Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add randommonicle/claude-skills --skill mass-red-triagegit clone --depth 1 https://github.com/randommonicle/claude-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/randommonicle/claude-skills/mass-red-triage)<a href="https://agentmods.dev/skills/randommonicle/claude-skills/mass-red-triage"><img src="https://agentmods.dev/badge/skills/randommonicle/claude-skills/mass-red-triage/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/randommonicle/claude-skills/mass-red-triage"><img src="https://agentmods.dev/badge/skills/randommonicle/claude-skills/mass-red-triage.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00110 | $0.00595 |
| Opus 5 | $0.00055 | $0.00298 |
| Sonnet 5 | $0.00022 | $0.00119 |
| Haiku 4.5 | $0.00011 | $0.00060 |
Grade A, and why
mass-red-triage scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 43 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Mass-red triage
Seven incidents where the correct first move was classification, not debugging: 105 reds that were throttling, ~80 reds off 3 real failures, "0 failed" beside an abnormal exit that was a truncated run, and every-spec-fails-in-seconds environment defects. Hours were lost debugging code for infrastructure artefacts — and the inverse error, trusting a truncated green, is worse.
The triage, in order
- Find the FIRST root failure. Worker-restart cascades multiply one fault into dozens; the timestamps and the first stack tell you which red is causal.
- Check for a rate-limit wall. A provider throttle masks the one real red behind it — always re-run to completion once the wall is identified.
- Check for truncation. "0 failed" beside an abnormal exit code or a short duration is not a pass; grep the counted summary lines, never trust the tail of the output.
- Check for an environment defect. Every spec failing in seconds at the same module line is one broken import or service, not many bugs.
- Bound the blast radius by evidence: the lockfile diff and the change diff say what could have broken; a red outside that bound is infrastructure until proven otherwise.
- Run the suite twice to split flake from regression, and update a lagging branch before judging its reds — a shared-state smoke fails on whatever PR is in flight.
- Instrument opaque failures: one
console.error(skipReason)beats reasoning in circles about why a spec is being skipped.
What this skill does not do
It does not make checks honest (prove-it-can-fail governs whether a check can fail truthfully) and does not fix the root cause — it gets you to the right root cause without burning hours on artefacts.
Why
Mass reds are usually one fault wearing many costumes, and the costumes are expensive to debug individually. Classification first converts a day of whack-a-mole into minutes of attribution. Evidence: PropOS LESSONS_LEARNED Sessions 29, 35 (two entries), 37, 40, 42, 48, 49.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 43 lines · 110 tokens per session scan A 76cfaeb46a16
mass-red-triage is a skill published in the GitHub repository randommonicle/claude-skills (23 stars, last pushed 6d ago), licensed Apache-2.0. It adds 110 tokens to every session and 595 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
4-phase root cause debugging: understand bugs before fixing.
langsmith-observability
LLM observability platform for tracing, evaluation, and monitoring. Use when debugging LLM applications, evaluating model outputs against datasets, monitoring production systems, or building systematic testing pipelines for AI applications.
experimental-code-coverage-local-debugger
Runs code coverage locally via Universal Test Runner (UTR) or helper scripts, mimicking LUCI trybots. Activate when CQ tryjobs fail or underreport coverage, to test local GN/recipe repairs before uploading, or to debug hermetic crashes.
adversarial-reviewer
Adversarial code review that assumes bugs exist and hunts for them. Use when asked to review code, find bugs, audit for correctness, stress-test a PR, or when someone says "tear this apart" or "what's wrong with this". Give no benefit of the doubt — every line is guilty until proven innocent.
cli-e2e
Write, modify, or debug Docker-based Composio CLI end-to-end tests under ts/e2e-tests/cli, including binary invocation, fixture isolation, output assertions, and package manifests. Use for CLI E2E test suites only; use cli-command for CLI source implementation.
work
Deliver one maintainer-approved EmDash issue, choosing the bug-fix path for a defect and the direct implementation path for an enhancement or task.