Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/random6913/claude-code-superkit/gan-generatornpx skills add RaNDoM6913/claude-code-superkit --skill gan-generatorgit clone --depth 1 https://github.com/RaNDoM6913/claude-code-superkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/random6913/claude-code-superkit/gan-generator)<a href="https://agentmods.dev/skills/random6913/claude-code-superkit/gan-generator"><img src="https://agentmods.dev/badge/skills/random6913/claude-code-superkit/gan-generator.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00040 | $0.01837 |
| Opus 5 | $0.00020 | $0.00919 |
| Sonnet 5 | $0.00008 | $0.00367 |
| Haiku 4.5 | $0.00004 | $0.00184 |
Grade A, and why
gan-generator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 170 lines — stays where its author put it; the contents beside it link to each section on GitHub.
GAN Generator
Step 2 of 3 in the GAN harness. Takes a plan from gan-planner and writes the production code + Playwright tests that satisfy it. Every scenario gets an implementation AND its own test. Codex CLI has no subagents: run this as the second of three skills in sequence — the planner's markdown plan is your input, and your hand-off note feeds the evaluator step.
Hard Rules
- NEVER
test.skip/xit/ disable a failing test to reach green — fix the code or the test. - NEVER mock the project's own backend in e2e tests; mock only external services and injected failures (e.g., route → 500).
- The happy-path persistence assertion (
page.reload()+ re-assert) is non-negotiable. - Implement ONLY what the plan scopes — no extra features, abstractions, or "improvements".
- Max 3 fix attempts per failing test; after the 3rd, stop and hand off
Local test result: FAILEDwith details — an honest FAILED beats a disabled test or an endless loop. - Every plan scenario gets both an implementation and its own
test()block.
Phase 0 — Load Plan
The input is a markdown plan from gan-planner. Read it carefully:
- Identify all scenarios (happy + edge + error + auth)
- Identify the file list (what to modify, what to create)
- Identify the test file location
- Identify the anti-slop checklist (the plan's
## Rubricsection is forgan-evaluator— pass it through untouched)
If anything in the plan is ambiguous → STOP and ask for clarification. Do NOT guess.
Workflow
Step 1: Implement the code
For each file in the plan's "Files to be modified" list:
- Read the existing file (if it exists)
- Apply the smallest change that fulfills the scenarios (
minimal-change-engineerdiscipline: no drive-by refactors, no new abstractions for a single use) - Do NOT add extra abstractions, features, or "improvements" not in the plan
- Keep imports tidy
Step 2: Write Playwright tests
For each scenario, write a single test() block:
import { test, expect } from '@playwright/test';
test.describe('<feature>', () => {
test('happy path — user creates a post', async ({ page }) => {
// Given
await loginAs(page, '[email protected]');
await page.goto('/posts');
// When
await page.getByRole('button', { name: 'New post' }).click();
await page.getByLabel('Title').fill('Hello world');
await page.getByLabel('Body').fill('First post content');
await page.getByRole('button', { name: 'Publish' }).click();
// Then
await expect(page.getByText('Hello world')).toBeVisible({ timeout: 2000 });
await expect(page).toHaveURL(/\/posts\/\w+/);
// Persistence assertion
await page.reload();
await expect(page.getByText('Hello world')).toBeVisible();
});
test('empty state — no posts shown to first-time user', async ({ page }) => {
await loginAs(page, '[email protected]');
await page.goto('/posts');
await expect(page.getByText(/no posts yet/i)).toBeVisible();
});
test('error state — graceful failure on server error', async ({ page }) => {
await page.route('**/api/posts', r => r.fulfill({ status: 500 }));
await loginAs(page, '[email protected]');
await page.goto('/posts');
await expect(page.getByText(/something went wrong/i)).toBeVisible();
});
test('auth-required — redirect to login when unauthenticated', async ({ page }) => {
await page.goto('/posts');
await expect(page).toHaveURL(/\/login/);
});
});
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 170 lines · 40 tokens per session scan A c1d6d1fc7b06
gan-generator is a skill published in the GitHub repository RaNDoM6913/claude-code-superkit (2 stars, last pushed 1mo ago), licensed MIT. It adds 40 tokens to every session and 1,837 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
apm-review-panel
Use this skill to run a multi-persona expert advisory review on a labelled pull request in microsoft/apm. The panel fans out to five mandatory specialists plus a test-coverage specialist (active on every PR that touches src/) plus three conditional specialists (auth, doc-writer, performance-expert), all running in…
apm-issue-autopilot
Use this skill to drive any open microsoft/apm issue (bug, feature, docs, refactor, perf) from raw intake to a mergeable PR with triage as the central, paramount gate. Run the apm-triage-panel rubric per issue first, then present ONE consolidated triage review for the whole batch and escalate to the maintainer BY…
apm-spec-guardian
Use this skill to run a four-panel adversarial advisory review on any pull request that touches the OpenAPM specification artifact (docs/src/content/docs/specs/openapm-.md), its inline / sidecar JSON Schemas (docs/src/content/docs/specs/schemas/.schema.json), or the conformance fixture seed…
apm-triage-panel
Use this skill to triage one microsoft/apm issue selected by the daily sweep, the status/needs-triage fast path, or manual dispatch. Emit one synthesized comment with a decision, label set, exact milestone, and suggested next action.
cli-logging-ux
Use this skill when editing or creating CLI output, logging, warnings, error messages, progress indicators, or diagnostic summaries in the APM codebase. Activate whenever code touches console helpers (richsuccess, richwarning, richerror, richinfo, richecho), DiagnosticCollector, STATUSSYMBOLS, CommandLogger, or any…
pr-description-skill
Use this skill to write the PR description (PR body) for any pull request opened against microsoft/apm. Produces one self-sufficient GitHub-Flavored Markdown artifact: TL;DR, Problem (WHY), Approach (WHAT), Implementation (HOW), 1-3 validated mermaid diagrams, explicit trade-offs, validation evidence, and a…