Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/pillip/claude-dev-kit/scannpx skills add pillip/claude-dev-kit --skill scangit clone --depth 1 https://github.com/pillip/claude-dev-kitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00023 | $0.02637 |
| Opus 5 | $0.00012 | $0.01319 |
| Sonnet 5 | $0.00005 | $0.00527 |
| Haiku 4.5 | $0.00002 | $0.00264 |
Grade A, and why
scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 191 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Kit Preamble — scan
Kit Script Root
Kit root: ${CLAUDE_PLUGIN_ROOT}
- Absolute path above → plugin install (substituted at load time; no project
scripts/dir): prefix every kit script command with it, e.g.bash <kit-root>/scripts/checkpoint.sh …. Absolute paths also work from worktrees. - Literal
${…}placeholder above → standalone layout: run commands as written.
Project Context Detection
Run these checks silently at the start. Use results to adapt behavior:
[ -f issues.md ]— if true, this project uses the sprint system. Respect issue numbering and STATUS.md.[ -f docs/sprint_state.md ]— if true and Status showsrunning, a sprint is active. Be aware of parallel work in worktrees.[ -f docs/prd_digest.md ]— if true, read it for quick project context before starting.
Kit Rules
- Verify
gh auth statusbefore any GitHub operation.
Algorithm
Phase 1 — Discovery
- Ensure
docs/directory exists. - Determine scan target: if
$ARGUMENTSis provided and is a valid directory path, use it as the scan root. Otherwise, use the project root. - Check for
--forceflag in$ARGUMENTS: if present, skip existing-file prompts and overwrite all. - Check for
--auditflag in$ARGUMENTS: if present, produce onlydocs/scan_report.md(read-only mode, no other docs generated). - Inventory existing
docs/files. If any target documents already exist and neither--forcenor--auditis set, ask the user: overwrite or keep existing? - Invoke the codebase-scanner agent via Task tool:
- Prompt: "You are the codebase-scanner agent. Analyze the codebase at [scan root]. Follow your agent guidelines precisely."
- Pass: scan root path, list of existing docs
- The agent returns a structured scan_context (do NOT write it to disk — it is an internal intermediate artifact).
CHECKPOINT — MANDATORY — NEVER SKIP Verify the scan_context contains all required sections: Project Identity, Architecture, Inferred Requirements, Quality Assessment. If any section is missing or empty: STOP and retry the codebase-scanner agent before proceeding.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 191 lines · 23 tokens per session scan A 9610b58cd4c3
scan is a skill published in the GitHub repository pillip/claude-dev-kit (11 stars, last pushed 16d ago), licensed MIT. It adds 23 tokens to every session and 2,637 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
knowledge-base
Create and maintain a Markdown knowledge base that any AI agent can read, search, and update. Use when the user wants to start a knowledge base, add or update notes, organize docs/notes for an agent or LLM to consume, build an index of notes, or run a cleanup/maintenance pass on an existing MD knowledge base. Triggers…
peer-review
Structured manuscript/grant review with checklist-based evaluation. Use when writing formal peer reviews with specific criteria methodology assessment, statistical validity, reporting standards compliance (CONSORT/STROBE), and constructive feedback. Best for actual review writing, manuscript revision. For evaluating…
build-teaql-app
Build or change a TeaQL application in Java, Rust, Go, Swift, Python, C#/.NET, or TypeScript, including Kotlin/JVM applications that consume Java-generated libraries. Mandatory order: first draft and save a complete KSML model, then verify the client and evaluate that saved model, repair it through repeated evaluation…
dd-code-generation
Use pup CLI for immediate Datadog operations or generate code for integration into applications.
taiyi-integration
TaiyiForge 第9阶段 — 闭环归档,CHANGELOG.md。四端通用。.
taiyi-ui-design
TaiyiForge 第 4 阶段 — UI/UX 契约,产出 UI-DESIGN.md。四端通用。.