sync

A command that coordinates synchronization between an operator’s fork of a coding harness and its canonical upstream repository. It supports publishing local changes, catching up with a selected upstream feature, and checking differences without changing anything.

In plain words
What is it for?
Use it to publish fork changes upstream, apply a specific upstream feature to the fork, or report synchronization drift in read-only mode.
Why use it?
It prevents contributors from using the wrong direction or merge method when keeping the two repositories aligned. It also preserves documented differences between the fork and upstream.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/mifunedev/openharness/sync
Any agent
npx skills add mifunedev/openharness --skill sync
Clone the repo
git clone --depth 1 https://github.com/mifunedev/openharness

Made for: Claude Code, Codex.

Per session 231 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,762 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00231 $0.01762
Opus 5 $0.00115 $0.00881
Sonnet 5 $0.00046 $0.00352
Haiku 4.5 $0.00023 $0.00176

Measured 2d ago against content hash 724618bdde45, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

sync scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.oh/skills/sync/SKILL.md · 128 lines

How it starts

The opening of the file, as written. The whole thing — 128 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/sync — bidirectional origin↔upstream sync dispatcher

/sync <subcommand> routes origin↔upstream sync operations. The first whitespace-delimited token of $ARGUMENTS selects the subcommand; the remainder is that subcommand's own argument string. Each subcommand's full procedure lives in a reference doc under references/ — read that doc and follow it as the authoritative instructions.

The canonical topology (origin=operator fork, upstream=mifunedev canonical) and the intentional divergences that every sync must preserve live in references/topology.md. Read it before executing any subcommand.

Subcommands

Subcommand Direction Purpose Procedure
publish origin→upstream Branch off upstream/development, merge-no-commit origin/development, sanitize private state, reconcile structure, eval-gate, draft PR to upstream references/publish.md
catchup upstream→origin Cherry-pick the squash commit of a specific upstream feature onto origin/development; never git merge upstream/development references/catchup.md
status read-only Invoke /audit drift and interpret its section (A) framework-drift output to report which direction is needed inline — see below

Dispatch

ARGUMENTS="${ARGUMENTS:-}"
SUB="${ARGUMENTS%% *}"          # first token
REST="${ARGUMENTS#"$SUB"}"      # everything after it
REST="${REST# }"                # trim one leading space

Route on $SUB:

$SUB Action
publish Read references/publish.md; execute it with $REST as its argument string.
catchup Read references/catchup.md; execute it with $REST as its argument string.
status Run the status procedure below.
anything else (incl. empty) Print the usage line from argument-hint and stop. Do not guess.

Status procedure (inline)

The status subcommand is a thin wrapper around /audit drift — it does NOT reimplement framework drift detection.

  1. Invoke /audit drift and capture its full output.
  2. Parse the section (A) summary line (DRIFT-CHECK (A): or (A) Framework drift: OK):
    • Origin N behind upstream AND N ahead = 0: report "catchup is available (N commits to port from upstream/development)".
    • Origin N ahead of upstream AND N behind = 0: report "publish is available (N commits to push to upstream/development)".
    • Both non-zero: report "bidirectional work needed — run /sync catchup to port upstream features first, then /sync publish to push origin's changes forward."
    • Both zero: report "in sync — no action needed."
  3. Print the raw /audit drift section (A) output for operator context.

Read the full file on GitHub · 128 lines

Files

What ships with it

3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 128 lines · 231 tokens per session scan A 724618bdde45

Subscribe to this mod's changes

sync is a skill published in the GitHub repository mifunedev/openharness (36 stars, last pushed 2d ago), licensed Apache-2.0. It adds 231 tokens to every session and 1,762 once invoked, about $0.0012 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

data-visualization

Use for creating publication-quality charts and multi-panel analysis summaries. Triggers when tasks involve visualizing data, plotting results, creating charts, or producing visual reports from analysis output.

langchain-ai/deepagents · 40 tokens

cuml-machine-learning

Use for GPU-accelerated machine learning on tabular data using NVIDIA cuML. Triggers when tasks involve classification, regression, clustering, dimensionality reduction, or model training on datasets.

langchain-ai/deepagents · 43 tokens

blog-post

Writes and structures long-form blog posts, creates tutorial outlines, and optimizes content for SEO with cover image generation. Use when the user asks to write a blog post, article, how-to guide, tutorial, technical writeup, thought leadership piece, or long-form content.

langchain-ai/deepagents · 58 tokens

social-media

Drafts engaging social media posts, writes hooks, suggests hashtags, creates thread structures, and generates companion images. Use when the user asks to write a LinkedIn post, tweet, Twitter/X thread, social media caption, social post, or repurpose content for social platforms.

langchain-ai/deepagents · 58 tokens

remember

Review the current conversation and capture valuable knowledge — best practices, coding conventions, architecture decisions, workflows, and user feedback — into persistent memory (AGENTS.md) or reusable skills. Use when the user says: (1) remember this, (2) save what we learned, (3) update memory, (4) capture…

langchain-ai/deepagents · 71 tokens

textual-screenshot

Capture a Textual terminal UI as an SVG using its headless test harness. Use when asked to make, attach, or preview a screenshot of deepagents-code/dcode or another Textual app, visually verify a TUI state, or render a modal, screen, or widget without a desktop or browser.

langchain-ai/deepagents · 67 tokens