process-issues

process-issues is a skill for Cursor from markmhendrickson/neotoma. It costs 38 tokens per session (1,345 once invoked), scanned A, a copy of process_issues, MIT.

A workflow for triaging and processing open Neotoma software issues from discovery through a plan and possible implementation.

In plain words
What is it for?
It lists issues, filters out queue artifacts, creates plans, requests missing context, opens pull requests or worktrees when appropriate, and handles test-only or security issues.
Why use it?
It brings consistency to an issue queue and helps separate issues that need more information, reproduction work, code changes, or security handling.

Skill for Cursor

Written for Cursor: installed under .cursor/. Also seen: mentions subagents.

Good fit It lists issues, filters out queue artifacts, creates plans, requests missing context, opens pull requests or worktrees when appropriate, and handles test-only or security issues.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/markmhendrickson/neotoma/process-issues
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add markmhendrickson/neotoma --skill process-issues
Clone the repo
git clone --depth 1 https://github.com/markmhendrickson/neotoma

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for process-issues

README.md
[![agentmods](https://agentmods.dev/badge/skills/markmhendrickson/neotoma/process-issues.svg)](https://agentmods.dev/skills/markmhendrickson/neotoma/process-issues)
Your own site
<a href="https://agentmods.dev/skills/markmhendrickson/neotoma/process-issues"><img src="https://agentmods.dev/badge/skills/markmhendrickson/neotoma/process-issues.svg" alt="Measured on agentmods" height="20"></a>
Per session 38 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,345 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 97% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00038 $0.01345
Opus 5 $0.00019 $0.00673
Sonnet 5 $0.00008 $0.00269
Haiku 4.5 $0.00004 $0.00135

Measured 3d ago against content hash 83ea8e9d6da3, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

process-issues scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

97% identical to process_issues — 14 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.cursor/skills/process-issues/SKILL.md · 92 lines

How it starts

The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Process Issues

Use this skill to work the Neotoma issue queue end-to-end.

For each open issue, the skill should create or update one or more plan entities, then do one of three things:

  • Open a PR for a public-release reproduction.
  • Create a local worktree for a local commit or branch reproduction.
  • Post an add_issue_message asking for missing context when the reproduction environment is unclear.
  • Close any clearly test-only issues that the queue surfaces.
  • Open a related GitHub security advisory when the issue is a security issue.

Workflow

  1. Discover open issues with neotoma issues list --state open (or the current CLI equivalent when the flag shape differs).
  2. Honor reporting mode before any execution:
    • off -> generate and store plans only
    • consent -> ask before executing a per-issue plan
    • proactive -> execute safe plans autonomously
  3. Filter queue artifacts before reproduction work:
    • Exclude open PRs or PR URLs accidentally surfaced by the queue command; do not route them through the issue workflow.
    • Identify clearly test-only issues using queue context such as labels like test, test-flow, test-cleanup, or live-issues-tooling, and titles/descriptions that indicate sample/live/public test issues rather than product bugs.
    • For each test-only issue, create or update a cleanup plan entity, then honor reporting mode:
      • off -> store the cleanup plan only
      • consent -> ask before closing
      • proactive -> close the issue immediately with a brief cleanup comment
    • Report closed test issues in the final aggregate output.
  4. Spawn parallel subagents with a default concurrency cap of 4, one non-test issue per subagent.
  5. Per issue:
    • Load the issue snapshot, conversation thread, and any reporter environment fields.
    • Classify the reproduction environment as public_release, local_commit, local_branch, or unknown.
    • Classify whether the issue is a security issue based on labels, title/body, affected surface, or prior issue/advisory context.
    • If the environment is missing, conflicting, or still unreproducible, call add_issue_message with a structured request for the missing detail and mark the plan awaiting_input.
    • Otherwise, synthesize and store a plan entity linked to the source issue and relevant conversation_message rows.
    • If the issue is a security issue, create a related GitHub security advisory before publishing other public artifacts:
      • Reuse an existing related advisory when one already exists.
      • Otherwise open a new draft advisory with a minimal, redacted summary, affected versions/surfaces, reproduction notes, and mitigation status.
      • Record the advisory URL or identifier in the plan and include it in the final aggregate report.
    • If the plan touches schema, security, foundation docs, or an ambiguous architectural boundary, stop and ask instead of executing.
    • If execution is safe and allowed by reporting mode:
      • public_release -> branch from main, implement and test the change, then open a PR. Public issues may include Fixes #<github_number>; private issues must use neutral wording with no private identifiers.
      • local_commit or local_branch -> create a detached git worktree, initialize it, implement and test the change there, then report the worktree_path.
  6. Aggregate subagent outcomes and report created plans, closed test issues, advisories, worktrees, PRs, and outstanding information requests.
  7. Summarize comprehensively for the user after each /process-issues run:
    • Include the set of issues reviewed in the run.
    • For each issue, state the current status, classification, and the concrete action taken so far.
    • For security issues, state whether a related advisory was created, reused, or is still blocked.
    • Call out any blocker, missing context, or user decision needed to make more forward progress.
    • Separate "completed / no further action needed now" issues from "still active / blocked" issues.
    • End with a concise "What I need from you" section when any issue requires user input, branch guidance, reproduction detail, environment confirmation, or prioritization.

Read the full file on GitHub · 92 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 92 lines · 38 tokens per session scan A 83ea8e9d6da3

Subscribe to this mod's changes

process-issues is a skill published in the GitHub repository markmhendrickson/neotoma (31 stars, last pushed 4d ago), licensed MIT. It adds 38 tokens to every session and 1,345 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. It is 97% identical to process_issues, differing in 14 lines, and is treated as a copy.

Related

Other skills, from other repositories