Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/raccioly/docguard/docguard-guardnpx skills add raccioly/docguard --skill docguard-guardgit clone --depth 1 https://github.com/raccioly/docguardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/raccioly/docguard/docguard-guard)<a href="https://agentmods.dev/skills/raccioly/docguard/docguard-guard"><img src="https://agentmods.dev/badge/skills/raccioly/docguard/docguard-guard.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00053 | $0.01590 |
| Opus 5 | $0.00026 | $0.00795 |
| Sonnet 5 | $0.00011 | $0.00318 |
| Haiku 4.5 | $0.00005 | $0.00159 |
Grade A, and why
docguard-guard scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 174 lines — stays where its author put it; the contents beside it link to each section on GitHub.
DocGuard Guard Skill
User Input
$ARGUMENTS
You MUST consider the user input before proceeding (if not empty).
Goal
Execute DocGuard's full guard validator suite against the current project, parse structured results, triage findings by severity and impact, and produce an actionable remediation plan. This skill transforms raw CLI output into an AI-digestible quality assessment.
Pre-Execution Checks
-
Verify DocGuard is available:
- Check if
npx docguard-cli --versionsucceeds - If not available, check if
node cli/docguard.mjs --helpexists (local dev mode) - If neither works: ERROR "DocGuard CLI not found. Install with: npm i -g docguard-cli"
- Check if
-
Detect project root:
- Look for
.docguard.json,docs-canonical/, orCHANGELOG.mdas project markers - If none found: ERROR "No CDD project detected. Run
docguard initfirst."
- Look for
Execution Flow
Step 1: Run Guard with Machine-Readable Output
Execute the guard command and capture full output:
npx docguard-cli guard 2>&1
If in a DocGuard development environment (cli/docguard.mjs exists), use:
node cli/docguard.mjs guard 2>&1
Step 2: Parse Validator Results
Extract from guard output each validator's status. Build an internal results table:
| Validator | Priority | Checks Passed | Total Checks | Status |
|---|---|---|---|---|
| Structure | HIGH | N | M | ✅/⚠️/❌ |
| Doc Sections | HIGH | N | M | ✅/⚠️/❌ |
| ... | ... | ... | ... | ... |
Status mapping:
✅= All checks passed⚠️= Warning (non-blocking, but should fix)❌= Failure (blocking — must fix before commit)
Step 3: Severity Triage
Classify every non-passing check using this priority matrix:
CRITICAL (fix immediately):
- Structure failures (missing canonical docs)
- Security failures (hardcoded secrets, missing SECURITY.md)
- Test-Spec failures (tests don't match spec)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 174 lines · 53 tokens per session scan A 2a226f0305f2
docguard-guard is a skill published in the GitHub repository raccioly/docguard (27 stars, last pushed yesterday), licensed MIT. It adds 53 tokens to every session and 1,590 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
EU AI Act Documentation
What compliance documentation to produce under the EU AI Act — Annex IV technical documentation, EU declaration of conformity, risk-management file, data-governance records, and GPAI training-data summary — and how to structure it.
golden-rss
Use when testing the rss golden build.
golden-chat-topics
Use when testing the goldenchattopics golden build.
golden-chat-single
Use when testing the goldenchatsingle golden build.
decided-import
Reformat ONE existing document (a decision, requirement, design, roadmap, or prompt) into ONE valid RAC (requirements-as-code) artifact, with a mandatory human-review step before any file is written and decided validate as the deterministic close. Use when a user wants to add or import a single existing decision or…
keep-the-why
Extract and preserve the reasoning code cannot explain - decisions, rejected alternatives, workarounds, incidents, constraints - plus project setup and maintainer interviews. Not for what changed (see Keep a Changelog) - only why.