skill-lifeguard

skill-lifeguard is a skill for Claude Code, Codex from majiayu000/spellbook. It costs 92 tokens per session (1,067 once invoked), scanned A, original, MIT.

A maintenance guide for making an agent skill more reliable over time, with clear forbidden behaviors, checks, and signs of drift.

In plain words
What is it for?
It is used to audit or patch skills, add pass-or-fail checkpoints, define completion checks, and create small replay tests.
Why use it?
It reduces brittle workflows, repeated failures, and false claims that a skill completed its job.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Needs its repository: it runs a file that does not travel with it, so clone the repository first. The line is python3 ./scripts/validate_skills.py --check.

Good fit It is used to audit or patch skills, add pass-or-fail checkpoints, define completion checks, and create small replay tests.

Compare 6 skills from other repositories ↓
Install

Getting it into your agent

It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.

Clone the repo
git clone --depth 1 https://github.com/majiayu000/spellbook
agentmods
npx agentmods add skills/majiayu000/spellbook/skill-lifeguard

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for skill-lifeguard

README.md
[![agentmods](https://agentmods.dev/badge/skills/majiayu000/spellbook/skill-lifeguard/github.svg)](https://agentmods.dev/skills/majiayu000/spellbook/skill-lifeguard)
Your own site
<a href="https://agentmods.dev/skills/majiayu000/spellbook/skill-lifeguard"><img src="https://agentmods.dev/badge/skills/majiayu000/spellbook/skill-lifeguard/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for skill-lifeguard

Your own site · 80×15
<a href="https://agentmods.dev/skills/majiayu000/spellbook/skill-lifeguard"><img src="https://agentmods.dev/badge/skills/majiayu000/spellbook/skill-lifeguard.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 92 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,067 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00092 $0.01067
Opus 5 $0.00046 $0.00534
Sonnet 5 $0.00018 $0.00213
Haiku 4.5 $0.00009 $0.00107

Measured 8d ago against content hash 30fbf3f43577, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

skill-lifeguard scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/skill-lifeguard/SKILL.md · 128 lines

How it starts

The opening of the file, as written. The whole thing — 128 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Skill Lifeguard

Use this skill to make an existing or new skill self-maintaining enough for real agent work. It complements skill-audit and skill-creator: use this skill for the reliability contract, then use those skills for library fit and authoring.

Read references/examples.md when you need example contract wording. Use assets/reliable-contract-template.md when drafting a reusable section.

Reliable Skill Contract

Every high-value workflow skill should either include these five elements or record why an element is intentionally deferred:

Element Required Evidence
Explicit negative examples Named forbidden behaviors and concrete alternatives.
Verification checkpoints Pass/fail checks after important phases, not only at the end.
Machine-checkable done conditions Commands, assertions, artifacts, or state queries from the current session.
Replay or smoke hooks A small way to rerun or sample the workflow, plus a log-to-patch loop.
Drift signal detection Observable signs that the skill is stale, undertriggering, overtriggering, or producing false success.

Workflow

  1. Search before creating or moving skill files.
  2. Read the target skill and nearby docs that define its expected workflow.
  3. Classify the skill maturity:
    • manual: workflow still needs human validation.
    • skill: manually validated and packaged as reusable instructions.
    • automation: repeatedly reliable and safe enough for scheduled or hook-driven use.
  4. Score the five contract elements as present, partial, missing, or deferred.
  5. Patch the smallest durable home: SKILL.md for routing and boundaries, references/ for long examples, scripts/ for deterministic checks, assets/ or templates/ for reusable report shapes.
  6. Run repository validation and any skill-specific smoke check.

Operating Contract

  • Direct actions: audit skill files, draft contract gaps, patch local skill instructions, and run local validation.
  • Escalate before: publishing skills, installing into user runtime directories, deleting user files, changing secrets, or promoting manual workflows into scheduled automation.
  • Evidence-backed pushback: refuse reliability claims that lack fresh verification, replay hooks, or drift signals.
  • Feedback loop: turn repeated corrections, false-success signals, or failed smoke runs into a skill patch and rerun validation.

Read the full file on GitHub · 128 lines

Files

What ships with it

2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 128 lines · 92 tokens per session scan A 30fbf3f43577

Subscribe to this mod's changes

skill-lifeguard is a skill published in the GitHub repository majiayu000/spellbook (278 stars, last pushed yesterday), licensed MIT. It adds 92 tokens to every session and 1,067 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.