Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/robhowley/py-pit-skills/click-cli-linternpx skills add robhowley/py-pit-skills --skill click-cli-lintergit clone --depth 1 https://github.com/robhowley/py-pit-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/robhowley/py-pit-skills/click-cli-linter)<a href="https://agentmods.dev/skills/robhowley/py-pit-skills/click-cli-linter"><img src="https://agentmods.dev/badge/skills/robhowley/py-pit-skills/click-cli-linter.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00035 | $0.01068 |
| Opus 5 | $0.00017 | $0.00534 |
| Sonnet 5 | $0.00007 | $0.00214 |
| Haiku 4.5 | $0.00003 | $0.00107 |
Grade A, and why
click-cli-linter scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 193 lines — stays where its author put it; the contents beside it link to each section on GitHub.
click-cli-linter
Use this skill when reviewing or fixing an existing Python CLI built with Click.
This skill focuses on:
- identifying structural problems
- detecting non-idiomatic Click usage
- improving CLI UX
- proposing minimal patches rather than unnecessary rewrites
Apply this skill when the user:
- asks to audit a Click CLI
- wants feedback on existing Click code
- asks why a Click CLI feels messy or hard to maintain
- wants minimal fixes for a Click-based command-line tool
- pastes Click code and asks for improvement
Do not apply when:
- the user wants a new CLI designed from scratch with no existing code
- the task is unrelated to Python CLIs
- the user explicitly wants another framework
Invocation heuristics
Prefer this skill when the user:
- mentions existing Click code
- asks for review, linting, cleanup, or refactoring
- wants architecture feedback on a Click CLI
- wants to fix help text, options, command grouping, or code layout
Do not prefer this skill when:
- there is no existing CLI to review
- the task is purely explanatory and not evaluative
- the user is asking for a fresh implementation only
Mission
Audit an existing Click CLI and provide:
- the most important detected issues
- why they matter
- the smallest effective patch
- an improved version when useful
Prefer minimal, high-leverage improvements over full rewrites.
Core review mental model
Review the CLI across three layers:
- architecture
- Click idioms
- command-line UX
Do not nitpick style unless it affects correctness, maintainability, or usability.
The 5 review invariants
Always follow these rules.
1. Prioritize real problems
Focus on:
- architecture breakdown
- non-idiomatic Click usage
- poor command discoverability
- inconsistent argument and option patterns
- output and help text problems
Do not pad the review with trivial style comments.
2. Prefer minimal patches
Fix the smallest thing that materially improves the CLI.
Prefer:
print("Done")
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 193 lines · 35 tokens per session scan A 27df8c858c1a
click-cli-linter is a skill published in the GitHub repository robhowley/py-pit-skills (5 stars, last pushed 5mo ago), licensed MIT. It adds 35 tokens to every session and 1,068 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
python-backend
Production Python async patterns including asyncio TaskGroup, FastAPI dependency injection and middleware, SQLAlchemy 2.0 async sessions, and database connection pool tuning. Python 3.11+ runtime concerns such as ExceptionGroup, cancellation semantics, and session rollback. Use when building async services, wiring…
python
Use when building FastAPI applications, implementing async endpoints, setting up Pydantic schemas, working with SQLAlchemy, or writing pytest tests for Python backend services.
database
Relational database authority — PostgreSQL, async ORM (SQLAlchemy 2 / asyncpg), Alembic schema migrations, Supabase Python and JS clients, query optimisation, index strategy, connection pooling, transaction patterns, and bulk operations across Python and Node stacks.
crudauth
Use when building or modifying authentication in a FastAPI app with crudauth (the crudauth PyPI package) — covers CRUDAuth, the AuthUserMixin / makeauthidentity user model, IdentityConfig, currentuser(...) gates, session + bearer transports, OAuth (Google/GitHub), email verification / password reset / change, custom…
FastAPI Testing Patterns
FastAPI application testing with TestClient, dependency injection overrides, async testing, database testing with SQLAlchemy, and OpenAPI validation.
pytest
Advanced Python unit testing framework for customer support tech enablement, covering FastAPI, SQLAlchemy, PostgreSQL, async operations, mocking, fixtures, parametrization, coverage, and comprehensive testing strategies for backend support systems.