Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add qarium/goga --skill goga-toolgit clone --depth 1 https://github.com/qarium/gogaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/qarium/goga/goga-tool)<a href="https://agentmods.dev/skills/qarium/goga/goga-tool"><img src="https://agentmods.dev/badge/skills/qarium/goga/goga-tool/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/qarium/goga/goga-tool"><img src="https://agentmods.dev/badge/skills/qarium/goga/goga-tool.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00007 | $0.00335 |
| Opus 5 | $0.00003 | $0.00168 |
| Sonnet 5 | $0.00001 | $0.00067 |
| Haiku 4.5 | $0.00001 | $0.00034 |
Grade A, and why
goga-tool scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a command dispatcher. The user invoked a command with argument: $ARGUMENTS
Dispatch Logic
Argument extraction:
- Take the exact value of the $ARGUMENTS variable. Call it TARGET_TOOL.
- Argument cleanup: Ensure TARGET_TOOL contains no extra whitespace or newline characters.
- Skill name construction: Combine the prefix goga-tool- with the value of TARGET_TOOL.
Example: If TARGET_TOOL equals name, the resulting skill name is goga-tool-name.
Skill invocation: Find the skill named goga-tool-{TARGET_TOOL} in your knowledge base or the project file system and strictly follow its instructions as if the user had invoked it directly. Pass the current task context to this skill.
Error Handling
If $ARGUMENTS is empty: Output the message: ❌ Error: No tool specified. Use the syntax /goga:tool . Example: /goga:tool name
If skill goga-tool-{TARGET_TOOL} is not found: Output the message: ❌ Skill goga-tool-{TARGET_TOOL} not found. Check the tool name or ensure the skill file exists.
Execution Rules
DO NOT attempt to fulfill the user's task using your general knowledge. You MUST delegate execution to the target skill goga-tool-{TARGET_TOOL}.
Use the Skill tool to invoke skills.
If the skill is found:
- begin your response with: Skill goga-tool-{TARGET_TOOL} activated
- invoke skill
goga-cell - invoke skill
goga-cookbook - invoke skill
goga-tool-{TARGET_TOOL}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 35 lines · 7 tokens per session scan A e16620bcf0b4
goga-tool is a skill published in the GitHub repository qarium/goga (29 stars, last pushed 3d ago), licensed BSD-3-Clause. It adds 7 tokens to every session and 335 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
doubt-driven-review
In-flight adversarial check on a non-trivial decision BEFORE it stands — distinct from post-hoc review of a finished diff. Use on "stress-test this decision", "are we sure about this", "verify before commit", "poke holes in this", when working in unfamiliar code, or before an irreversible step (migration, prod deploy…
release-cut
Cut a new pi-agent-dashboard release: promote ## [Unreleased] in CHANGELOG.md, bump every workspace package.json per SemVer, commit, tag v , and push — triggering the Release workflow that publishes every non-private workspace, builds the Electron artifacts, and creates a GitHub Release. Use on "cut a release"…
spec-coherence-check
Sweep all active OpenSpec proposals for staleness, conflicts, and obsolescence against the current codebase and archived changes. Use when proposals may be outdated, when checking cross-proposal conflicts, or before starting a batch of implementations. Produces a gap-analysis report, updates a priority queue file, and…
ship-it
Worktree-side implementation orchestrator for an OpenSpec change. Idempotent: gates automated scenarios on filesystem reality, owns the red-test fix loop, runs the docker harness with always-teardown, then drives ship-change inline. Escape hatch writes SHIPITBLOCKED.md. Runnable headless. Triggers: "ship it", "build…
faq-mine
Mine docs/faq.md from README.md, docs/.md, and the pi-hermes memory stores. Dispatches @fast subagents per source, dedupes against the existing FAQ, and merges entries in caveman style. Use when asked to "build / regenerate / extend the FAQ", "mine docs into FAQ", "mine hermes memory into FAQ", "surface runtime…
session-to-guideline
Turn a pi session into a Markdown "how-we-did-it" collaboration guideline: reads the session's JSONL transcript and synthesizes a reusable playbook of which prompts worked, what had to be steered, and how to reproduce the result faster. Use when: "document this session", "write up how we did X with the AI", "make a…