Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/recca0120/code-quest/zod-validationnpx skills add recca0120/code-quest --skill zod-validationgit clone --depth 1 https://github.com/recca0120/code-questWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00051 | $0.01786 |
| Opus 5 | $0.00026 | $0.00893 |
| Sonnet 5 | $0.00010 | $0.00357 |
| Haiku 4.5 | $0.00005 | $0.00179 |
Grade A, and why
zod-validation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 196 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Zod v4 Validation Reference
v4 vs v3 Key Differences (IMPORTANT)
| Area | v3 | v4 |
|---|---|---|
| Error params | message, invalid_type_error, required_error |
Single error param |
| Native enum | z.nativeEnum(Enum) |
z.enum(Enum) (absorbed) |
| Strict object | .strict() |
z.strictObject({}) or .strict() (both work) |
| Passthrough | .passthrough() |
z.looseObject({}) or .passthrough() (both work) |
| Deep partial | .deepPartial() |
Removed — use nested .optional() |
| Type generics | ZodType<O, D, I> (3 params) |
ZodType<O, I> (2 params) |
| Infinite numbers | Passed z.number() |
Now rejected |
_def internal |
schema._def |
schema._zod.def |
Type Inference
const Schema = z.object({ name: z.string(), age: z.number().optional() });
type Input = z.input<typeof Schema>; // before coercion/transform
type Output = z.output<typeof Schema>; // after coercion/transform (same as z.infer)
type T = z.infer<typeof Schema>; // alias for z.output
Use z.input for form data (raw), z.output / z.infer for processed data.
Parse Patterns
// Throws ZodError on failure
const data = Schema.parse(input);
// Safe — always returns, never throws
const result = Schema.safeParse(input);
if (result.success) {
result.data; // typed output
} else {
result.error; // ZodError (NOTE: ZodError no longer extends Error in v4)
}
Prefer safeParse in request handlers and form submission paths.
Custom Error Messages (v4 API)
// v4: use `error` param (NOT message/invalid_type_error/required_error)
z.string({ error: "Name is required" })
z.string().min(3, { error: "Too short" })
// Error map function
z.string({ error: (issue) => issue.input === undefined ? "Required" : "Invalid" })
Schema Composition
// Extend / merge
const Base = z.object({ id: z.string() });
const Extended = Base.extend({ name: z.string() });
// Pick / Omit
const Partial = Extended.pick({ name: true });
// Discriminated union (preferred over z.union for objects)
const Event = z.discriminatedUnion("type", [
z.object({ type: z.literal("click"), x: z.number(), y: z.number() }),
z.object({ type: z.literal("keydown"), key: z.string() }),
]);
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 196 lines · 51 tokens per session scan A b672ed62e613
zod-validation is a skill published in the GitHub repository recca0120/code-quest (11 stars, last pushed 2mo ago), licensed MIT. It adds 51 tokens to every session and 1,786 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…