Borrowing it
Nothing to install: this file belongs to MyceliumInc/Outfit. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/MyceliumInc/Outfit/main/.claude/skills/create-outfit/SKILL.mdgit clone --depth 1 https://github.com/MyceliumInc/OutfitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/myceliuminc/outfit/create-outfit)<a href="https://agentmods.dev/skills/myceliuminc/outfit/create-outfit"><img src="https://agentmods.dev/badge/skills/myceliuminc/outfit/create-outfit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/myceliuminc/outfit/create-outfit"><img src="https://agentmods.dev/badge/skills/myceliuminc/outfit/create-outfit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00043 | $0.01221 |
| Opus 5 | $0.00022 | $0.00611 |
| Sonnet 5 | $0.00009 | $0.00244 |
| Haiku 4.5 | $0.00004 | $0.00122 |
Grade A, and why
create-outfit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 127 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Create an Outfit
You are helping the user author a new Outfit: a single declarative file that defines an agent persona that is portable across runtimes and enforced by the Outfit Gateway. Your job is to turn a fuzzy "I want an agent that does X" into a valid, minimal, least-privilege outfit spec, then validate it.
1. Understand the persona
Ask only what you cannot infer. You need enough to fill in:
- name: kebab-case (a-z, 0-9, hyphen), e.g.
release-manager. - what it is for: one-line description.
- identity: how it should think and behave (becomes the system prompt).
- what it must be able to do: maps to capabilities below.
- what it must NOT do: shapes the scopes (least privilege).
Default to the narrowest set of capabilities that lets the persona do its job.
A read-only reviewer should not get fs.write; a report writer should be scoped
to a single output directory.
2. The spec
apiVersion: outfit/v1
name: <kebab-case>
description: <one line>
version: 0.1.0
identity:
prompt: |
<who the agent is, its goals, and how it behaves. Be specific about the
boundaries you also enforce below, so the model and the gateway agree.>
capabilities: [] # the portable, gateway-enforced core (see ontology)
skills: [] # instruction bundles, inlined into the persona
integrations: [] # raw MCP servers, the escape hatch (non-portable)
extensions: {} # runtime-specific extras (hooks, slash commands)
3. Capability ontology
Only these capability ids exist. Each is implemented and scope-checked by the gateway, so they behave identically on every runtime. The default posture is deny: an empty scope denies everything.
| id | scope shape |
|---|---|
shell.exec |
allow / deny: command glob patterns |
fs.read |
paths: path globs |
fs.write |
paths: path globs |
fs.list |
paths: path globs |
http.fetch |
domains: hostname globs |
web.search |
domains: hostname globs (+ provider) |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 127 lines · 43 tokens per session scan A 1eae36dbaf3d
create-outfit is a skill published in the GitHub repository MyceliumInc/Outfit (7 stars, last pushed 1mo ago), licensed MIT. It adds 43 tokens to every session and 1,221 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
deploy-docker-compose
Run the Omnigent server as a Docker compose stack (server + Postgres) on any Docker host — your laptop, a VPS, EC2 by hand, or as the base layer of any container-platform deploy. Invoke when the user wants to build the image, bring up the compose stack, debug the stack on a host they already have, or extend the stack…
api-docs
Document a module or public API surface (functions, classes, CLI commands, endpoints) from the code itself. Use when the user asks for API reference, to document a module, or to write usage docs for a public interface.
research
Run deep research on any topic using the Deep Research MCP server. Use this skill whenever the user wants to research a topic, gather information, find sources, or create a research document. Triggers on: 'research this', 'find out about', 'gather information on', 'I need to understand', 'deep dive into', or any…
security-audit
Audit a codebase or directory for security issues (hardcoded secrets, injection, unsafe deserialization, weak crypto, authz gaps) and produce a structured findings report. Use when the user asks for a security review, an audit, or to check code for vulnerabilities. Report only — never fix.
Workspace Data Analyst
Analyze CSV files in the workspace and summarize insights.
run_jinx
Execute a jinx by name (already loaded on the team) or by filesystem path (e.g. a freshly createdjinx that isn't yet registered), passing input values as a JSON object. Returns the jinx's output field or the full context dict. Use this to run a jinx you just wrote without exiting the session.