Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add mirkobozzetto/arsenal --skill proposegit clone --depth 1 https://github.com/mirkobozzetto/arsenalWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mirkobozzetto/arsenal/propose)<a href="https://agentmods.dev/skills/mirkobozzetto/arsenal/propose"><img src="https://agentmods.dev/badge/skills/mirkobozzetto/arsenal/propose/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/mirkobozzetto/arsenal/propose"><img src="https://agentmods.dev/badge/skills/mirkobozzetto/arsenal/propose.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00025 | $0.00458 |
| Opus 5 | $0.00013 | $0.00229 |
| Sonnet 5 | $0.00005 | $0.00092 |
| Haiku 4.5 | $0.00003 | $0.00046 |
Grade A, and why
propose scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 45 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Propose
Gather only the context needed to answer the design question. Prefer the smallest sufficient format: short for a bounded reversible choice, standard for one system, full for a genuine cross-system design. No format interview when the request already determines the appropriate size.
Use references/proposal-template.md for stable section numbers and artifact shape. Write problem, real alternatives (including status quo when relevant), tradeoffs, design, risks, recommendation and runnable implementation tasks. Do not manufacture alternatives, diagrams, metrics or verification layers to fill a template. Ask only about a blocking decision not recoverable from code or the request. Research only unresolved external questions.
Review the draft yourself. An independent review is optional and requires explicit user consent, never merely omission of --no-review. Retain supported findings only. Leave status Draft or Review until the user explicitly accepts the proposal; writing it is not implementation approval.
Keep the existing docs/proposals/-/PROPOSAL.md layout and links to a source brief. Do not supersede that brief until the design is accepted. Render via scripts/render.py only on --html or request. Do not launch ship, open a browser, create an index, or start another agent just to finish.
Arsenal handoff
When called by Arsenal, return the proposal, status and unresolved decisions to Arsenal. Do not launch ship yourself. Explicit user acceptance remains required before Arsenal can consume the proposal for implementation, even when the original request was to build the feature.
Execution policy
Work solo. Ask before any subagent or reviewer, even in auto mode. Explain the independent scope and expected benefit first. No hidden advisor, nested delegation, model retuning, repeated successful checks, or progress spam. Use existing context before asking questions. Stop when the requested result is delivered. User stops and scope changes override pending steps.
What ships with it
13 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/interview-questions.md 4.0 KB
- references/proposal-template.md 5.8 KB
- scripts/render.py 8.6 KB runs code
- steps/step-00-init.md 410 B
- steps/step-01-context.md 421 B
- steps/step-02-problem.md 407 B
- steps/step-03-alternatives.md 398 B
- steps/step-04-design.md 421 B
- steps/step-05-risks.md 403 B
- steps/step-06-recommendation.md 434 B
- steps/step-07-impl-plan.md 429 B
- steps/step-08-review.md 461 B
- steps/step-09-finalize.md 501 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago Changed · +7 lines bb6208152638
- 6d ago Changed · -74 lines · +25 tokens per session 5202c9b66308
- 12d ago First seen · 112 lines · 0 tokens per session scan A e00c44efbe55
propose is a skill published in the GitHub repository mirkobozzetto/arsenal (15 stars, last pushed 4d ago), licensed MIT. It adds 25 tokens to every session and 458 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
extract-source-sample
Given the path to a finished content-goose ad-run folder, extract everything that defines that ad — recipe shot list, VO script, characters, voices, world, atom-skills, master mp4 — and emit a source-sample.json in the exact shape the upload-ad-sample skill writes to the Goose Ads library. Also links every character…
google-search-ads-builder
End-to-end Google Search Ads campaign builder. Performs deep keyword research (competitor SEO, review language mining, Reddit/HN community terminology, site audit), builds keyword architecture with funnel mapping and intent classification, creates ad group structure, generates headline/description variants, builds…
create-workflow-diagram
Create FigJam/Miro-style workflow diagrams as high-quality PNG images from plain-text workflow descriptions. Renders beautiful HTML diagrams with connected nodes, arrows, and labels, then screenshots them for sharing.
comprehensive-enrichment
Enrich any person or company from any identifier — email, name, LinkedIn URL, domain, company name, Twitter/X handle. Use when asked to enrich, look up, or research a lead, contact, person, or company.
inbound-lead-enrichment
Fills in missing data for inbound leads — researches the company, identifies the person's role and seniority, finds other stakeholders at the company, checks for existing CRM relationships, and updates the lead record. Produces enriched lead data ready for qualification or outreach. Tool-agnostic.
create-chatgpt-mockup
Render pixel-accurate ChatGPT mobile (iOS) screen mockups in light mode from a thread JSON. Supports user text bubbles, user image attachments, assistant markdown prose, citation chips, the OpenAI spiral logo, the Apps-SDK GPT chip in the composer, and three header styles (model-tag, plain title, "Get Plus"). Fixed…