Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add pssah4/digital-innovation-agents --skill dia-setupgit clone --depth 1 https://github.com/pssah4/digital-innovation-agentsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pssah4/digital-innovation-agents/dia-setup)<a href="https://agentmods.dev/skills/pssah4/digital-innovation-agents/dia-setup"><img src="https://agentmods.dev/badge/skills/pssah4/digital-innovation-agents/dia-setup/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/pssah4/digital-innovation-agents/dia-setup"><img src="https://agentmods.dev/badge/skills/pssah4/digital-innovation-agents/dia-setup.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00093 | $0.02761 |
| Opus 5 | $0.00046 | $0.01380 |
| Sonnet 5 | $0.00019 | $0.00552 |
| Haiku 4.5 | $0.00009 | $0.00276 |
Grade A, and why
dia-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 258 lines — stays where its author put it; the contents beside it link to each section on GitHub.
DIA Setup
This skill is the activation and configuration entry point for the
Digital Innovation Agents plugin in a user project. It manages a
single configuration file (.dia/config.toml) and a set of anchor
blocks in agent-facing files. It does not run any phase skill, does
not read or modify the backlog, and does not invoke flow.py. The
only external command it may run is a read-only gh project view
reachability check when the user configures a GitHub Project number.
The skill is split into two paths driven by a single check at the
start: does .dia/config.toml already exist? If no, run the
activation flow. If yes, run the reconfigure flow.
Modes
The plugin supports three modes, written into .dia/config.toml as
the field mode:
off: plugin is neutral. Anchor blocks are removed from agent-facing files, the SessionStart hook does not inject the bootstrap skill, and phase-skills that probe the mode skip their GitHub-side calls.git-only: anchor blocks are present, the SessionStart hook injects the bootstrap, the local git hooks (pre-commit, pre-merge-commit) andscripts/merge-to-dev.share recommended. No GitHub issue or PR synchronization.github-sync: asgit-only, plusflow.pyis invoked from phase-skills to mirror backlog state to GitHub issues and project cards, runpromote-to-epicafter requirements engineering, and keep status in sync.
Activation flow (no .dia/config.toml yet)
- Mode question. Use
AskUserQuestionwith three options:git-only(recommended for most projects with a single developer),github-sync(recommended for teams that already work with GitHub Issues / Projects),off(recommended when the user wants to install the plugin without active behavior). Each option must list a+ Pro:line and a- Con:line in its description per the project User Interaction Protocol.
1b. Profile question (only if mode != off). Use
AskUserQuestion with two options:
full(Recommended for a complete V-Model cycle): every phase skill is binding as written.lean("only durable decisions and stable navigation"): rules consolidated in AGENTS.md with CLAUDE.md as pointer,_devprocess/SYSTEM-MAP.md, post-hoc ADRs behinddecisions/README.md, status in GitHub Issues (github-sync) or a thin BACKLOG (git-only). All other phase skills stay available but advisory. Modeled on a downstream project; pick it when the team will not run BA/RE ceremony anyway.
What ships with it
7 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 258 lines · 93 tokens per session scan A 55e6e631fb3c
dia-setup is a skill published in the GitHub repository pssah4/digital-innovation-agents (39 stars, last pushed 29d ago), licensed MIT. It adds 93 tokens to every session and 2,761 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
prowler-ui
Prowler UI-specific patterns. For generic patterns, see: typescript, react-19, nextjs-16, tailwind-4. Trigger: When working inside ui/ on Prowler-specific conventions (shadcn, folder placement, actions/adapters, shared types/hooks/lib).
prowler-pr
Creates Pull Requests for Prowler following the project template and conventions. Trigger: When working on pull request requirements or creation (PR template sections, PR title Conventional Commits check, changelog gate/no-changelog label), or when inspecting PR-related GitHub workflows like conventional-commit.yml…
prowler-test-api
Testing patterns for Prowler API: JSON:API, Celery tasks, RLS isolation, RBAC. Trigger: When writing tests for api/ (JSON:API requests/assertions, cross-tenant isolation, RBAC, Celery tasks, viewsets/serializers).
tailwind-4
Tailwind CSS 4 patterns and best practices. Trigger: When styling with Tailwind (className, variants, cn()), especially when dynamic styling or CSS variables are involved (no var() in className).
prowler-commit
Creates professional git commits following conventional-commits format. Trigger: When creating commits, after completing code changes, when user asks to commit.
prowler-docs
Prowler documentation style guide and writing standards. Trigger: When writing documentation for Prowler features, tutorials, or guides.