Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add openshift-eng/ai-helpers --skill detect-permafailgit clone --depth 1 https://github.com/openshift-eng/ai-helpersWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/openshift-eng/ai-helpers/detect-permafail)<a href="https://agentmods.dev/skills/openshift-eng/ai-helpers/detect-permafail"><img src="https://agentmods.dev/badge/skills/openshift-eng/ai-helpers/detect-permafail.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00022 | $0.10296 |
| Opus 5 | $0.00011 | $0.05148 |
| Sonnet 5 | $0.00004 | $0.02059 |
| Haiku 4.5 | $0.00002 | $0.01030 |
Grade A, and why
detect-permafail scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 885 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Detect Permafail
When to Use This Skill
Use this skill when you have 2-10 consecutive failures of the same job and need to determine if the failures represent a systematic/permanent failure (permafail) versus a flaky failure. This is critical for CI/CD pipeline analysis to distinguish between:
- Permafail: A systematic failure affecting the same test(s) or infrastructure issue, detected by analyzing comparable runs (same failure type):
- 2-3 comparable runs: All must have the same failure (100% match)
- 4-5 comparable runs: At least 4 must have the same failure (80% match)
- 6-10 comparable runs: At least ceil(count × 0.7) must have the same failure (70% match)
- Flaky: Non-deterministic failures with varying root causes, or failures that don't meet the permafail thresholds
Prerequisites
- Access to OpenShift CI Prow job artifacts via gcsweb URLs
- Access to the
Bashtool for runningplugins/ci/scripts/classify-job-failures.py - Python with the
requestspackage available for artifact fetching - Knowledge of Prow artifact structure (from
fetch-prowjob-jsonandprow-job-artifact-searchskills) - 2-10 URLs pointing to consecutive job failures (from Prow/OpenShift CI, ordered newest to oldest)
- Job name context to verify consistency across all failures
- PR information to provide context for analysis
Implementation Steps
Step 1: Validate Inputs
Standard Mode (URL-based):
Verify that all required inputs are present with expected types and constraints:
failure_urls: Array of 2-10 strings matching Prow job URL patternhttps://prow.ci.openshift.org/view/gs/<bucket>/<path>/<job-name>/<build-id>where path may belogs/,pr-logs/pull/, or other GCS paths (must be consecutive runs, ordered newest to oldest)job_name: Non-empty string identifier of the job being analyzedpr_info: Object containing PR number (integer) and repository context (string)- Each URL must match the Prow job URL pattern above
Reject requests if:
- URLs count is less than 2 or more than 10
- Job names don't match across all URLs (validate via prowjob.json metadata, not path position)
- PR context is missing
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 885 lines · 22 tokens per session scan A eea95463ef38
detect-permafail is a skill published in the GitHub repository openshift-eng/ai-helpers (116 stars, last pushed 3d ago), licensed Apache-2.0. It adds 22 tokens to every session and 10,296 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
smoke-test
Health smoke tests + auto-fix for gbrain installs (and OpenClaw services when present). Run after machine/container restarts or whenever something seems broken. Tests critical services, auto-fixes bounded local issues, and reports worker topology without starting daemons. Extensible via user-defined test scripts in…
mcore-create-issue
Investigate a failing GitHub Actions run or job and create a GitHub issue for the failure.
debug-task
Diagnose and fix moon tasks that are broken, misconfigured, or behaving unexpectedly. Use this skill when a moon task is failing, not running, skipped, hanging, producing stale or wrong output, cached when it shouldn't be, re-running every time when it should be cached, or when outputs are empty or missing after a…
github-ci-fix
Fix failing GitHub CI / Actions checks via fixgithubprci and push to the existing PR head, or fix a branch's failing CI via a linked repair worktree.
github-ci-fix
Use when the user asks OpenSRE to fix failing GitHub CI, GitHub Actions checks, failing pull request checks, a broken PR branch, or CI on a named branch such as main.
ci-triage
Classify CI failures — distinguish clear regressions from infra flakes and security-test failures. Produces structured failure reports.