Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add lukasrepublic/agentic-foundry --skill id-validategit clone --depth 1 https://github.com/lukasrepublic/agentic-foundryWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/lukasrepublic/agentic-foundry/id-validate)<a href="https://agentmods.dev/skills/lukasrepublic/agentic-foundry/id-validate"><img src="https://agentmods.dev/badge/skills/lukasrepublic/agentic-foundry/id-validate.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00310 | $0.03450 |
| Opus 5 | $0.00155 | $0.01725 |
| Sonnet 5 | $0.00062 | $0.00690 |
| Haiku 4.5 | $0.00031 | $0.00345 |
Grade A, and why
id-validate scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 166 lines — stays where its author put it; the contents beside it link to each section on GitHub.
id-validate — read-only static VALIDATION of the change (infra-delivery step 6, RO)
The infra-delivery step sequence (a documented procedure this skill family forms — no workflow engine or state-machine file ships) drives an infra change → merge. Step 6 is the static-validation step
for the everyday-change loop: a PROCEDURE skill the generic agent runs to
statically validate the change before the test / plan / merge steps. It runs read-only
structural + render/policy checks — tofu validate and tofu fmt (the IaC is
syntactically well-formed + canonically formatted; both are directly on the loader's tofu
read-role allowlist — tofu read-only verbs = plan/validate/output/fmt) plus the active
profile's existing read-only infra_binding.policy slot (the render + conftest/OPA evaluation:
kustomize build / helm template → kubeconform + conftest). It surfaces violations (the
malformed config, the lint diff, the failing policy rule) and records the validation observation as
a .foundry/id-validate-report STEP-REPORT NOTE. It is a fast mistake-catcher feeding the
operator + the downstream test/plan steps; the merge floor (the adopter's branch protection + CI
checks — see docs/merge-floor.md) remains the only merge authority.
ADVISORY — not a gate (the merge floor is the merge authority)
This skill is ADVISORY. It surfaces violations + records a STEP-REPORT NOTE; it does NOT gate,
approve, block, or merge. id-validate does NOT self-certify a PASS. Honest disclosure: the
derive_walk_verdict machinery this note used to name as the GREEN-deciding authority over a FROZEN
acceptance contract was retired and does not exist today. It is craft
guidance FOR the trusted operator — a mistake-catcher for the missed tofu validate or the policy
fail waved through — not a defense against them, and not a merge authority. The merge floor
is the only merge authority.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 166 lines · 310 tokens per session scan A b1decece8422
id-validate is a skill published in the GitHub repository lukasrepublic/agentic-foundry (1 stars, last pushed 2d ago), licensed MIT. It adds 310 tokens to every session and 3,450 once invoked, about $0.0015 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
journey-simulation
Use when caller wants to observe how a stranger encounters a flow, artifact, or sandbox — triggers like "simulate a user journey", "test our onboarding / checkout / signup", "will my ICP convert", "how does a cold reader experience this README", "first-time user test", "cognitive walkthrough", or any request to…
are-you-done
A completion checker for coding work that asks for evidence before allowing an assistant to say a task is finished.
yolo-verify
Use to check a feature's work against its successcriteria and record the result. Produces verification.md and, on pass, the YOLO-Verified trailer. Triggers on "verify this", "does it meet the criteria", or as the verify step of yolo-feature.
test-architect
Acts as a Principal Test Architect to plan, write, prune, run, and hand off automated tests for any codebase in any language or framework — never touching production code, never committing, never running against production. Use whenever the user wants to add, fix, expand, refactor, or review tests for a feature, bug…
scenarios-from-requirements
Write brutally thorough, fully-traceable test scenarios from a requirement — a Jira/Confluence (or Trello/Linear/Azure DevOps/GitHub Issues) source of truth — BEFORE any test code, then a self-contained HTML/CSV coverage report. This is the requirements-first counterpart to the Test Architect: it trusts the spec and…
g-review
Run the review gate on the current branch diff. Runs the test suite, captures the diff, and dispatches code-lead, which verifies done conditions and reviews the diff itself. Issues MERGE READY or HOLD.