Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Osipchuk/agent-skills --skill rubber-duckgit clone --depth 1 https://github.com/Osipchuk/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/osipchuk/agent-skills/rubber-duck)<a href="https://agentmods.dev/skills/osipchuk/agent-skills/rubber-duck"><img src="https://agentmods.dev/badge/skills/osipchuk/agent-skills/rubber-duck/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/osipchuk/agent-skills/rubber-duck"><img src="https://agentmods.dev/badge/skills/osipchuk/agent-skills/rubber-duck.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00145 | $0.00464 |
| Opus 5 | $0.00072 | $0.00232 |
| Sonnet 5 | $0.00029 | $0.00093 |
| Haiku 4.5 | $0.00015 | $0.00046 |
Grade A, and why
rubber-duck scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
rubber-duck
Help the person solve it themselves. The act of articulating a problem to something that won't just answer is what surfaces the solution. Start as a silent-ish duck; grow teeth only when they're spinning.
The escalation ladder
Gear 0 — Listen. Invite them to explain the problem as if to someone who knows nothing about it. Reflect back the key facts and the implicit assumptions you heard them make. Very often the answer surfaces right here — let it; don't rush to question.
Gear 1 — Clarify. Ask narrow, factual questions about what they've actually observed or already tried — not "what do you think it is?". One question per turn. Let them do the reasoning between your questions.
Gear 2 — Teeth. Only when they're repeating themselves, clearly stuck, or pushing for the answer: ask the one pointed question that exposes the gap in their reasoning. Still do not supply the fix.
The escape hatch
If they explicitly ask you to stop and just answer (roughly twice), or it's plainly an emergency, drop the method and answer directly. Insisting on the method past its usefulness is the failure mode, not a virtue.
Never
- Dump the solution in Gear 0 or 1.
- Ask more than one question per turn.
- Withhold to seem clever. The goal is their insight, not your cleverness.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 39 lines · 145 tokens per session scan A abeacf1cd7b1
rubber-duck is a skill published in the GitHub repository Osipchuk/agent-skills (5 stars, last pushed 1mo ago), licensed MIT. It adds 145 tokens to every session and 464 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
lx
Codebase exploration tool that reads many files or whole directories in a single call, with per-file headers, glob include/exclude filters, function/type skeleton extraction (signatures only, no bodies), and head/tail line slicing.
opencode-export
Export opencode sessions to self-contained HTML + JSON archives for sharing, review, or backup. Use when the user wants to save, archive, or share their AI coding session history.
log-work
Log the work segment that you did after the last work log until now in a.
meeting-transcript-to-action-items
Listen to a meeting recording and extract structured action items, decisions, and open questions. Maintains a persistent ledger across runs — previously-open actions are auto-resolved when mentioned as done in subsequent meetings. Outputs actions.csv (importable to Linear/Asana/Notion) + recap.md (paste into Slack).…
tokf-discover
Find missed token savings by scanning AI coding session files for commands that ran without tokf filtering.
handoff
Write a portable, secret-scrubbed handoff doc so this work can continue in any AI tool or on any machine. Use when saying "handoff", "running out of tokens", or "continue elsewhere".