Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/oxsecurity/megalinter/megalinter-fixnpx skills add oxsecurity/megalinter --skill megalinter-fixgit clone --depth 1 https://github.com/oxsecurity/megalinterWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/oxsecurity/megalinter/megalinter-fix)<a href="https://agentmods.dev/skills/oxsecurity/megalinter/megalinter-fix"><img src="https://agentmods.dev/badge/skills/oxsecurity/megalinter/megalinter-fix.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00091 | $0.01295 |
| Opus 5 | $0.00046 | $0.00647 |
| Sonnet 5 | $0.00018 | $0.00259 |
| Haiku 4.5 | $0.00009 | $0.00129 |
Grade A, and why
megalinter-fix scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
The source is not reproduced here
Licensed AGPL-3.0
The repository is licensed AGPL-3.0, which this catalogue does not treat as permission to reproduce the file. Read it at the source.
What ships with it
60 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- linters/action_actionlint.md 4.8 KB
- linters/action_zizmor.md 5.2 KB
- linters/ansible_ansible_lint.md 5.0 KB
- linters/api_spectral.md 1.9 KB
- linters/arm_arm_ttk.md 4.3 KB
- linters/bash_exec.md 3.4 KB
- linters/bash_shellcheck.md 4.7 KB
- linters/bash_shfmt.md 4.1 KB
- linters/bicep_bicep_linter.md 5.4 KB
- linters/c_clang_format.md 4.7 KB
- linters/c_cppcheck.md 4.1 KB
- linters/c_cpplint.md 4.7 KB
- linters/clojure_clj_kondo.md 4.2 KB
- linters/clojure_cljstyle.md 4.7 KB
- linters/cloudformation_cfn_lint.md 4.9 KB
- linters/copypaste_jscpd.md 4.0 KB
- linters/cpp_clang_format.md 4.8 KB
- linters/cpp_cppcheck.md 4.1 KB
- linters/cpp_cpplint.md 4.7 KB
- linters/csharp_csharpier.md 4.4 KB
- linters/csharp_dotnet_format.md 4.6 KB
- linters/csharp_roslynator.md 4.5 KB
- linters/css_biome.md 1.8 KB
- linters/css_stylelint.md 5.4 KB
- linters/dart_dartanalyzer.md 4.7 KB
- linters/dockerfile_hadolint.md 4.2 KB
- linters/editorconfig_editorconfig_checker.md 5.3 KB
- linters/env_dotenv_linter.md 4.8 KB
- linters/gherkin_gherkin_lint.md 4.8 KB
- linters/go_golangci_lint.md 5.1 KB
- linters/go_revive.md 4.6 KB
- linters/graphql_biome.md 1.9 KB
- linters/graphql_graphql_schema_linter.md 5.0 KB
- linters/groovy_npm_groovy_lint.md 5.1 KB
- linters/html_djlint.md 4.3 KB
- linters/html_htmlhint.md 4.3 KB
- linters/java_checkstyle.md 4.7 KB
- linters/java_pmd.md 4.8 KB
- linters/javascript_biome.md 1.9 KB
- linters/javascript_es.md 5.4 KB
- linters/javascript_prettier.md 4.6 KB
- linters/javascript_standard.md 4.1 KB
- linters/json_biome.md 1.9 KB
- linters/json_jsonlint.md 4.1 KB
- linters/json_npm_package_json_lint.md 4.5 KB
- linters/json_prettier.md 4.1 KB
- linters/json_v8r.md 4.3 KB
- linters/jsx_biome.md 1.8 KB
- linters/jsx_eslint.md 4.8 KB
- linters/kotlin_detekt.md 4.2 KB
- linters/kotlin_ktlint.md 4.9 KB
- linters/kubernetes_helm.md 4.7 KB
- linters/kubernetes_kubeconform.md 4.3 KB
- linters/kubernetes_kubescape.md 4.0 KB
- linters/latex_chktex.md 4.5 KB
- linters/lua_luacheck.md 5.1 KB
- linters/lua_stylua.md 3.4 KB
- linters/markdown_markdown_table_formatter.md 4.1 KB
- linters/markdown_markdownlint.md 5.5 KB
- linters/markdown_rumdl.md 4.7 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 56 lines · 91 tokens per session scan A 6d9d70218d40
megalinter-fix is a skill published in the GitHub repository oxsecurity/megalinter (2,577 stars, last pushed today), licensed AGPL-3.0. It adds 91 tokens to every session and 1,295 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
ruff-docs
Ruff — fast Python linter and formatter in Rust. 900+ rules, Black-compatible formatter, LSP, CI/CD.
dd-code-generation
Use pup CLI for immediate Datadog operations or generate code for integration into applications.
implement
Research, implement, test, document, and review a Fallow feature, fix, refactor, or repository improvement. Use when asked to build or change Fallow.
open-draft-pr
Prepare local changes for review with an intentional commit, push, and ready PR for fallow. Use when the user wants to publish work, open a PR, or turn local changes into a reviewable branch.
browser-smoke-review
Use browser automation to review docs pages, preview URLs, rendered output, or web-facing fallow surfaces. Use when the user wants a screenshot-based review, browser smoke test, docs site check, or preview deployment inspection.
debug-false-positive
Diagnose and fix a Fallow false positive or false negative through extraction, resolution, graph, analysis, reporting, and real-consumer verification.