Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add rodrigohighermind/highermind-code-skills --skill hm-validate-allgit clone --depth 1 https://github.com/rodrigohighermind/highermind-code-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/rodrigohighermind/highermind-code-skills/hm-validate-all)<a href="https://agentmods.dev/skills/rodrigohighermind/highermind-code-skills/hm-validate-all"><img src="https://agentmods.dev/badge/skills/rodrigohighermind/highermind-code-skills/hm-validate-all.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00098 | $0.01868 |
| Opus 5 | $0.00049 | $0.00934 |
| Sonnet 5 | $0.00020 | $0.00374 |
| Haiku 4.5 | $0.00010 | $0.00187 |
Grade A, and why
hm-validate-all scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 139 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/hm-validate-all — Validação Completa Pré-Ship (v1.1)
Você está agora em modo orquestrador. Seu trabalho e disparar as 5 skills de validação em ordem otimizada, consolidar findings, e entregar UM único report priorizado que diz: baseline-ready (Dev Team pode entregar pro Owner) OU BLOQUEADO.
Princípio central
Validação manual passo-a-passo perde tempo. Orquestracao ganha. Mesma barra de qualidade que rodar cada skill isolada, sem o overhead de checkin manual entre cada uma. Bloqueante ship e tratado como bloqueante. Technical debt e tratado como debt.
Esta skill declara baseline-ready, não product-ready
- Baseline-ready = Dev Team validou os 5 checks abaixo + auditorias de segurança/engenharia/QA/design/deploy. Skill declara.
- Product-ready = Owner validou UX, fit com tese, qualidade visual end-to-end. Só Owner declara.
Os 5 checks obrigatorios do baseline-ready (do ~/.claude/CLAUDE.md global) já sao cobertos pelo /hm-qa v4. Esta skill consolida + adiciona security/engineering/designer/deploy:
- typecheck verde — coberto por
/hm-qa+/hm-engineer - lint verde — coberto por
/hm-qa+/hm-engineer - smoke test rodado pelo Dev Team — coberto por
/hm-qa - zero
console.errorem código novo — coberto por/hm-qa - zero TODO CRÍTICO em código novo — coberto por
/hm-qa
Se qualquer um dos 5 falhar, veredicto e BLOQUEADO. Sem exceção. Owner não valida produto enquanto baseline não esta verde.
Quando usar
- Antes de qualquer ship pra produção (interno ou externo)
- Apos sprint grande (multi-features, refactors estruturais)
- Antes de owner aprovar entrega final
- Quando quer confiança de "esta pronto" em uma checagem só
Não usar pra: validação parcial (ex: só segurança → use /hm-security direto), debug de bug especifico, code review de PR pequena (use /review).
Ordem de execução (importa)
Skills não independem entre si. Ordem certa evita retrabalho:
/hm-securityprimeiro. Security gate bloqueia tudo. Se tem CRÍTICO, não continua com as outras (perda de tempo)./hm-engineerdepois. Código fundamenta funcionalidade. Bug estrutural invalida QA passing./hm-qaterceiro. Funcionalidade validada apos segurança + código OK./hm-designerquarto. Design polish vale apos funcional. Inverso = polir UI de feature quebrada./hm-deployúltimo. Deploy gate só importa apos tudo acima OK.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 139 lines · 98 tokens per session scan A 4730e557a178
hm-validate-all is a skill published in the GitHub repository rodrigohighermind/highermind-code-skills (192 stars, last pushed 2mo ago), licensed MIT. It adds 98 tokens to every session and 1,868 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
research-engineer
An uncompromising Academic Research Engineer. Operates with absolute scientific rigor, objective criticism, and zero flair. Focuses on theoretical correctness, formal verification, and optimal implementation across any required technology.
tika-eval-compare
Compare extracts from two Tika builds over a corpus to detect regressions in content, encoding, exceptions, and embedded-document handling. Use for "compare before/after extracts", "eval this change against the corpus".
neuron-evaluation-engineer
Create and run AI evaluations with datasets, assertions, and output drivers in Neuron AI. Use this skill whenever the user mentions evaluation, testing AI systems, creating evaluators, dataset-driven testing, assertion-based validation, or wants to measure AI system performance. Also trigger for tasks involving…
jetson-validate-image
Use after jetson-flash-image to run static BSP checks, on-target smoke/regression tests on a flashed DUT, or both. Not for build or flash steps. Triggers: validate bsp, on-target validation.
atmos-validation
Validate Atmos projects, components, arbitrary JSON Schema inputs, EditorConfig, and GitHub Actions; use affected-file selection and native CI annotations.
skill-benchmark
Benchmark AI skill effectiveness by measuring implementation quality against legacy constraints.