Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/qingye-lab/rootloom/setup-rootloomnpx skills add qingye-lab/rootloom --skill setup-rootloomgit clone --depth 1 https://github.com/qingye-lab/rootloomWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00087 | $0.01257 |
| Opus 5 | $0.00044 | $0.00629 |
| Sonnet 5 | $0.00017 | $0.00251 |
| Haiku 4.5 | $0.00009 | $0.00126 |
Grade A, and why
setup-rootloom scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 94 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Set up Rootloom Personal Core
Resolve this Skill directory and use its deterministic setup script.
Choose a preset
python3 <skill-dir>/scripts/setup_rootloom.py list-components
| Preset | Result |
|---|---|
skills-only |
Plugin Skills only; the project-guidance Hook is disabled |
guidance |
Global working agreement plus read-only project-context Hook |
personal |
Guidance plus optional Autonomy; recommended and default |
Exact capabilities are global-policy, project-context, and autonomy.
autonomy always includes global-policy because the Rules intentionally defer authorization mode and scope to that guidance. Legacy engineering and command-safety inputs remain compatibility aliases but are not recommended names.
Optional global layer
codex plugin add rootloom@rootloom completes the plugin installation. It exposes Rootloom Skills without writing global guidance, command Rules, setup state, or review gates. Stop there for the lowest-cost experience.
Only when the user explicitly wants cross-project guidance, the project-guidance Hook, or command Rules, inspect and install an optional preset:
python3 <skill-dir>/scripts/setup_rootloom.py plan --preset personal
python3 <skill-dir>/scripts/setup_rootloom.py install --preset personal
python3 <skill-dir>/scripts/setup_rootloom.py status
apply remains a compatibility/expert command. Prefer install for the first setup and upgrade after the Codex plugin snapshot has been refreshed.
The personal preset manages only:
~/.codex/AGENTS.md;~/.codex/rules/rootloom.rules;~/.codex/.rootloom/components.json;~/.codex/.rootloom/state.json, a pending transaction journal, and a simple backup manifest.
Setup is serialized by an ordinary local lock, refuses symlinked or user-owned targets, stages the complete target set before publishing a transaction journal, resumes interrupted staged work before the next mutating setup or rollback operation, writes each file atomically, and preserves original content and mode for rollback. Recovery refuses a target changed after interruption and does not claim hostile shared-filesystem locking.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 94 lines · 87 tokens per session scan A 9c2d1119758f
setup-rootloom is a skill published in the GitHub repository qingye-lab/rootloom (7 stars, last pushed 20d ago), licensed MIT. It adds 87 tokens to every session and 1,257 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
audit-onboarding-proposal
Independently audit a brownfield onboarding transcript, operational map, or exact proposed documentation patch before application. Use when a fresh reviewer must verify an $onboard-repository first pass, distinguish environment-caused Unknowns from reasoning defects, score its safety and evidence gates, or run a…
improve-harness
Run one explicitly authorized, evidence-backed improvement to a repository's agent guidance, tools, runbooks, or validation. Use only when the user invokes $improve-harness or explicitly asks to improve the Harness after observed reusable agent friction. Do not use for ordinary product changes, speculative cleanup…
ai-elements
Build AI chat interfaces using ai-elements components — conversations, messages, tool displays, prompt inputs, and more. Use when the user wants to build a chatbot, AI assistant UI, or any AI-powered chat interface.
red-team-adversarial
Adversarial security and resilience analysis — auto-triggered during /review and /test based on task classification. Provides attack surface analysis, boundary testing, auth bypass attempts, dependency chain attacks, and Beast Mode stress testing.
product-decision-agent
中文产品决策 Agent。用于中国大陆互联网产品、运营、增长、商业化、数据、项目推进和组织协作场景:产品规划、需求分析、PRD、需求优先级、排期、版本规划、Roadmap、MVP、灰度、上线、迭代、增长停滞、拉新、投放、渠道、裂变、CAC、LTV、ROI、留存、转化、DAU/MAU、GMV、漏斗、社区运营、内容供给、创作者、用户运营、活动运营、私域、会员、定价、指标异常、数据口径、埋点、A/B…
architecture-review
Use for clean architecture, modular monoliths, hexagonal boundaries, service boundaries, data flow, dependency direction, ADRs, or large feature planning.