Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/poco-ai/agentero/releasenpx skills add poco-ai/Agentero --skill releasegit clone --depth 1 https://github.com/poco-ai/AgenteroWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/poco-ai/agentero/release)<a href="https://agentmods.dev/skills/poco-ai/agentero/release"><img src="https://agentmods.dev/badge/skills/poco-ai/agentero/release.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00081 | $0.01647 |
| Opus 5 | $0.00041 | $0.00823 |
| Sonnet 5 | $0.00016 | $0.00329 |
| Haiku 4.5 | $0.00008 | $0.00165 |
Grade A, and why
release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 178 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agentero Release
Prepare evidence-backed bilingual Release notes and write them directly to the Draft GitHub Release. Use dry runs when the user explicitly requests read-only preview.
Establish the release range
- Read
git status, the current branch, local and remote tags, and the target Release state. Preserve unrelated working-tree changes. - Resolve both endpoints to immutable commits and verify that the base is an ancestor of the target.
- For a stable target, default to the latest earlier published stable Release reachable from the target. For a prerelease, prefer the preceding prerelease in the same version series, then fall back to the latest stable Release.
- Display the selected
<base>..<target>range. Stop for user direction when the target, release channel, ancestry, or previous Release is ambiguous. - Never move or overwrite an existing remote tag. Treat a tag already observed by GitHub Actions or attached to a Release as immutable.
Collect evidence
Run the bundled collector from the repository root:
node .agents/skills/release/scripts/collect-release-context.mjs <base> <target>
Use merged pull requests as the main narrative units. Always inspect uncovered first-parent commits as a second source; the presence of one PR does not make other mainline commits disappear.
For each candidate change:
- Prefer the PR title, body, linked issues, labels, and changed behavior.
- Use the first-parent commit subject, body, and changed files when no merged PR covers the commit.
- Inspect the relevant diff or documentation when the public effect is unclear.
- Collect issues closed during the release range that are not already covered by
a merged PR. Use
gh issue list --state closed --search "closed:>={base-date}"or inspectCloses/Fixesreferences in commit messages. - Exclude release bumps, formatting, tests, internal refactors, and routine documentation unless they change installation, compatibility, security, or visible behavior.
- Combine multiple commits that implement one user-visible outcome.
- Keep a PR, commit, or issue URL as evidence for every bullet.
- Include the first committer or PR author for each bullet so contributors are
credited in the notes. Resolve GitHub usernames — the git commit author
name (e.g.
QiyuanChen) is not necessarily the GitHub handle (e.g.qychen2001). For PRs, use the PRauthor.loginfield directly. For uncovered commits, rungh api repos/poco-ai/Agentero/commits/<sha>and extract theauthor.loginfield. Fall back to the commitauthor.nameonly when the GitHub API returns null (e.g. unauthenticated local commits). - Report uncertainty or conflicting evidence instead of inventing behavior.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 178 lines · 81 tokens per session scan A 3adcbb3febf5
release is a skill published in the GitHub repository poco-ai/Agentero (409 stars, last pushed today), licensed MIT. It adds 81 tokens to every session and 1,647 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
aatmf-t10-confidentiality-breach
AATMF T10 — Integrity & Confidentiality Breach. System prompt extraction, training-data extraction, model-weight leakage, private-key recovery.
mochi-remind
Handle due reminders — notify the user with natural language and mark them done.
memory
Use when the user asks to remember, recall, forget, update, search, or inspect durable OpenSquilla memory, including profile facts in USER.md and long-term notes in MEMORY.md or memory//.md.
lazarus-group
Adversary-emulation profile for Lazarus Group (G0032, aka Hidden Cobra / Diamond Sleet / Labyrinth Chollima), a North Korean RGB-linked actor conducting espionage, destructive, and financially motivated operations.
sidewinder-rattlesnake
Adversary-emulation profile for SideWinder (G0121 / Rattlesnake / T-APT-04 / Razor Tiger), India's suspected state-sponsored cyber-espionage actor.
ha-data-stores
Map of Hope Agent's local data stores and safe read-only query workflow. Use when the user asks where Hope Agent stores data, wants to inspect sessions/messages/memory/logs/background jobs/knowledge indexes/settings, asks the model to query local app data, or debugging requires checking persisted state. Trigger…