Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/outlinedriven/outline-driven-development/capture-isolated-patchnpx skills add OutlineDriven/outline-driven-development --skill capture-isolated-patchgit clone --depth 1 https://github.com/OutlineDriven/outline-driven-developmentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/outlinedriven/outline-driven-development/capture-isolated-patch)<a href="https://agentmods.dev/skills/outlinedriven/outline-driven-development/capture-isolated-patch"><img src="https://agentmods.dev/badge/skills/outlinedriven/outline-driven-development/capture-isolated-patch.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00053 | $0.01105 |
| Opus 5 | $0.00026 | $0.00553 |
| Sonnet 5 | $0.00011 | $0.00221 |
| Haiku 4.5 | $0.00005 | $0.00111 |
Grade A, and why
capture-isolated-patch scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- capture-isolated-patch — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 42 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Capture isolated patch
Contract
| Field | Bound contract |
|---|---|
| Trigger | A candidate change must be produced without touching the working tree. |
| Authority | Reversible local writes only: write to an ephemeral worktree and a temporary patch file under the worktree's parent temporary directory; never write to the original working tree. Rollback is git worktree remove --force <path>. |
| Side effect | Creates an ephemeral worktree, runs the declared command inside it, and returns the exit code plus a binary-safe patch path. No commit, no push, no merge. The worktree is preserved on extraction failure. |
| Done | Patch bytes are returned, or the failure is preserved for inspection; the original working tree is unchanged either way. |
Inputs
command(required): the shell command that produces the candidate change. Run it inside the ephemeral worktree, with that worktree as its working directory.base-ref(optional): the git ref the worktree is created from. Defaults to the currentHEAD.repo-path(optional): path to the repository. Defaults to the current working directory.
Procedure
- Require
command. Accept optionalbase-ref(default: currentHEAD) and optionalrepo-path(default: current working directory). Done when: the command is present and optional inputs are resolved to defaults or supplied values. - Verify
repo-pathis a git work tree andbase-refresolves, both scoped torepo-path:git -C <repo-path> rev-parse --is-inside-work-treeandgit -C <repo-path> rev-parse --verify <base-ref>. Stop and report the exact failing check before creating any worktree if either check fails. Done when: both checks pass, or the failing check is named and the run stops. - Create an ephemeral worktree at a fresh temporary path with
git -C <repo-path> worktree add --detach <tmp-path> <base-ref>. Record<tmp-path>as the worktree path. Done when: the worktree is created and its path is recorded, or the git error is reported. - Run
commandinside the worktree with the worktree as its working directory. Capture stdout, stderr, and the exit code. Do not commit, push, or merge. Done when: the command returns with stdout, stderr, and exit code captured. - After the command returns, stage untracked files so a newly created file is captured: run
git -C <tmp-path> add -N .to mark them intent-to-add. Then compute the worktree diff againstbase-refwithgit -C <tmp-path> diff --binary <base-ref>so binary file changes are representable. Write the diff to a patch file under the worktree's parent temporary directory. Done when: the binary-safe diff is written to a patch file, or the extraction failure is captured. - If extraction succeeds, remove the ephemeral worktree with
git worktree remove --force <tmp-path>and return the patch file path, the command exit code, and captured stdout/stderr. The patch was already written outside the worktree in step 5, so forcing the removal discards only the worktree's working files and loses nothing. Done when: the worktree is removed and the patch path, exit code, and output are returned. - If extraction fails, preserve the worktree in place and return the worktree path, the command exit code, and the failure reason. Do not delete the worktree. Done when: the worktree is preserved and its path, exit code, and failure reason are returned.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 42 lines · 53 tokens per session scan A 40084611ca69
capture-isolated-patch is a skill published in the GitHub repository OutlineDriven/outline-driven-development (52 stars, last pushed yesterday), licensed Apache-2.0. It adds 53 tokens to every session and 1,105 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
fin-brief-generator
根据用户输入或已有研究输出(文献综述/想法报告/新颖性报告),自动生成或更新FINBRIEF.md,减少用户填写负担。.
doc-review
Use when the user asks to review or critique a prose planning document — a plan, spec, PRD, requirements doc, or design doc.
autolearn
Compound a solved problem into a durable in-repo learning doc. Use when a verified non-trivial fix lands, the user says "compound this", "document this fix", or "remember this". This is the automatic-capture entry point; for an explicitly requested one-off write-up, use compound.
askme
Explore intent with Verbalized Sampling before planning. Use when the task is ambiguous, you need maximum clarifying questions, or you want collaborative or adversarial mode via /askme.
deps-upgrade
Use when dependency upgrades need tiered batches for CVEs, a major release, forced compatibility, scheduled hygiene, a pre-release lockfile audit, or a cadence-driven or vulnerability-triggered sweep. Classifies each update on a risk ladder, verifies it, or defers it with a reason. Not for PR queue triage; use…
strict-validation-setup
Use when a user invokes a strict-mode validation or verifiable-goals loop setup. Bootstraps strict-mode tooling and per-task GOALS.md scaffolding so an agentic loop can self-verify. Don't use for remote, credential, publish, deploy, or irreversible changes.