Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/melodic-software/claude-code-plugins/recheck-against-upstream-deepnpx skills add melodic-software/claude-code-plugins --skill recheck-against-upstream-deepgit clone --depth 1 https://github.com/melodic-software/claude-code-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/melodic-software/claude-code-plugins/recheck-against-upstream-deep)<a href="https://agentmods.dev/skills/melodic-software/claude-code-plugins/recheck-against-upstream-deep"><img src="https://agentmods.dev/badge/skills/melodic-software/claude-code-plugins/recheck-against-upstream-deep.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00123 | $0.01320 |
| Opus 5 | $0.00062 | $0.00660 |
| Sonnet 5 | $0.00025 | $0.00264 |
| Haiku 4.5 | $0.00012 | $0.00132 |
Grade A, and why
recheck-against-upstream-deep scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 99 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Recheck against upstream. Deep
The fan-out tier of the sibling /discipline:recheck-against-upstream. Same
upstream-conformance discipline; heavier execution. Where the base skill
rechecks the one surface in play inline, this one fans fresh-context
subagents out over a whole subsystem, framework, or repo, doc-by-doc, the
execution tier the base skill's context cannot cover from within itself.
The shared method. Re-anchor, audit, correct forward, report, and the tone
that firing this is not an accusation, lives in
${CLAUDE_PLUGIN_ROOT}/context/re-anchor-audit-correct.md.
The discipline this re-anchors, its portable baseline, and the three
divergence categories (gap / deliberate / undocumented) live in the sibling
recheck-against-upstream. Read
both; this file adds only the fan-out delta. There is no separate copy of
the discipline or the taxonomy here. Update the sibling and this tier
follows.
When this tier, not the inline recheck
Reserve the fan-out for when the upstream surface area is broad enough to justify the subagent cost: a whole framework's configuration, an entire integration's API usage, a subsystem that leans on many upstream contracts at once. For a single surface or a short session, the inline recheck in the sibling is the right tool; this tier is overkill.
The fan-out
Run this in place of the sibling's inline audit and correct-forward steps:
- Enumerate the surfaces. List every upstream-dependent surface in the subsystem/repo under review. Each config block, API call site, infra definition, and documented contract the work rests on. Do not spot-check one.
- Fan out, throttled, doc-by-doc. Dispatch fresh-context subagents (blind to the assumptions that produced each surface) to fetch the CURRENT official upstream docs for that surface and classify its divergence per the sibling's three categories. Throttle the dispatch in bounded waves rather than launching one agent per surface at once. A sustained wide fan-out trips server-side burst overload (529s) and loses agents mid-run. Cap concurrency to a modest wave (roughly a dozen or fewer); process the surfaces wave by wave.
- Retry the failed subset only. If an agent errors or times out, retry that surface once; on a second failure mark it unverifiable, an honest skip, never a false pass. Never blind-re-run the whole fan-out to recover a few stragglers.
- Checkpoint the partial ledger mid-run, if a durable slice exists. So a crash mid-fan-out does not lose completed waves, checkpoint the partial ledger to the session's durable topic-memory slice when one is available; where the session has no such durable store, proceed without it rather than asserting a persistence surface. This is the only persistence this tier performs. Nothing is mandatory beyond it.
- Merge and report an inline divergence ledger. One list keyed by surface: its category (gap / deliberate / undocumented) and the current upstream source that resolved it. Correct gaps toward upstream this turn; re-check that deliberate divergences still hold and flag any the docs have overtaken; surface undocumented ones for the human with both options.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 99 lines · 123 tokens per session scan A 243588dd1252
recheck-against-upstream-deep is a skill published in the GitHub repository melodic-software/claude-code-plugins (14 stars, last pushed yesterday), licensed MIT. It adds 123 tokens to every session and 1,320 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
parallel-orchestrator
Manage parallel Claude Code workstreams using git worktrees. Use when: splitting large tasks across multiple workers, coordinating parallel development, monitoring worker progress, integrating completed work, analyzing work item documents (code reviews, issue lists). Triggers: parallel, orchestrator, worktrees…
parallel-worker
Execute focused implementation tasks in a parallel workflow. Use when: working on assigned files in a worktree, making checkpoint commits, signaling dependencies or blockers, completing orchestrator-assigned tasks. Triggers: worker, checkpoint, worktree, assigned scope, commit prefix, parallel task.
build-priority-queue
For ordered processing: A search, Dijkstra, event simulation, task scheduling. Efficient min/max extraction with heap-based queue.
catch-expected-errors
For iteration with errors: catch exceptions during exploration, skip invalid cases, continue to next attempt.
compose-small-helpers
For complex behavior: build from tiny functions, chain transformations, make code read like a pipeline of operations.
count-combinations
For probability and counting: permutations, combinations, sample spaces, Monte Carlo simulation, brute-force enumeration, card/dice problems.