Borrowing it
Nothing to install: this file belongs to rosselps/whyguard. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/rosselps/whyguard/main/.kiro/skills/trace-historical-decision/SKILL.mdgit clone --depth 1 https://github.com/rosselps/whyguardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/rosselps/whyguard/trace-historical-decision)<a href="https://agentmods.dev/skills/rosselps/whyguard/trace-historical-decision"><img src="https://agentmods.dev/badge/skills/rosselps/whyguard/trace-historical-decision.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00037 | $0.00434 |
| Opus 5 | $0.00018 | $0.00217 |
| Sonnet 5 | $0.00007 | $0.00087 |
| Haiku 4.5 | $0.00004 | $0.00043 |
Grade A, and why
trace-historical-decision scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
When to use this skill
Before removing, simplifying, or "cleaning up" a condition, guard clause, retry, timeout, validation call, or special-case branch — especially in payments, auth, orders, dates, or external-API code — trace why it exists first.
Workflow
- Identify the exact file, symbol, and changed lines you are about to touch.
- Run the deterministic scan against the relevant commit range:
(Today this is the CLI vertical slice; once the MCP server ships, prefer callingpnpm whyguard scan --base <base-ref> --head <head-ref> --format jsonwhyguard.trace_symbolinstead.) - Review every evidence ID and its strength (
strong/medium/weak) — never treat evidence as reliable without checking strength. - State the protected behavior separately from the current implementation. Example: "protects: one idempotency key creates at most one order" vs. "implemented via: an early-return guard checking a Map".
- If evidence is weak or absent, say explicitly that the reason is unknown. Do not invent an incident, issue, or justification.
- Propose a regression test that encodes the protected behavior before suggesting removal or replacement of the historical code.
Anti-patterns to avoid
- Removing a guard clause because it "looks redundant" without running a trace first.
- Citing an issue/PR number from memory instead of the evidence returned by the tool.
- Treating
weakevidence as if it werestrong. - Concluding "no evidence found" without checking the introducing commit via
git log -S.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 38 lines · 37 tokens per session scan A a21a47cf4e6f
trace-historical-decision is a skill published in the GitHub repository rosselps/whyguard (0 stars, last pushed 1mo ago), licensed MIT. It adds 37 tokens to every session and 434 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
static-code-analysis
Selects, configures, and integrates a static analysis tool for the project's language. Covers tool selection, rule configuration, CI integration, fixing existing violations, and pre-commit hook setup. Invoked when the user asks to add linting, set up static analysis, or configure a code quality tool.
mypy
Skill "mypy" from bobmatnyc/claude-mpm, covering mypy - static type checking for python, basic mypy, with common type stubs, for fastapi projects and for django projects.
grafema-codebase-analysis
Analyze codebases using a graph database instead of reading source files. Use when understanding code architecture, finding functions or call patterns, tracing data flow, checking dependencies, or answering "where is X used?" questions. Grafema builds a queryable code graph from static analysis — prefer querying the…
code_explorer
Explores the repository to locate primary source files, coupled UI components, and test files for bug reports or feature requests.
session-investigator
Investigate fast-agent session and history files to diagnose issues. Use when a session ended unexpectedly, when debugging tool loops, when correlating sub-agent traces with main sessions, or when analyzing conversation flow and timing. Covers session.json metadata, history JSON format, message structure, tool…
smiles-validation
Strict SMILES validation, structural comparison, and modification verification. Catches invalid LLM-generated molecules.