Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/onsager-ai/dev-skills/rust-node-cinpx skills add onsager-ai/dev-skills --skill rust-node-cigit clone --depth 1 https://github.com/onsager-ai/dev-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/onsager-ai/dev-skills/rust-node-ci)<a href="https://agentmods.dev/skills/onsager-ai/dev-skills/rust-node-ci"><img src="https://agentmods.dev/badge/skills/onsager-ai/dev-skills/rust-node-ci.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00137 | $0.01737 |
| Opus 5 | $0.00068 | $0.00869 |
| Sonnet 5 | $0.00027 | $0.00347 |
| Haiku 4.5 | $0.00014 | $0.00174 |
Grade A, and why
rust-node-ci scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 203 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Rust+Node.js CI/CD
GitHub Actions workflows and composite actions for Rust+Node.js hybrid projects.
When to Use This Skill
Activate when any of the following are true:
- Working with
.github/workflows/in a repo with bothCargo.tomlandpackage.json - Setting up, fixing, or extending CI/CD pipelines
- Installing composite actions into a project
- User mentions "CI", "workflow", "GitHub Actions", "cross-build", or "artifact"
Decision Tree
What does the user need?
Set up CI from scratch?
→ Copy templates/workflows/ into .github/workflows/
→ Install composite actions from templates/actions/ into .github/actions/
→ Customize platform matrix for your targets
Fix a failing CI job?
→ Node job → CI Jobs section
→ Rust build/cross-compile → Composite Actions section + references/troubleshooting.md
→ Publish workflow → see rust-npm-publish skill
Add a new platform to the build matrix?
→ Publish Workflow Matrix section
→ Full platform reference → see rust-npm-publish skill
Understand dev vs release versioning in CI?
→ Dev Versioning section
Workflow Architecture
┌─────────────┐ ┌──────────────────┐
│ Node Build │ │ Rust Build │
│ (test/lint) │ │ (per platform) │
└──────┬──────┘ └────────┬─────────┘
│ │
│ ┌─────────────┐ │
└──►│ Artifacts │◄──┘
└──────┬──────┘
│
┌──────▼──────┐
│ Publish │
└─────────────┘
Workflows
| Workflow | Trigger | What It Does |
|---|---|---|
ci.yml |
PR, push to main | Node build+test+lint, Rust fmt+clippy+test |
publish.yml |
Release, dispatch | Cross-build → publish to npm |
copilot-setup-steps.yml |
repository_dispatch | Copilot agent onboarding |
Templates: templates/workflows/
CI Jobs
Node Job
steps:
- uses: ./.github/actions/setup-workspace
- run: pnpm build
- run: pnpm test
- run: pnpm typecheck
What ships with it
12 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/troubleshooting.md 2.0 KB
- templates/actions/compute-version/action.yml 1.7 KB
- templates/actions/compute-version/README.md 793 B
- templates/actions/rust-cross-build/action.yml 1.5 KB
- templates/actions/rust-cross-build/README.md 718 B
- templates/actions/setup-workspace/action.yml 923 B
- templates/actions/setup-workspace/README.md 533 B
- templates/actions/wait-npm-propagation/action.yml 2.2 KB
- templates/actions/wait-npm-propagation/README.md 664 B
- templates/workflows/ci.yml 1.2 KB
- templates/workflows/copilot-setup-steps.yml 888 B
- templates/workflows/publish.yml 4.5 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 203 lines · 137 tokens per session scan A be9a096dc6c1
rust-node-ci is a skill published in the GitHub repository onsager-ai/dev-skills (5 stars, last pushed 22d ago), licensed MIT. It adds 137 tokens to every session and 1,737 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
ci-security-scanning-with-strix
Add security scanning to CI/CD with Strix — GitHub Actions, GitLab CI, or any pipeline — so every pull request gets a diff-scoped AI pentest that blocks vulnerable code before it merges, with results as PR comments and SARIF uploaded to code scanning. Covers both the self-hosted open-source CLI (runs in your runner)…
desktop-principles
Desktop-specific UX principles - hover states, pointer precision, keyboard shortcuts, multi-window, focus management. Covers macOS, Windows, Linux, web desktop.
upgrading-golang
Upgrades Go version across the entire Chainloop codebase including source files, Docker images, CI/CD workflows, and documentation. Use when the user mentions upgrading Go, golang version, or updating Go compiler version.
python-canary-fix
Investigate and propose fixes for Python canary cron failures in the openinference repo. Use when the user mentions Python canary failures, Python cron failures, or when the auto-fix CI job reports Python instrumentation canary issues.
ci-fixer
CI failures - read error, minimal fix, verify.
infrastructure-setup
Provides project infrastructure conventions and review criteria for local setup, Docker, Git hooks, CI/CD, service delivery, release artifacts, monitoring, backups, and operations. Use when: "настрой инфраструктуру", "измени CI/CD", "подготовь деплой", "настрой Docker", "собери release artifact", "настрой мониторинг"…