Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add qarium/goga --skill goga-accept-usage-reviewgit clone --depth 1 https://github.com/qarium/gogaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/qarium/goga/goga-accept-usage-review)<a href="https://agentmods.dev/skills/qarium/goga/goga-accept-usage-review"><img src="https://agentmods.dev/badge/skills/qarium/goga/goga-accept-usage-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/qarium/goga/goga-accept-usage-review"><img src="https://agentmods.dev/badge/skills/qarium/goga/goga-accept-usage-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00018 | $0.00747 |
| Opus 5 | $0.00009 | $0.00374 |
| Sonnet 5 | $0.00004 | $0.00149 |
| Haiku 4.5 | $0.00002 | $0.00075 |
Grade A, and why
goga-accept-usage-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 95 lines — stays where its author put it; the contents beside it link to each section on GitHub.
goga-accept-usage-review
Identity
You are responsible for validating cell-level usage files against actual implementation during acceptance: verifying example accuracy and API description completeness.
Key Principle
You compare usages against actual implementation, update cell-level usages when necessary, and record discrepancies in project usages without modifying them.
Algorithm
Step 1. Load context
- Load the Acceptance Scope Report
- For each cell from the Acceptance Scope Report:
a. Load CODEMANIFEST
b. Load implementation files
c. Load all cell-level usages:
<cell_path>/.usages/*.mdd. Load all project usages referenced by the cell via theUsagesdirective (files from.goga/usages/)
Step 2. Analyze cell-level usages
Question: How accurately do cell-level usages describe the cell facade API for the consumer?
Cell-level usages (.usages/*.md) are consumer-facing documentation for the cell facade API. They describe ready-to-use facade usage patterns.
For each file in <cell_path>/.usages/*.md:
- Example validity: Do the usage examples work with the current cell facade API?
- Description accuracy: Do parameter descriptions, signatures, and behavior match the actual API?
- Entity name alignment: Do entity names in the usage match signatures in CODEMANIFEST?
- Coverage completeness: Are all key facade usage scenarios documented?
- Self-sufficiency: Can the consumer understand the pattern without reading the cell source code?
- No duplication: Does the usage avoid duplicating CODEMANIFEST annotations? (Usage describes how to use, not what to implement)
For each discrepancy — update the cell-level usage file.
Step 3. Analyze project usages
Question: Are the project usages referenced by the cell accurate?
Project usages (.goga/usages/) are shared practice documents: libraries, tools, conventions. The agent does not refactor project usages — only records issues.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 95 lines · 18 tokens per session scan A aa6a3e7b3b25
goga-accept-usage-review is a skill published in the GitHub repository qarium/goga (29 stars, last pushed 3d ago), licensed BSD-3-Clause. It adds 18 tokens to every session and 747 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
scenario-design
Draft real-life test SCENARIOS (not smoke tests) from a change/feature spec. Derives edge-case, performance, frontend-quirk and error-handling scenarios with ISTQB techniques, routes each to a test level, and writes test-plan.md, emitting clarification questions on a spec gap. Use on "design test scenarios", "what…
run-dashboard-e2e-local-changes
Run Playwright E2E (tests/e2e/) against the docker/ all-in-one harness so it reflects LOCAL code changes, not a stale cached image.
rn-testing
This skill should be used when the user asks to "write a Maestro test", "create E2E flows", "add testIDs", "run UI tests", "run E2E tests", "verify a feature works", "test my screen", "set up maestro-runner", "mock network requests", "inspect store state", "write test assertions", or needs guidance on test timing…
capturing-proof
This skill should be used when the user asks to "capture proof", "record a demo of this feature", "make a video showing it works", "record the flow for the PR", "generate a PR body", "capture screenshots for the PR", "proof-capture", or when a verified feature needs PR-ready proof artifacts (video + numbered…
run-action
Explicit Codex workflow: Execute a learned Maestro flow ("action") by name with optional -e KEY=VALUE parameters. Looks the flow up via packages/rn-dev-agent-core/dist/learned-actions.js (same inventory as $rn-dev-agent:list-learned-actions), then replays it via cdprunaction — auto-repair-aware orchestration with…
build-and-test
Explicit Codex workflow: Build the Expo/React Native app (local or EAS), install it, start Metro, then test a requested feature end-to-end.