Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/maxence2997/mx-harness/mx-flownpx skills add maxence2997/mx-harness --skill mx-flowgit clone --depth 1 https://github.com/maxence2997/mx-harnessWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00078 | $0.08566 |
| Opus 5 | $0.00039 | $0.04283 |
| Sonnet 5 | $0.00016 | $0.01713 |
| Haiku 4.5 | $0.00008 | $0.00857 |
Grade A, and why
mx-flow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 924 lines — stays where its author put it; the contents beside it link to each section on GitHub.
mx-flow
Trigger
/mx-flow <topic> ← full pipeline: idea to PR
/mx-flow finish <name> ← post-merge cleanup (read references/finish.md and follow it)
Non-negotiables
Violating any of these is a workflow failure. They bind every phase and every sub-agent this skill dispatches.
- Worktree before any code edit — before making any code change,
verify the working directory is a git worktree
(
git rev-parse --git-dircontainsworktrees/). If not, STOP and run Phase 4 first. - Iron Law — no production code without a failing test first. Code written before its test exists must be deleted and reimplemented after the test is in place. No exceptions.
- Never weaken a gate to get green — no
--no-verify, no lint suppressions to silence a finding, no deleting/skipping a failing test, no rewriting a RED test to match broken behavior, no relaxed assertions, no widened timeouts. A gate fighting you is a design signal: apply the wrong-direction rubric (doctrine below) — change approach or ask. - Review before verify — do not enter Phase 6 unless mx-team-review
and mx-review-triage have run on the current branch diff at least once
in this session. If unsure, check for a review report in
.mx/<name>/tmp/. - Retry budget — the same task failing verification twice (regardless of approach) → stop retrying. In a harness with sub-agents, escalate to the strongest tier with the full failure trail (what was tried, exact diffs, exact errors); otherwise present that trail to the user with concrete options. Never a third identical attempt. (Small-tier/haiku workers get only ONE attempt before escalating — counting rule: mx-doctrine model-dispatch §6.)
Gates
mx-flow pauses at one human gate (spec approval). All other gates auto-proceed — reports are still shown for visibility. Gates are review opportunities, not "y/n continue" prompts.
| Gate | Behaviour |
|---|---|
| GATE 1 — Spec | Human. Show the draft spec; discuss and adjust until the user explicitly confirms. Do not proceed without approval. With the approval, also collect the Phase 5a execution mode (inline / delegated) — one extra question, same gate. |
| GATE 2 — Task list | Auto. Show the task list for visibility, then proceed immediately. |
| GATE 3 — Triage | Auto. Show the triage report, auto-approve all "fix" items, execute immediately. |
| GATE 4 — PR | Auto. Draft and publish the PR autonomously; show the draft for visibility. Pause only if the agent cannot determine how to proceed (no remote, ambiguous platform, missing credentials). |
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 924 lines · 78 tokens per session scan A 461699313944
mx-flow is a skill published in the GitHub repository maxence2997/mx-harness (5 stars, last pushed 6d ago), licensed MIT. It adds 78 tokens to every session and 8,566 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
manuscript-typography
Audit academic manuscripts for typographic design conventions: booktabs table style, caption placement, dashes/quotes, units and numbers, cross-reference style, page layout, typographic hierarchy, professional polish. Triggers on: "check typography", "fix formatting", "polish my paper", "check my LaTeX", "typographic…
architecture-reviewer
Architecture reviews across 7 dimensions (structural, scalability, enterprise readiness, performance, security, ops, data) with scored reports. Triggers on: "review architecture", "critique design", "audit system", "assess scalability", "enterprise readiness", "technical due diligence". NOT for diagrams, use…
concept-to-video
Turn concepts into animated explainer videos using Manim (Python) with MP4/GIF output, audio overlay, multi-scene composition. Triggers on: "create a video", "animate this", "make an explainer", "manim animation", "motion graphic". NOT for React video, use remotion-video.
linkedin-post-style
Writes LinkedIn posts in a direct, analytical, dry-humored technical voice with visual companion guidance. Triggers on: "write this in my style", "draft a post", "rewrite this for LinkedIn", "post about this", "how should I phrase this".
manuscript-provenance
Computational provenance audit verifying every number, table, and figure in a manuscript derives from code, not manual entry. Triggers on: "check provenance", "verify reproducibility", "audit my pipeline", "are my numbers from code", "provenance audit". Companion to manuscript-review (prose audit).
manuscript-review
Pre-publication manuscript audit producing a section-level refactoring report with citation hygiene and submission-readiness checks. Triggers on: "review my paper", "check before submission", "is this ready to submit", "pre-pub checklist", "refactor my paper", "check my references", "does the abstract work".