Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/modiqo/skillspec/local-csv-reportnpx skills add modiqo/skillspec --skill local-csv-reportgit clone --depth 1 https://github.com/modiqo/skillspecWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/modiqo/skillspec/local-csv-report)<a href="https://agentmods.dev/skills/modiqo/skillspec/local-csv-report"><img src="https://agentmods.dev/badge/skills/modiqo/skillspec/local-csv-report.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00063 | $0.02765 |
| Opus 5 | $0.00032 | $0.01383 |
| Sonnet 5 | $0.00013 | $0.00553 |
| Haiku 4.5 | $0.00006 | $0.00277 |
Grade A, and why
local-csv-report scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
81% identical to generic-skill-creator — 26 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 122 lines — stays where its author put it; the contents beside it link to each section on GitHub.
local csv report
Use durable executor to turn a local CSV into durable JSON and text reports with file provenance, dependency checks, privacy guardrails, and optional reuse.
This skill is a thin loader for the colocated skill.spec.yml. The spec is the source of truth for routes, rules, dependencies, imports, resources, recipes, tests, and trace requirements. Do not treat the spec as background prose; treat it as the execution contract for this task.
Runtime Contract
-
Load
./skill.spec.ymlfrom this skill folder before taking task actions. -
When the
skillspecCLI is available and the spec shape is unfamiliar, runskillspec sensemake ./skill.spec.yml --view indexto learn the section roles, counts, query handles, and navigation grammar without dumping the full YAML. -
Then create the ordered phase plan and current-route action checklist:
skillspec plan ./skill.spec.yml --input='<user task>' --trace-dir "${PWD}/.skillspec/traces" skillspec act ./skill.spec.yml --input='<user task>' --run <run_dir> --phase <phase-id> -
Strip skill invocation prefixes such as
/my-skill,$my-skill, or/durable-executor-specbefore passing--input. -
Preserve the emitted trace
run_dir. -
Read the full phase plan and action checklist before using tools. Treat them as the active execution SOP, not as advice. The
PHASE TOOL BOUNDARY - HARDsection is the permission boundary for the next action. -
For each execution phase, run
skillspec act ./skill.spec.yml --input='<user task>' --run <run_dir> --phase <phase-id>before acting, record phase progress in<run_dir>/execution.jsonl, then runskillspec progress show ./skill.spec.yml --run <run_dir>to see completed, current, blocked, and remaining phases. -
Pull active details with
skillspec query ./skill.spec.yml <handle> --view summaryand relationship edges withskillspec refs ./skill.spec.yml <handle> --view summary. Prefer precise handles such asrule:<id>,rule:<id>.forbid,command:<id>.requires, andstate:<id>.nextover reading the whole spec. -
Before every substrate/tool call, apply the phase tool boundary and checklist allow/deny questions. Any unlisted tool, data source, execution substrate, provider, adapter, CLI, browser mode, API, or skill requires explicit user permission before use. The selected route and matched rules override lower-level skill defaults and generic tool preferences.
-
When the CLI is available after a trace exists, run
skillspec trace align ./skill.spec.yml --decision-trace <run_dir>and, when structured action evidence exists, add--execution-trace <run_dir>/execution.jsonl. The command writes<run_dir>/alignment.json; report the alignment status, meaning, model layers, evidence gaps, user-facing proof rows, summary, and trace path. -
If
skillspec plan,skillspec act, orskillspec progressis unavailable, fall back toskillspec decide, then manually construct the same ordered phase checklist and progress notes before using tools. If the CLI is unavailable, readskill.spec.ymldirectly and apply the same contract manually. Do not expand this loader into a second source of truth.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 122 lines · 63 tokens per session scan A 8e80714987aa
local-csv-report is a skill published in the GitHub repository modiqo/skillspec (739 stars, last pushed 27d ago), licensed Apache-2.0. It adds 63 tokens to every session and 2,765 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 81% identical to generic-skill-creator, differing in 26 lines, and is treated as a copy.
Other skills, from other repositories
dcf-model
Build discounted cash flow valuation workbooks in Excel.
audit-xls
Audit a spreadsheet for formula accuracy, errors, and common mistakes. Scopes to a selected range, a single sheet, or the entire model (including financial-model integrity checks like BS balance, cash tie-out, and logic sanity). Triggers on "audit this sheet", "check my formulas", "find formula errors", "QA this…
google-drive-sheets
Find, read, export, edit, and manage the user's Google Drive, Docs, Sheets, and Slides through per-user OAuth.
feishu
Work with Feishu or Lark bots, docs, sheets, bitables, approval flows, and OpenAPI/MCP setup without hardcoding credentials.
large-file-parquet-analysis-and-highlight
当Excel文件总行数超过1万行时,通过转换为Parquet格式提升读取性能,提取目标指标并计算最大值,最后将结果输出为Excel并对特定行进行高亮标注。.
excel-basic-statistics-and-routing
Skill "excel-basic-statistics-and-routing" from OpenSenseNova/SenseNova-Skills, covering skill steps, 保存区间提取与汇总结果 and 保存筛选与统计结果.