Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add petergaultney/lemonaid --skill watch-briefsgit clone --depth 1 https://github.com/petergaultney/lemonaidWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/petergaultney/lemonaid/watch-briefs)<a href="https://agentmods.dev/skills/petergaultney/lemonaid/watch-briefs"><img src="https://agentmods.dev/badge/skills/petergaultney/lemonaid/watch-briefs/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/petergaultney/lemonaid/watch-briefs"><img src="https://agentmods.dev/badge/skills/petergaultney/lemonaid/watch-briefs.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00041 | $0.00584 |
| Opus 5.5 | $0.00016 | $0.00234 |
| Sonnet 5.5 | $0.00008 | $0.00117 |
| Haiku 4.5 | $0.00004 | $0.00058 |
Grade A, and why
watch-briefs scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Watch children's briefs
Use lemonaid watch briefs --children --self to wait on direct children through
Lemonaid's Lemon-ID parent links. Grandchildren are their own parent's responsibility.
You need an attached brief to use --self; an explicit parent Lemon-ID, channel, or
brief name can replace it.
Check lemonaid watch briefs --children --self --status first. If a waiter is running,
keep it; a duplicate exits 3. An optional --me "<watcher name>" keeps independent
watchers apart. Use the same name for status checks and every rearm.
In Claude Code, start lemonaid watch briefs --children --self --once as a background
Bash task with timeout: 2147483647, then end the turn. Its completion wakes you. Rearm
after handling a batch, or if the harness stops the task at its background time limit.
In Codex, check that CODEX_THREAD_ID is set and codex queue --help succeeds. Start
lemonaid watch briefs --children --self --codex-thread as an escalated exec_command
session, then end the turn. The bare flag reads the thread ID from the environment;
codex queue needs access outside the workspace sandbox. A setup refusal means no
waiter started. The first batch queues a turn and exits.
The first run takes current children as its baseline. Rearms report Status and ask
changes made since the last successful delivery, plus newly linked children, without
repeating delivered events. All Status transitions count, including working. Progress
edits stay quiet; whitespace and bullet formatting in asks stay quiet too. Missing or
unlinked briefs are ignored. Changes are sampled every 5 seconds and delivered after
2 quiet seconds; --interval and --quiet adjust these timings.
When woken, read the named children's briefs and act on their current Status and asks.
Then rearm the same command. Do not replace this waiter with a polling loop or scheduled
wakeups. Record its exact command in your brief's ## Waiters, and keep your status and
what you are waiting on current.
State and locks are separate from other watchers, under $TMPDIR/lemonaid-watch-briefs/.
--state-dir moves them. A failed delivery is not recorded, so a rearm retries it.
Stop your own waiter by its process ID when the child work no longer needs watching,
and remove its command from your brief. Do not delete shared lock files.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 43 lines · 41 tokens per session scan A 1abfa74b0171
watch-briefs is a skill published in the GitHub repository petergaultney/lemonaid (11 stars, last pushed today), licensed MIT. It adds 41 tokens to every session and 584 once invoked, about $0.0002 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-08.
Other skills, from other repositories
first-reader
Beta readers for any draft, run by simulating how a real reader experiences it, moment by moment. A skim gate, a no-lookahead timed read producing an attention transcript with quit points, a recall test of what a reader remembers the next day, and a trust ledger of the implied author. Use when the user asks for a beta…
mcp-apps-builder
MANDATORY for ALL MCP server work - mcp-use framework best practices and patterns. READ THIS FIRST before any MCP server work, including: Creating new MCP servers Modifying existing MCP servers (adding/updating tools, resources, prompts, widgets) Debugging MCP server issues or errors Reviewing MCP server code for…
project-graveyard
Scans the developer's machine for dead side projects, autopsies each one from its git history (died at the payments wall, killed by a newer project, finished but never shipped), surfaces their personal death patterns, and picks the corpse most worth resurrecting — then helps ship it. Use when the user mentions…
commit-archaeologist
Reconstructs why code exists from local git history, including the introducing commit, later changes, current authors, repeated companion files, and likely intent. Use when the user asks "why does this code exist", "who wrote this function and why", or to "explain the history of this function" before a rewrite…
dependency-doctor
Checks requirements.txt, pyproject.toml, and package.json dependency manifests for surface-level direct-dependency footguns: standard-library shadowing pins, abandoned backports, unpinned dependencies, and obvious intra-manifest conflicts, plus opt-in PyPI yanked releases. Use when the user asks to check a manifest…
scope-creep-detector
Analyzes git diffs against a stated intent to detect scope creep, unrelated files, broad pull requests, changes that grew beyond a fix, dependency additions, public API renames, config or CI edits, oversized hunks, and formatting-only files. Use when the user asks whether a change grew beyond the fix, a PR is too…