflight"><img src="https://agentmods.dev/badge/skills/liuyingxuvka/flowguard/flowguard-existing-model-preflight/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/liuyingxuvka/flowguard/flowguard-existing-model-preflight"><img src="https://agentmods.dev/badge/skills/liuyingxuvka/flowguard/flowguard-existing-model-preflight.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00025 | $0.00585 |
| Opus 5 | $0.00013 | $0.00293 |
| Sonnet 5 | $0.00005 | $0.00117 |
| Haiku 4.5 | $0.00003 | $0.00059 |
Grade A, and why
flowguard-existing-model-preflight scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 46 lines — stays where its author put it; the contents beside it link to each section on GitHub.
FlowGuard Existing Model Preflight
This is a standalone FlowGuard satellite skill for existing-model lookup; it does not replace the downstream owner or the FlowGuard check engine.
Purpose
FlowGuard satellite for existing-model boundaries, ownership, evidence, and duplicate risk.
Entrypoint Scope
It owns lookup, not the downstream route.
Local Material Routing
After admission, read references/existing_model_preflight_protocol.md for lookup and proof.
Entrypoint Acceptance Map
Choose reuse, extend, child, new, or none; block duplicate ownership; select a downstream route.
Use When
- Use before non-trivial work where existing commitments, fields, or models may own the change.
Do Not Use When
- Do not replace native validation; skip trivial work; return unclear scope to
flowguard.
Required Workflow
- Audit the observed head, accepted revision, effective intent, commitments, and behavior plane.
- Search affected models/specs/docs; bind owners, evidence, WorkContexts, and same-intent surfaces.
- Report exact path-quality fingerprints or typed gaps; reuse only with exact identities and topology.
- Preserve unknown, contradictory, unmapped, or scoped facts; return lookup, reuse, and duplicate risk.
- Blueprint/qualification consumes owner, disposition, provider/profile, and finding identities. The native model directory is the only DNA source; standalone export is retired.
Hard Gates
- Only an exact observed instance through the accepted revision and complete
CurrentEffectiveIntentViewis authoritative; history and path matches are candidates. - Model-purpose gate: freeze task-specific failure(s) and claim_boundary; bind native good/bad-per-failure/oracle/current evidence. Reusable types are not fixed-purpose: no mode/fallback; only FlowGuard-declared checks may support completion claims. Require the real FlowGuard check engine and AGENTS.md managed record; forbid fake mini-frameworks or caller-authored currentness.
- Shared words never promote a wrong-plane hit; WorkContext is read-only. Missing or stale owner/provider/mesh/path-quality identity blocks the claim.
- Lightweight path quality triggers ModelMaturation, not contraction, deep review, or code-edit authority.
- Blueprint handoffs never copy native inventories; ArchitectureReduction needs current equivalence/facade or retirement proof.
- Preflight proves lookup/scope only; ModelMaturation decides understanding and DevelopmentProcessFlow admission.
What ships with it
5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 46 lines · 25 tokens per session scan A ac673553cba1
flowguard-existing-model-preflight is a skill published in the GitHub repository liuyingxuvka/FlowGuard (2 stars, last pushed 15d ago), licensed MIT. It adds 25 tokens to every session and 585 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
backend-idempotency
Use this skill when the user says 'idempotency', 'idempotent', 'idempotency key', 'exactly-once', 'retry safety', 'deduplication', 'duplicate detection', 'idempotent endpoint', 'safe retry'. This skill implements idempotency keys and exactly-once semantics so retries never result in duplicate side effects. Applies to…
copilotkit-upgrade
Use when migrating a CopilotKit v1 application to v2 -- updating package imports, replacing deprecated hooks and components, switching from GraphQL runtime to AG-UI protocol runtime, and resolving breaking API changes.
notifications
Send notifications through the unified notification router.
telegram-setup
Connect a Telegram bot to the Vellum Assistant gateway with automated webhook registration and credential storage.
chat-complex-documents
Chat with and search your complex documents — ask questions, extract tables and fields, and get answers grounded in the source. Connects the hosted Unstructured Transform MCP server to parse, structure, and enrich PDFs, Word/Excel/PowerPoint, images, scanned files, emails, and 60+ other formats into clean, AI-ready…
vellum-skills-catalog
Discover bundled skills and search/install community skills from the skills.sh registry.