Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/megaprompting/torque-loop/preflightnpx skills add Megaprompting/torque-loop --skill preflightgit clone --depth 1 https://github.com/Megaprompting/torque-loopWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00093 | $0.01220 |
| Opus 5 | $0.00046 | $0.00610 |
| Sonnet 5 | $0.00019 | $0.00244 |
| Haiku 4.5 | $0.00009 | $0.00122 |
Grade A, and why
preflight scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 83 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/preflight — embarrass the branch before the reviewer does
v0.7 shipped, got reviewed, and needed a same-day PATCH-THEN-KEEP hardening pass
(fog write bypassed on --json, probe invariants convention-only, gated reasons
unenforced). Every one was findable before the PR. This skill is that finding pass.
The mechanizable checks live in a script, not in prose — a discipline a model has to
remember to run is weak. scripts/preflight.js owns the deterministic verdicts; this
skill runs it, then does the judgment the script deliberately leaves open.
Step 1 — Run the mechanical pass
npm run preflight # or: node scripts/preflight.js [base-ref] (default base: main)
It prints all 12 checks in a fixed shape and exits non-zero if any MECHANICAL check fails. Trust its verdict on these five — they need no judgment:
- 1 green world —
npm test+ratchet doctorboth exit 0. - 4 version alignment — five version fields + README examples all match.
- 7 dependency gate — no new
dependencies/devDependencies(or a Danny quote in[Unreleased]). - 9 leak scan — no private paths (
reference/PROBLEM-STATEMENT-*,*.private.md,.lucid/,.ratchet/,.sandbox-*) and no exact private-line quotes in the diff. - 10 trace tags — changed durable docs (
CLAUDE.md,reference/*, handoffs) carry aTraced by:tag; commits carry aCo-authored-byfooter.templates/is exempt.
A MECHANICAL FAIL is real; fix it before anything else. The script's SMALLEST PATCHES
block names each fix.
Step 2 — Rule on the checks the script only gathers evidence for
The script prints these as HUMAN: lines with the candidates it found. You make the call —
it cannot. Read the gathered evidence, then decide PASS/FAIL for each:
- 2 testless change (weak signal — distrust a clean line). The script's token-grep is
noisy: common identifiers match half the suite, so "has test hits" is near-meaningless.
For every
src/|bin/hunk, name the specific test that fails without it. No name → FAIL. - 3 weakened falsifier. The script flags removed asserts / newly-loose lines in
test/. Decide whether any assertion was genuinely loosened without a commit-body reason. If so → FAIL. - 5 prose enforcement. The script lists new
must/never/requireslines in SKILL.md/README. For each, point at the CLI line that enforces it + the test proving the refusal throws, OR confirm the CHANGELOG labels it prompt-level. Unlabeled invariant → FAIL. - 6 diff minimality. The script catches renames + whitespace-only files (the cheap
cases) and is blind to elegance-churn (the expensive one). Map every remaining hunk to the
locked target yourself. Any hunk that doesn't map → FAIL:
revert this hunk. - 8 parked-decision creep. The script lists parked loop ids and any the diff mentions. Decide whether a hunk actually implements a parked loop (a mention alone is fine). If so → FAIL.
- 11 scope + emptiness (weak signal). For any new score/read the script surfaced,
confirm it exposes a
scope:field and that new rendered sections state emptiness. - 12 changelog. The script shows whether
[Unreleased]was touched and whether a CLI-enforced/prompt-level label is present. Decide if behavior changed and the entry is adequate.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 83 lines · 93 tokens per session scan A fc5510eaf61e
preflight is a skill published in the GitHub repository Megaprompting/torque-loop (5 stars, last pushed 1mo ago), licensed MIT. It adds 93 tokens to every session and 1,220 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
new-plugin
Factory line for adding a new HAR verification plugin (like playwright or rocketsim) for any framework — research the framework docs, build the template under src/templates/plugins/, register it everywhere, validate on a real repository, and open a PR. Use when asked to add/create a plugin, plugin template, or…
factory-line
Factory line for executing one station of a declared multi-station program — read the installed line bundle (har line status), plan parallel work into isolated HAR slots, run the cumulative gate with har line gate, and hand off for human review. Use when asked to "run a factory line", "run the next station", "execute…
v1-milestone
Factory line for executing one milestone of the HAR v1.0.0 refactor (epic os-factory/har#225) — plan the wave of parallel subagents, implement each issue in its own HAR slot, ship stacked PRs, run the fixture-e2e milestone gate, and hand off for review. Use when asked to "run the next v1 milestone", "work on v1.0.0"…
ctx
Codebase intelligence and evidence-driven governance with the indexed ctx CLI. Use when exploring an unfamiliar repository, locating symbols or callers, checking for existing implementations, estimating change impact, enforcing architecture rules, scoring a branch, finding hotspots or duplication, or analyzing…
ctx
Codebase intelligence and evidence-driven governance with the indexed ctx CLI. Use when exploring an unfamiliar repository, locating symbols or callers, checking for existing implementations, estimating change impact, enforcing architecture rules, scoring a branch, finding hotspots or duplication, or analyzing…
golden-rss
Use when testing the rss golden build.