Borrowing it
Nothing to install: this file belongs to RichardGeorgeDavis/Codex-Workspace. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/RichardGeorgeDavis/Codex-Workspace/main/.agents/skills/repo-onboarding/SKILL.mdgit clone --depth 1 https://github.com/RichardGeorgeDavis/Codex-WorkspaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/richardgeorgedavis/codex-workspace/repo-onboarding)<a href="https://agentmods.dev/skills/richardgeorgedavis/codex-workspace/repo-onboarding"><img src="https://agentmods.dev/badge/skills/richardgeorgedavis/codex-workspace/repo-onboarding/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/richardgeorgedavis/codex-workspace/repo-onboarding"><img src="https://agentmods.dev/badge/skills/richardgeorgedavis/codex-workspace/repo-onboarding.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00025 | $0.00326 |
| Opus 5 | $0.00013 | $0.00163 |
| Sonnet 5 | $0.00005 | $0.00065 |
| Haiku 4.5 | $0.00003 | $0.00033 |
Grade A, and why
repo-onboarding scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Repo Onboarding
Use this skill when adding a repo under repos/ or making an existing repo workspace-ready.
Checklist
- Classify the repo conservatively from files first.
- Add or refine
.workspace/project.jsononly if runtime behavior is not obvious. - Ensure
README.mdexists. If it is missing, start fromtools/templates/repo-docs/README.template.md. - Make sure the README explains setup, run, preview, and current repo purpose.
- Add a repo-local cover block that points to a PNG path such as
docs/cover.png, using the placeholder template until a real capture exists. - Add repo-level
AGENTS.mdonly when repo-specific rules are genuinely needed. - If the repo needs Codex-visible capabilities, use
.codex/skills/. - Add
.agents/skills/only when the repo also benefits from a tracked compatibility mirror. - If the repo needs broader multi-tool agent hints, use
.workspace/agent-stack.json.
Helpful commands
tools/scripts/bootstrap-repo.sh
tools/scripts/init-agents-tree.sh repos/<repo>
tools/scripts/sync-codex-skills.sh repos/<repo>
Good defaults
- Frontend-style repos default to
direct. - WordPress repos usually stay
external. - Agent tooling should be scaffolded as tracked files, not hidden state.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 35 lines · 25 tokens per session scan A 4a0f5f0da92e
repo-onboarding is a skill published in the GitHub repository RichardGeorgeDavis/Codex-Workspace (2 stars, last pushed 1mo ago), licensed MIT. It adds 25 tokens to every session and 326 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
recipe-create-meet-space
Create a Google Meet meeting space and share the join link.
workthreads
SpecStory Workthreads - a weekly work-thread rollup across a team's repos from SpecStory coding histories (any agent - Claude Code, Codex, Cursor, Gemini, and more). It groups the window's sessions into threads of work per project and labels each new / open / recently closed, so a lead sees what shipped, what is still…
atmos-config
Atmos root configuration: atmos.yaml discovery, precedence, deep merging, basepath, imports, minimal bootstrap, and routing to narrower Atmos skills.
magpie-security-issue-import-from-md
Open one or more tracking issues from a markdown file containing a batch of security findings. Each finding becomes one tracker landing in the Needs triage board column. The file itself is the full report — there is no inbound reporter to reply to and no PR to inspect.
remove
Remove a deployed framework or addon from the current workspace.
handle-linkedin-connection-request-signal
Use this skill when someone sends a team member an inbound LinkedIn connection request. An inbound request is a deliberate, ACTIVE first-party intent signal — meaningfully stronger than a passive profile view — and it deserves different scoring rules. The skill resolves and enriches the requester, gates them through…