Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/markus-global/markus/agent-buildingnpx skills add markus-global/markus --skill agent-buildinggit clone --depth 1 https://github.com/markus-global/markusWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00033 | $0.04088 |
| Opus 5 | $0.00016 | $0.02044 |
| Sonnet 5 | $0.00007 | $0.00818 |
| Haiku 4.5 | $0.00003 | $0.00409 |
Grade C, and why
agent-building scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
- "Never run `rm -rf` or other destructive commands" How it starts
The opening of the file, as written. The whole thing — 279 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agent Building
This skill teaches you how to create Markus agent packages — self-contained directory-based artifacts that define an AI agent's identity, capabilities, constraints, and visual assets.
Artifact Directory
CRITICAL: Agent artifacts MUST be saved under this exact path — the Builder page, install system, and deliverable detection all depend on it:
~/.markus/builder-artifacts/agents/{agent-name}/
├── agent.json # Manifest (auto-created from your JSON output)
├── README.md # Public-facing overview for Hub/Builder (REQUIRED)
├── ROLE.md # Identity and system prompt (REQUIRED)
├── HEARTBEAT.md # Periodic self-check checklist (RECOMMENDED)
├── POLICIES.md # Constraints & guardrails (optional)
├── CONTEXT.md # Domain context & references (optional)
└── images/ # Image assets (avatar, screenshots)
└── avatar.jpg # Agent avatar/thumbnail image
Do NOT write artifacts to ~/.markus/shared/, your working directory, or any other location. Only ~/.markus/builder-artifacts/agents/ is recognized by the system.
When the user installs the artifact, files are deployed to ~/.markus/agents/{agentId}/role/. The ROLE.md becomes the agent's system prompt — it IS the agent's identity, not an override of a template.
Package Slug (name) — REQUIRED
The manifest name is the package slug: directory name, Hub URL segment (/@user/{slug}), and share/publish id.
Rules (hard — invalid manifests are rejected on write / save / share):
- English kebab-case only: lowercase letters
a-z, digits0-9, hyphens- - 2–64 characters; must start with a letter
- Pattern examples:
code-reviewer,paper-mentor,seo-auditor - NOT allowed: Chinese (
智库研究团队), spaces, underscores, UPPERCASE, emoji, or empty - Put the human-readable title (any language) in
displayName, never inname
| User language | name (slug) |
displayName |
|---|---|---|
| Chinese "论文导师" | paper-mentor |
论文导师 |
| English "Code Reviewer" | code-reviewer |
Code Reviewer |
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 279 lines · 33 tokens per session scan C 1e82a3b0dc7b
agent-building is a skill published in the GitHub repository markus-global/markus (157 stars, last pushed 6d ago), licensed Apache-2.0. It adds 33 tokens to every session and 4,088 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
dashclaw-ship
The single command that gets a DashClaw change ON MAIN AND LIVE — it resolves everything blocking production, never defers, and never hands back a checklist. Lands feature branches on main (rebase, gate, merge, push so Vercel deploys), bumps the unified platform+SDK version, and realigns every description of the…
dashclaw-governance
Governance behavior for AI agents governed by DashClaw. Teaches the governance protocol: when to call guard (risk thresholds), how to interpret decisions (allow/warn/block/requireapproval), when to record actions, how to wait for approvals, and session lifecycle management. Loads org-specific policies and capabilities…
instrument-agent
Integrate DashClaw SDK into any agent using the 4-step governance loop.
troubleshoot
Debug DashClaw errors, signal issues, and misconfigurations.
compliance-drift-evals
Set up compliance exports, drift detection, evaluations, scoring, and learning analytics.
build-dashclaw
Contribute to the DashClaw codebase — architecture, scaffolding, tests, CI.