Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/okhp3/skillz/catalog-integritynpx skills add OKHP3/skillz --skill catalog-integritygit clone --depth 1 https://github.com/OKHP3/skillzWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/okhp3/skillz/catalog-integrity)<a href="https://agentmods.dev/skills/okhp3/skillz/catalog-integrity"><img src="https://agentmods.dev/badge/skills/okhp3/skillz/catalog-integrity.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00022 | $0.00215 |
| Opus 5 | $0.00011 | $0.00108 |
| Sonnet 5 | $0.00004 | $0.00043 |
| Haiku 4.5 | $0.00002 | $0.00021 |
Grade A, and why
catalog-integrity scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Catalog integrity
Use when
Run after changing a skill contract, family metadata, evidence artifacts, catalog derivation, or generated catalog assets.
Callable command
node .agents/skills/catalog-integrity/run.mjs
The command runs the existing artifacts/forge/scripts/build-catalog.js and
test-catalog.mjs from their migrated workspace locations. It sets the local
development escape hatch for a shallow checkout only; CI still fails closed.
Inputs and outputs
- Input: the current checkout's root distribution families and generated
artifacts/forge/public/data/assets. - Output: concise pass/fail lines and a non-zero exit on invalid counts, metadata, evidence vocabulary, payload split, or provenance.
Never paste credentials into the command. A local shallow-history warning is not a release pass; a CI shallow-history failure blocks publishing.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 31 lines · 22 tokens per session scan A 4353b66e4012
catalog-integrity is a skill published in the GitHub repository OKHP3/skillz (3 stars, last pushed today), licensed MIT. It adds 22 tokens to every session and 215 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
vastai-sdk
Vast.ai Python SDK — high-level API for GPU instances, volumes, serverless endpoints, and billing.
pm-aarrr
Use when: 产品上线后需要分析用户增长、制定增长策略、诊断产品健康度、优化AARRR各环节 Do NOT use when: 产品未上线、仅需单一指标分析无需全链路.
pm-docs
Use when: 需要输出PRD/BRD/MRD产品文档、方案文档、商业计划文档、需要文档模板 Do NOT auto-select when: 用户用自然语言说"写需求文档""写PRD""帮我设计需求"等新产品请求 → 这些必须先路由到 start-super-pm Direct slash-command use is allowed: 用户显式输入 /pm-docs 时可直接进入,但必须通过本 skill 的前置门禁 Do NOT use when: 文档已完备无需生成、仅需口头讨论无需书面输出.
pm-position
Use when: 需要明确产品定位、设计商业模式、规划盈利方式、制定定价策略、进行盈利预测 Do NOT use when: 产品定位已明确、仅需执行无需重新定位.
pm-retro
Use when: 迭代结束后需要复盘总结经验教训、改进团队流程、记录改进行动项 Do NOT use when: 迭代尚未结束、团队不需要正式复盘.
product-marketing-copywriter
当市场调研分析师与营销专员、内容创作者需要推广产品时,使用本技能可精准分析受众痛点与产品卖点,一键生成高转化标题与正文,快速产出激发购买欲的优质营销文案,大幅提升销售转化率。.