Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/raccioly/docguard/docguard-fixnpx skills add raccioly/docguard --skill docguard-fixgit clone --depth 1 https://github.com/raccioly/docguardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/raccioly/docguard/docguard-fix)<a href="https://agentmods.dev/skills/raccioly/docguard/docguard-fix"><img src="https://agentmods.dev/badge/skills/raccioly/docguard/docguard-fix.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00045 | $0.02318 |
| Opus 5 | $0.00023 | $0.01159 |
| Sonnet 5 | $0.00009 | $0.00464 |
| Haiku 4.5 | $0.00005 | $0.00232 |
Grade A, and why
docguard-fix scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 230 lines — stays where its author put it; the contents beside it link to each section on GitHub.
DocGuard Fix Skill
User Input
$ARGUMENTS
You MUST consider the user input before proceeding (if not empty).
If user specifies --doc <name>, focus on that single document.
If no arguments, fix ALL issues found by docguard diagnose.
Goal
Research the actual codebase to generate or repair canonical documentation that passes DocGuard's 19-validator guard suite. This skill replaces generic templates with real, project-specific content and iterates until quality checks pass.
Operating Constraints
- NEVER use placeholder content — every section must reference real files, real modules, real dependencies
- ALWAYS back up before overwriting — use
safeWrite()pattern or create.bakfiles - Maximum 3 validation iterations — if still failing after 3 rounds, report remaining issues and stop
- Research before writing — understand the codebase first, then generate documentation
Execution Flow
Step 0: Apply Mechanical Fixes First (no AI needed)
npx docguard-cli fix --write 2>&1
Removes endpoints documented in docs-canonical/API-REFERENCE.md that the OpenAPI
spec confirms no longer exist (table row + detail block). Only edits
docguard:generated docs, idempotent, prints what changed. Don't hand-edit these.
Step 1: Diagnose Current State
Run the diagnostic to identify all issues (each tagged mechanical or agent):
npx docguard-cli diagnose 2>&1
Parse the output to build an issue inventory:
| Issue ID | Severity | Category | File | Description | Autofix? |
|---|---|---|---|---|---|
| I001 | ERROR | Structure | SECURITY.md | Missing file | Yes |
| I002 | WARN | Freshness | ARCHITECTURE.md | 5 commits behind | Yes |
| ... | ... | ... | ... | ... | ... |
If $ARGUMENTS contains --doc <name>, filter to only issues affecting that document.
Step 2: Prioritize Fix Order
Sort issues by fix dependency and impact:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 230 lines · 45 tokens per session scan A 3360a857df26
docguard-fix is a skill published in the GitHub repository raccioly/docguard (27 stars, last pushed 3d ago), licensed MIT. It adds 45 tokens to every session and 2,318 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
EU AI Act Documentation
What compliance documentation to produce under the EU AI Act — Annex IV technical documentation, EU declaration of conformity, risk-management file, data-governance records, and GPAI training-data summary — and how to structure it.
golden-rss
Use when testing the rss golden build.
golden-chat-topics
Use when testing the goldenchattopics golden build.
golden-chat-single
Use when testing the goldenchatsingle golden build.
decided-import
Reformat ONE existing document (a decision, requirement, design, roadmap, or prompt) into ONE valid RAC (requirements-as-code) artifact, with a mandatory human-review step before any file is written and decided validate as the deterministic close. Use when a user wants to add or import a single existing decision or…
keep-the-why
Extract and preserve the reasoning code cannot explain - decisions, rejected alternatives, workarounds, incidents, constraints - plus project setup/decline and maintainer interviews. Not for what changed (see Keep a Changelog) - only why.