Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add OutlineDriven/outline-driven-development --skill ci-sweepergit clone --depth 1 https://github.com/OutlineDriven/outline-driven-developmentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/outlinedriven/outline-driven-development/ci-sweeper)<a href="https://agentmods.dev/skills/outlinedriven/outline-driven-development/ci-sweeper"><img src="https://agentmods.dev/badge/skills/outlinedriven/outline-driven-development/ci-sweeper.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00054 | $0.00999 |
| Opus 5 | $0.00027 | $0.00500 |
| Sonnet 5 | $0.00011 | $0.00200 |
| Haiku 4.5 | $0.00005 | $0.00100 |
Grade A, and why
ci-sweeper scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- ci-sweeper — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 48 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CI sweeper
Contract
| Field | Bound contract |
|---|---|
| Trigger | A recurring or requested sweep monitors CI failures over a bounded attempt window. |
| Authority | Reversible local writes only: observe CI checks, propose or implement one minimal isolated repair in a worktree, and run the verifier. Never push, merge, publish, deploy, or mutate credentials. |
| Side effect | One minimal isolated repair in a worktree plus one independent verifier run; hands off on flake, ambiguity, budget exhaustion, or circuit-breaker trip. |
| Done | Root cause reproduced or classified non-actionable; any patch is minimal, independently verified, and returned as a proposal; retries stop at the configured cap without symptom patching. |
Inputs
- CI run identifier or failing check name to sweep.
- Repository checkout path and the base commit the CI run used.
- Verifier command: the test or check command that independently confirms the repair.
- Attempt cap: maximum repair retries for this sweep.
- Optional: flake-detection window and circuit-breaker threshold (repeated non-convergence or repeated flakes that stop the sweep).
Procedure
- On each tick, fetch the current set of failing CI checks for the target run and record the attempt number against the configured cap. Done when: the failing checks are fetched and the attempt number is recorded.
- If the attempt cap is reached, stop and hand off; do not start a new repair. Done when: the sweep stops at the cap with a handoff, or the cap is not yet reached.
- Pick one failing check and reproduce the failure locally in an isolated worktree created from the base commit the CI run used. Done when: the failure is reproduced locally or confirmed non-reproducible.
- Classify the failure: reproduce the root cause, or classify it non-actionable (flake, environment, upstream). If the failure is a flake or the cause is ambiguous, hand off and do not patch. Done when: the failure is classified as root cause or non-actionable, or handed off.
- If a root cause is reproducible, implement one minimal isolated repair in the worktree: the smallest change that fixes the reproduced cause and nothing else. Done when: the minimal repair is implemented in the worktree.
- Run the verifier in the worktree independently of the repair; confirm the failing check passes and no other check regresses. Done when: the verifier confirms the fix and no regression, or the verifier failure is recorded.
- If the verifier fails or regresses, do not widen the patch; increment the attempt counter and either retry within budget or hand off. Done when: the attempt counter is incremented and the retry-or-handoff decision is made.
- Return the verified patch as a proposal (diff or branch) with the reproduced root cause and verifier evidence. Do not push, merge, or publish. Done when: the verified patch is returned as a proposal with evidence.
- If the circuit breaker trips (repeated non-convergence, repeated flakes, or budget exhaustion), stop the sweep and hand off with the accumulated evidence. Done when: the sweep stops with a handoff and accumulated evidence.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 48 lines · 54 tokens per session scan A 5310bf48165d
ci-sweeper is a skill published in the GitHub repository OutlineDriven/outline-driven-development (52 stars, last pushed yesterday), licensed Apache-2.0. It adds 54 tokens to every session and 999 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
ci-fix
Use when "CI is red", "fix the checks", or "make CI green", one check needs classifying, or a bounded sweep runs. Not for deploys, credentials, or rerun-as-fix. Non-CI bugs: use strike-the-root.
classify-ci-failure
Use when a CI check is failed, absent, pending too long, unstable, or reported unexpectedly. Classify it into a deterministic failure class with the next owner, then emit a reviewable fix plan, without patching. Not for sweeping and patching — use ci-sweeper.
ci-sweeper
Use when a requested sweep monitors CI failures over a bounded attempt window. Returns each root cause reproduced or classified non-actionable with any minimal verified patch as a proposal. Not for classifying one failure without patching — use classify-ci-failure.
gh-fix-ci
Inspect GitHub PR checks with gh, pull failing GitHub Actions logs, summarize the failure, then plan and implement the fix after user approval. Use when the user asks to debug or fix failing PR CI on GitHub Actions; external checks (Buildkite, etc.) are reported as URLs only.
mcore-create-issue
Investigate a failing GitHub Actions run or job and create a GitHub issue for the failure.
debug-task
Diagnose and fix moon tasks that are broken, misconfigured, or behaving unexpectedly. Use this skill when a moon task is failing, not running, skipped, hanging, producing stale or wrong output, cached when it shouldn't be, re-running every time when it should be cached, or when outputs are empty or missing after a…