Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/rabithua/feedbackserverplugin/triage-feedbacknpx skills add Rabithua/FeedbackServerPlugin --skill triage-feedbackgit clone --depth 1 https://github.com/Rabithua/FeedbackServerPluginWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00060 | $0.00390 |
| Opus 5 | $0.00030 | $0.00195 |
| Sonnet 5 | $0.00012 | $0.00078 |
| Haiku 4.5 | $0.00006 | $0.00039 |
Grade A, and why
triage-feedback scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Triage FeedbackServer feedback
Identify the Product first. If none is named, list Products; auto-select only one unambiguous result,
otherwise ask. Pass explicit Product and entity IDs to later tools. Follow nextCursor until the
requested range is complete.
Keep internal notes, client context, Visitor credentials, and diagnostic data private. Generate an
attachment URL only when explicitly asked to open or download it. Diagnostic bundles are more
sensitive: call get_diagnostic_bundle_url only for an explicit inspection or download request.
Explicit requests to reply, add an internal note, link, update, publish, or delete authorize the corresponding tool. Drafting, reviewing, planning, previewing, or summarizing do not authorize a write. Public Feedback exposes the body, attachments, author display code, and non-internal conversation as one unit; diagnostics and internal notes remain private.
Protected changes return confirmation_required. Show the Product, entity, visible text or status,
and public/deletion effect from the redacted preview. After explicit approval call
execute_confirmation({ confirmationId }); never reconstruct the original parameters. If the ID
expires, is replayed, or the precondition is stale, reread current state and prepare a new preview.
Never automatically retry a write. Public replies must be shown in full before sending.
Preserve error status, code, message, request ID, retry guidance, and remediation. On 401 route to
$setup-feedback-server; on 403 report the missing access and stop. Never ask for a token in chat.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 29 lines · 60 tokens per session scan A 8834c8060408
triage-feedback is a skill published in the GitHub repository Rabithua/FeedbackServerPlugin (0 stars, last pushed 3d ago), licensed MIT. It adds 60 tokens to every session and 390 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
tsq-retro
피드백 수집, KPT 회고, 개선 적용까지 전체 회고 사이클을 관리하는 스킬. Use when: /tsq-retro 호출 시, 피드백 기록 시, Phase 완료 후 회고 시, 패턴 분석 시, 개선 사항 적용 시, "피드백", "회고", "개선", "retro", "feedback", "improve" 언급 시.
feedback-prioritizer
Triages a backlog of raw customer feedback into a ranked list of opportunities scored on reach, severity, strategic fit, and confidence. Outputs a prioritized list with explicit "do not act" callouts for vocal-minority signals. Use when: triage feedback, prioritize feature requests, customer feedback backlog, what…
babysit
Same-session monitoring loop for PRs, CI runs, tickets, and deployments using the monitorstart / monitorupdate / autonudgestop MCP tools. The loop re-injects your check instructions into THIS session on an idle interval — same context, same tools — and works from dashboard chat, Slack threads, and Discord DMs. Use…
agile-product-owner
../../../product-team/agile-product-owner/skills/agile-product-owner/SKILL.md.
teamharness-task-delegation
Use when a Leader turns ready Quick Task or Project Work state into Worker task instructions, sends assignment messages, checks submitted results, and defines completion/blocker report contracts. Do not use to create projects, create rooms, or execute Worker tasks.
github-workflow
Use GitHub workflow tools to read work status, draft reports, summarize follow-ups, and execute only approved issue mutations.