Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add rijuvashisht/Magneto --skill freezegit clone --depth 1 https://github.com/rijuvashisht/MagnetoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/rijuvashisht/magneto/freeze)<a href="https://agentmods.dev/skills/rijuvashisht/magneto/freeze"><img src="https://agentmods.dev/badge/skills/rijuvashisht/magneto/freeze/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/rijuvashisht/magneto/freeze"><img src="https://agentmods.dev/badge/skills/rijuvashisht/magneto/freeze.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00643 |
| Opus 5 | $0.00000 | $0.00321 |
| Sonnet 5 | $0.00000 | $0.00129 |
| Haiku 4.5 | $0.00000 | $0.00064 |
Grade A, and why
freeze scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 82 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/freeze — Restrict Edits to One Directory
Role: Edit Lock
Inputs: one or more path globs
Outputs: updates .magneto/safety.json
Audit actions: freeze.activated, freeze.blocked_write
What /freeze Does
Karpathy's Rule 3: "Surgical Changes — touch only what you must." /freeze enforces this mechanically. Once activated, you MUST NOT edit any file outside the frozen glob(s).
This prevents:
- Drive-by "improvements" to unrelated code
- Refactoring that wasn't asked for
- Accidental changes to working systems while debugging something else
Activation
magneto freeze src/auth # lock edits to src/auth/ and subdirectories
magneto freeze src/auth src/api # lock edits to multiple directories
magneto freeze '**/*.test.ts' # lock edits to test files only
magneto unfreeze # release the lock
magneto careful status # show current freeze globs
Integration Contract (for host agents)
Before editing any file, check .magneto/safety.json:
state = read(".magneto/safety.json")
if state["freezeGlobs"]:
if not any(matches_glob(target_path, g) for g in state["freezeGlobs"]):
abort(f"Path {target_path} is outside freeze scope: {state['freezeGlobs']}")
audit("freeze.blocked_write", {"path": target_path})
Magneto provides a glob matcher via magneto safety check-path <path> — exit code 0 means allowed, 1 means blocked.
When to Use
- Debugging a specific module →
magneto freeze src/auth - Implementing one feature without scope creep →
magneto freeze src/payments - Production work where you need maximum discipline →
magneto guard src/payments
When NOT to Use
- Cross-cutting refactors that genuinely need to touch many files
- New feature scaffolding (freeze AFTER the files exist)
Example
User: /freeze src/auth
Agent: /freeze activated. Edits restricted to:
◆ src/auth
User: While you're at it, fix the typo in src/users/README.md
Agent: Blocked. src/users/README.md is outside the freeze scope.
Options:
1. Note this for later (mention it in design.md)
2. `magneto unfreeze`, then fix, then re-freeze
3. `magneto freeze src/auth src/users` to expand scope
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 82 lines · 0 tokens per session scan A c5ee5cac77f9
freeze is a skill published in the GitHub repository rijuvashisht/Magneto (6 stars, last pushed 2mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 643 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
expense-review-policy
Review invoices and contracts against accounts-payable policy before human approval.
skill-creator
Create, install, or update skills in the workspace. Use when (1) installing a skill from a URL or remote source, (2) creating a new skill from scratch, (3) updating or restructuring existing skills. Always use this skill for any skill installation or creation task.
image-generation
Generate or edit images from text prompts. Use when the user asks to create, draw, design, or edit an image, illustration, photo, icon, poster, or any visual content.
baby-sit
Monitor a GitHub pull request until CI is green, diagnose failures, and rerun only evidence-backed flaky GitHub Actions jobs.
continual-learning
Nightly refinement of an existing per-repo review-style prompt using this reviewer's own finding outcomes. Read confirmed (resolved-by-commit / thumbs-up) and dismissed (thumbs-down) findings, promote the bug patterns the team actually fixes, demote the false-positive patterns, reconcile against the current prompt…
peekaboo
Capture and automate macOS UI with the Peekaboo CLI.