Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/michaelcereda/stampo/configuration-buildernpx skills add MichaelCereda/stampo --skill configuration-buildergit clone --depth 1 https://github.com/MichaelCereda/stampoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/michaelcereda/stampo/configuration-builder)<a href="https://agentmods.dev/skills/michaelcereda/stampo/configuration-builder"><img src="https://agentmods.dev/badge/skills/michaelcereda/stampo/configuration-builder.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00032 | $0.01895 |
| Opus 5 | $0.00016 | $0.00948 |
| Sonnet 5 | $0.00006 | $0.00379 |
| Haiku 4.5 | $0.00003 | $0.00189 |
Grade C, and why
configuration-builder scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
curl -fsSL https://raw.githubusercontent.com/MichaelCereda/stampo/master/install.sh | sh Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -fsSL https://raw.githubusercontent.com/MichaelCereda/stampo/master/install.sh | sh How it starts
The opening of the file, as written. The whole thing — 266 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Stampo Builder
Create CLI tools powered by stampo. Two modes:
- Create a CLI from scratch - user describes commands, you generate stampo YAML configs
- Convert MCP tools to CLI - read MCP server definitions, generate equivalent stampo configs
About stampo
stampo is a CLI generator that turns YAML configs into complete command-line tools. Single static binary, zero runtime dependencies.
- Repository: https://github.com/MichaelCereda/stampo
- Documentation: https://github.com/MichaelCereda/stampo/blob/master/docs/configuration-reference.md
Prerequisites
Verify stampo is installed before generating configs:
stampo --version
If not installed, ask the user if they'd like you to install it. If they agree, detect the platform and use the appropriate method:
- macOS/Linux (recommended):
curl -fsSL https://raw.githubusercontent.com/MichaelCereda/stampo/master/install.sh | sh - Homebrew:
brew install michaelcereda/stampo/stampo - From source (requires Rust):
cargo install stampo
Do NOT install without the user's explicit consent.
Mode Detection
Ask the user:
What would you like to build?
- Create a CLI from scratch - describe the commands you need
- Convert MCP tools to CLI - turn MCP server tools into shell commands
If the user's message already makes their intent clear, skip the question.
Mode 1: Create CLI from Scratch
Flow
- Ask the user to describe their CLI: what it does, what commands it needs
- For each command, understand: description, flags (with types/descriptions), and the shell command to run
- If hierarchical commands, use
subcommandsnesting - Generate valid stampo YAML config (version 2.0)
- Show config for review
- Ask whether to install it
YAML Generation Rules
version: "2.0"
name: "<name>"
description: "<description>"
commands:
<command-name>:
description: "<what it does>"
flags:
- name: "<flag-name>"
short: "<single-char>" # optional
description: "<flag help text>"
cmd:
run:
- "<shell command using ${{flag_name}} and ${{env.VAR}}>"
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 266 lines · 32 tokens per session scan C 1e4d0828ac10
configuration-builder is a skill published in the GitHub repository MichaelCereda/stampo (5 stars, last pushed 9d ago), licensed MIT. It adds 32 tokens to every session and 1,895 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
printing-press-polish
Polish a generated CLI to pass verification and become publish-ready. Runs diagnostics (dogfood, verify, scorecard, go vet, gosec), automatically fixes all issues (verify failures, static-analysis findings, dead code, descriptions, README, MCP tool quality), reports the before/after delta, and offers to publish. Use…
printing-press-amend
Amend a published CLI from one of two input sources: (1) dogfood mode mines the active Claude Code session transcript for friction (missing flags, hand- rolled API payloads, silent-null returns); (2) direct-input mode accepts user-supplied asks (rename a command, add commands or feeds, fix a named bug, optionally…
pp-printing-press-oauth2
Printing Press CLI for Printing Press Oauth2. Purpose-built fixture for the OAuth2 device-code auth shape.
pp-printing-press-rich
Printing Press CLI for Printing Press Rich. Purpose-built fixture for rich auth env-var model coverage.
pp-printing-press-golden
Printing Press CLI for Printing Press Golden. Purpose-built fixture for golden generation coverage.
pp-learn-loop-example
Printing Press CLI for Learn Loop Example. Golden fixture exercising the spec-declared self-learning loop.