Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/poorgramer-zack/copilot-cli-things/create-extensionnpx skills add Poorgramer-Zack/copilot-cli-things --skill create-extensiongit clone --depth 1 https://github.com/Poorgramer-Zack/copilot-cli-thingsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/poorgramer-zack/copilot-cli-things/create-extension)<a href="https://agentmods.dev/skills/poorgramer-zack/copilot-cli-things/create-extension"><img src="https://agentmods.dev/badge/skills/poorgramer-zack/copilot-cli-things/create-extension.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00056 | $0.01764 |
| Opus 5 | $0.00028 | $0.00882 |
| Sonnet 5 | $0.00011 | $0.00353 |
| Haiku 4.5 | $0.00006 | $0.00176 |
Grade A, and why
Create Extension scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Runs shell commandslowCapability
Expected in a hook, worth knowing in a rule or an instructions file.
- **Add imports** for any Node.js built-in modules (e.g., `child_process`, `fs`) How it starts
The opening of the file, as written. The whole thing — 195 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Create Copilot CLI Extension
Prerequisites
Extensions require experimental mode. Before creating or testing an extension, ensure it is active:
- Launch flag:
copilot --experimental - Slash command (persistent):
/experimentalinside a running session
Without experimental mode, extensions will not be discovered or loaded.
What is an Extension
An extension is a JavaScript (.mjs) child process that communicates with the Copilot CLI via JSON-RPC over stdio. Extensions can register custom tools, intercept lifecycle events via hooks, and subscribe to real-time session events.
Extensions can: register tools the agent calls, intercept/modify prompts and tool calls, inject hidden context, send messages programmatically, subscribe to events, control error handling.
Extensions cannot: render interactive UI, use console.log(), share tool names with other extensions, use TypeScript directly.
File Location
Project-level (per-repo):
<git-root>/.github/extensions/<name>/extension.mjs
User-level (global, all repos):
~/.copilot/extensions/<name>/extension.mjs
The file must be named extension.mjs. Only immediate subdirectories are scanned. Project extensions shadow user extensions on name collision.
Extension Lifecycle
- Discovery — CLI scans extension directories for subdirectories containing
extension.mjs - Launch — Each extension is forked as a child process with the SDK module resolver pre-configured
- Connection — Extension calls
joinSession()to establish JSON-RPC over stdio - Registration — Tools and hooks from session options are registered with the CLI
- Active — Extension responds to tool calls, hooks fire on events, session APIs are available
- Reload — Extensions are stopped and re-launched on
/clear,extensions_reload(), or session replacement - Shutdown — On CLI exit: SIGTERM, then SIGKILL after 5 seconds
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 195 lines · 56 tokens per session scan A 2bd338cd6d94
Create Extension is a skill published in the GitHub repository Poorgramer-Zack/copilot-cli-things (2 stars, last pushed 5mo ago), licensed MIT. It adds 56 tokens to every session and 1,764 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
speckit-init
Scaffold a Spec Kit (spec-driven development) project for GitHub Copilot by running specify init --integration copilot --integration-options="--skills". USE FOR: starting a new spec-kit project, bootstrapping spec-driven development in an existing repo, installing spec-kit templates/scripts/commands for Copilot. DO…
speckit-bundle
Discover, install, and author Spec Kit bundles via specify bundle. USE FOR: searching/showing/listing bundles, installing/updating/removing a bundle (a curated set of extensions/presets/integrations/workflows), validating a bundle manifest, building a distributable bundle artifact, initializing a project and…
speckit-extension
Manage Spec Kit extensions via specify extension. USE FOR: installing/removing/updating spec-kit extensions, searching the extension catalog, showing extension info, enabling/disabling extensions, setting extension resolution priority, managing extension catalogs. DO NOT USE FOR: presets (use speckit-preset), bundles…
speckit-preset
Manage Spec Kit presets via specify preset. USE FOR: installing/removing presets, searching the preset catalog, showing preset info, resolving which template a preset name maps to, enabling/disabling presets, setting preset resolution priority, managing preset catalogs. DO NOT USE FOR: extensions (use…
speckit-workflow
Manage and run Spec Kit automation workflows via specify workflow. USE FOR: running a workflow by ID or local YAML, resuming a paused/failed run, checking run status, listing/installing/removing workflows, searching the workflow catalog, showing a workflow step graph. DO NOT USE FOR: extensions (use…
speckit-check
Check the local environment for Spec Kit by running specify check (and specify version). USE FOR: verifying required tools are installed, diagnosing a broken spec-kit setup, reporting CLI version/feature capabilities. DO NOT USE FOR: installing or upgrading the CLI itself (use the speckit-self skill).