Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add PostHog/posthog-foss --skill claudegit clone --depth 1 https://github.com/PostHog/posthog-fossWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/posthog/posthog-foss/claude)<a href="https://agentmods.dev/skills/posthog/posthog-foss/claude"><img src="https://agentmods.dev/badge/skills/posthog/posthog-foss/claude/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/posthog/posthog-foss/claude"><img src="https://agentmods.dev/badge/skills/posthog/posthog-foss/claude.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium MCP Rug Pull · line 133 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00107 | $0.02562 |
| Opus 5 | $0.00053 | $0.01281 |
| Sonnet 5 | $0.00021 | $0.00512 |
| Haiku 4.5 | $0.00011 | $0.00256 |
Grade A, and why
upgrade-claude-adapter scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 176 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Upgrade the Claude ACP adapter (upstream sync)
This is a runbook for syncing our fork of @anthropic-ai/claude-agent-acp (the upstream
Zed/agentclientprotocol ACP agent) that lives in packages/agent/src/adapters/claude/ with a newer
upstream release. The fork is heavily diverged. The job is to port the valuable upstream changes
(SDK bumps, bug fixes, new SDK-message handling) while preserving every intentional divergence — not
to make the fork identical to upstream.
UPSTREAM.md (this directory) is the source of truth for the fork point, last-synced
version/commit, the file mapping, the PostHog-only code, and the intentional
divergences. Read it first, update it last.
This file is a runbook, not an auto-registered slash command. Invoke it by telling Claude to "follow the upgrade skill in the claude adapter dir." Move it to
.claude/skills/<name>/SKILL.mdif you ever want it runnable as/<name>.
Inputs you need before starting
- Upstream source checkout — a local git clone of
github.com/agentclientprotocol/claude-agent-acp. You need its history to diff. If the user hasn't given the path, ask for it (it's usually somewhere like~/Cloud/claude-agent-acp). Do not guess. - This repo — the fork under
packages/agent/.
Process
0. Orient (read, don't write)
- Read
UPSTREAM.md. Note Last sync (commit + version), the pinned SDK versions, the File Mapping, PostHog-Only Code (Do Not Sync), and Intentional Divergences. - In the upstream checkout, list the change set since the last sync and skim the changelog:
git -C <upstream> log --oneline <last-sync-sha>..HEADgit -C <upstream> show <upstream>/CHANGELOG.md:CHANGELOG.md(or just readCHANGELOG.md)
- Confirm the new target version + HEAD sha and the target SDK versions from the upstream
package.json.
1. Triage every commit
Bucket each commit since the last sync:
- Port — bug fixes and new feature / SDK-message handling that are not in the PostHog-only list and don't fight a divergence.
- Dep bump — record the target SDK versions; the diff tells you if code changes ride along.
- Skip —
chore(main): release …,actions/*CI bumps, pure dependabot dev-dep bumps, and anything matching the PostHog-only / divergence lists.
What ships with it
60 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- claude-agent.clear.test.ts 26 KB runs code
- claude-agent.finish.test.ts 3.6 KB runs code
- claude-agent.permission-mode.test.ts 6.2 KB runs code
- claude-agent.refresh.test.ts 30 KB runs code
- claude-agent.resume-model.test.ts 17 KB runs code
- claude-agent.side-question.test.ts 12 KB runs code
- claude-agent.slash-command.test.ts 9.0 KB runs code
- claude-agent.streamed-text.test.ts 24 KB runs code
- claude-agent.task-notification.test.ts 7.2 KB runs code
- claude-agent.ts 127 KB runs code
- claude-agent.turn-queue.test.ts 6.2 KB runs code
- context-breakdown.test.ts 3.8 KB runs code
- context-breakdown.ts 3.3 KB runs code
- conversion/acp-to-sdk.test.ts 7.3 KB runs code
- conversion/acp-to-sdk.ts 6.4 KB runs code
- conversion/sdk-to-acp.test.ts 19 KB runs code
- conversion/sdk-to-acp.ts 42 KB runs code
- conversion/task-state.test.ts 9.0 KB runs code
- conversion/task-state.ts 4.8 KB runs code
- conversion/tool-use-to-acp.test.ts 937 B runs code
- conversion/tool-use-to-acp.ts 24 KB runs code
- git-command.ts 1.3 KB runs code
- hooks.test.ts 22 KB runs code
- hooks.ts 16 KB runs code
- image-sanitization.ts 2.1 KB runs code
- machine-auth.ts 2.4 KB runs code
- mcp/local-tools.test.ts 4.2 KB runs code
- mcp/local-tools.ts 1.1 KB runs code
- mcp/tool-metadata.test.ts 4.0 KB runs code
- mcp/tool-metadata.ts 4.8 KB runs code
- permissions/permission-handlers.test.ts 24 KB runs code
- permissions/permission-handlers.ts 27 KB runs code
- permissions/permission-options.test.ts 1.8 KB runs code
- permissions/permission-options.ts 4.5 KB runs code
- plan/utils.test.ts 773 B runs code
- plan/utils.ts 1.2 KB runs code
- questions/utils.ts 2.2 KB runs code
- session/commands.test.ts 1.7 KB runs code
- session/commands.ts 1.4 KB runs code
- session/initialization.test.ts 3.8 KB runs code
- session/initialization.ts 3.7 KB runs code
- session/instructions.test.ts 3.0 KB runs code
- session/instructions.ts 7.3 KB runs code
- session/jsonl-hydration.bench.ts 2.0 KB runs code
- session/jsonl-hydration.test.ts 56 KB runs code
- session/jsonl-hydration.ts 23 KB runs code
- session/mcp-config.test.ts 5.5 KB runs code
- session/mcp-config.ts 7.1 KB runs code
- session/model-config.test.ts 2.1 KB runs code
- session/model-config.ts 1.8 KB runs code
- session/models.test.ts 10 KB runs code
- session/models.ts 8.8 KB runs code
- session/options.test.ts 34 KB runs code
- session/options.ts 28 KB runs code
- session/repo-path.ts 811 B runs code
- session/rtk.test.ts 7.2 KB runs code
- session/rtk.ts 6.3 KB runs code
- session/settings.test.ts 11 KB runs code
- session/settings.ts 15 KB runs code
- session/traceparent-hook.test.ts 2.4 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 176 lines · 107 tokens per session scan A 1f43068df984
upgrade-claude-adapter is a skill published in the GitHub repository PostHog/posthog-foss (715 stars, last pushed today), licensed MIT. It adds 107 tokens to every session and 2,562 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
prowler-commit
Creates professional git commits following conventional-commits format. Trigger: When creating commits, after completing code changes, when user asks to commit.
gh-auth-isolation
Safely manage multiple GitHub identities (EMU + personal) in agent workflows.
comet-github
A routing guide for Comet-related GitHub work. It directs requests about pull requests, issues, CI failures, ideas, and fixes to the appropriate review or implementation process.
github-skill
Work with GitHub via the gh CLI — clone repositories, create/list/merge pull requests, create/list issues, and run any other gh command (API calls, workflow runs, releases, repo administration). List operations return parsed JSON.
re0-merge
Review and land an external contribution the way this suite does: gate it against the thesis, land it with the author's credit intact, complete a new skill rather than merging it raw, then approve, credit, and explain before closing. Use when reviewing a pull request, as any collaborator or maintainer, not only the…
nvca-chart-release
Release NVCA Operator chart changes from the native monorepo source to the vendored Helm chart. Use when updating the vendored NVCA Operator chart, changing NVCA image refs, publishing helm-nvca-operator, or validating the chart against a self-managed control plane.