Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add paulpreibisch/AgentVibes --skill bmad-helpgit clone --depth 1 https://github.com/paulpreibisch/AgentVibesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/paulpreibisch/agentvibes/bmad-help)<a href="https://agentmods.dev/skills/paulpreibisch/agentvibes/bmad-help"><img src="https://agentmods.dev/badge/skills/paulpreibisch/agentvibes/bmad-help.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00051 | $0.00826 |
| Opus 5 | $0.00026 | $0.00413 |
| Sonnet 5 | $0.00010 | $0.00165 |
| Haiku 4.5 | $0.00005 | $0.00083 |
Grade A, and why
bmad-help scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.
BMad Help
Purpose
Help the user understand where they are in their BMad workflow and what to do next. Answer BMad questions when asked.
Desired Outcomes
When this skill completes, the user should:
- Know where they are — which module and phase they're in, what's already been completed
- Know what to do next — the next recommended and/or required step, with clear reasoning
- Know how to invoke it — skill name, menu code, action context, and any args that shortcut the conversation
- Get offered a quick start — when a single skill is the clear next step, offer to run it for the user right now rather than just listing it
- Feel oriented, not overwhelmed — surface only what's relevant to their current position; don't dump the entire catalog
Data Sources
- Catalog:
{project-root}/_bmad/_config/bmad-help.csv— assembled manifest of all installed module skills - Config:
config.yamlanduser-config.yamlfiles in{project-root}/_bmad/and its subfolders — resolveoutput-locationvariables, providecommunication_languageandproject_knowledge - Artifacts: Files matching
outputspatterns at resolvedoutput-locationpaths reveal which steps are possibly completed; their content may also provide grounding context for recommendations - Project knowledge: If
project_knowledgeresolves to an existing path, read it for grounding context. Never fabricate project-specific details.
CSV Interpretation
The catalog uses this format:
module,skill,display-name,menu-code,description,action,args,phase,after,before,required,output-location,outputs
Phases determine the high-level flow:
anytime— available regardless of workflow state- Numbered phases (
1-analysis,2-planning, etc.) flow in order; naming varies by module
Dependencies determine ordering within and across phases:
after— skills that should ideally complete before this onebefore— skills that should run after this one- Format:
skill-namefor single-action skills,skill-name:actionfor multi-action skills
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 74 lines · 51 tokens per session scan A 8966c636a5ee
bmad-help is a skill published in the GitHub repository paulpreibisch/AgentVibes (153 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 51 tokens to every session and 826 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
sora-taira-testnet
Work against the SORA Taira testnet through its deployed Torii MCP endpoint for live account, asset, alias, contract, governance, Musubi package-registry, and transaction workflows. Use when Codex needs to inspect or mutate the Taira testnet, verify or add https://taira.sora.org/v1/mcp, prefer the curated iroha. tool…
skill-vetter-runtime
Review ClawHub or local Skill packages before installation, classify risk, and return a structured security report.
gateway
Start and manage the Kurtosis gateway for Kubernetes. The gateway forwards local ports to the Kurtosis engine and services running in a k8s cluster. Required when using Kurtosis with Kubernetes. Use when kurtosis engine status shows nothing on k8s or services aren't reachable.
performing-container-security-scanning-with-trivy
Scan container images, filesystems, and Kubernetes manifests for vulnerabilities, misconfigurations, exposed secrets, and license compliance issues using Aqua Security Trivy with SBOM generation and CI/CD integration.
evolve-create
Create a reusable gene from a novel fix pattern. Only invoke manually.
frontend-conventions
Frontend convention reference (SvelteKit / Svelte 5). Auto-injected into frontend-aware agents - not user-invocable.