Arbor is an autonomous research agent that proposes hypotheses, edits code, runs experiments, and retains improvements that succeed on held-out data in a growing hypothesis tree. Researchers use it to investigate problems and iteratively optimize solutions with real experiments. The catalogue skills and plugin expose Arbor's research-agent workflow to coding agents.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add RUC-NLPIR/Arbor --skill arbor-agent-setup-intakegit clone --depth 1 https://github.com/RUC-NLPIR/ArborWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ruc-nlpir/arbor/arbor-agent-setup-intake)<a href="https://agentmods.dev/skills/ruc-nlpir/arbor/arbor-agent-setup-intake"><img src="https://agentmods.dev/badge/skills/ruc-nlpir/arbor/arbor-agent-setup-intake/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ruc-nlpir/arbor/arbor-agent-setup-intake"><img src="https://agentmods.dev/badge/skills/ruc-nlpir/arbor/arbor-agent-setup-intake.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Excessive Agency · line 15 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00065 | $0.01718 |
| Opus 5 | $0.00032 | $0.00859 |
| Sonnet 5 | $0.00013 | $0.00344 |
| Haiku 4.5 | $0.00006 | $0.00172 |
Grade A, and why
arbor-agent-setup-intake scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 202 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Arbor Setup And Intake
Use this before the coordinator starts. The output is a concrete research contract plus a clean workspace/session ready for the Arbor cycle.
Fast Path
- Confirm the target project directory. Treat the launch cwd as the default unless evidence says it is wrong.
- Inspect README/config/eval files yourself. Do not ask the user to recite data you can read.
- Identify the primary metric, direction, and real evaluation command.
- Determine B_dev and B_test. If only one split exists, call it B_dev and record that no separate B_test is available.
- Run or locate a cheap baseline when feasible. If not feasible, state
baseline unknown - measure during INIT. - Propose one complete contract and ask for a single yes/edit confirmation.
- Initialize or select
.arbor/sessions/<run_name>/and hand the contract to the coordinator. - If real merges are allowed, define a non-protected
trunk_branchsuch asarbor/trunk/<run_name>. Treatmain/masteras the base branch, not the merge target.
For smoke/forward tests, never run expensive setup, data prep, training, GPU
jobs, or the discovered full eval command. Locate an existing score in cached
metadata/logs or use a clearly labelled mocked score, and include
smoke-only in the contract.
Research Contract
The instruction passed to the coordinator must contain all five components:
- Metric: exact score name, command that prints it, and maximize/minimize.
- Baseline anchor: current value if known, otherwise say it will be measured in INIT.
- Ambition: beat baseline, reach a target, or push as high as possible within the cycle budget.
- Scope preference: novelty-leaning, effect-leaning, or mixed. Infer it from the repo/task when possible.
- Hard constraints: at minimum, B_test is not for iteration, data/eval harness must not be modified to game the metric, and project-specific protected paths must be respected.
Do not prescribe a specific approach in the contract. The coordinator owns idea generation.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 202 lines · 65 tokens per session scan A b87c4f576803
arbor-agent-setup-intake is a skill published in the GitHub repository RUC-NLPIR/Arbor (1,059 stars, last pushed today), licensed Apache-2.0. It adds 65 tokens to every session and 1,718 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
skill-forge
Autonome Verbesserung nach dem Autoresearch-Paradigma (Karpathy). Zwei Modi: (1) Skill-Modus — optimiert eine SKILL.md durch iterative Mutation und Evaluation. (2) Generic-Modus — optimiert beliebige Dateien gegen jede mechanische Metrik (Testabdeckung, Bundle-Size, Lighthouse-Score, Docker-Image-Größe, etc.). Zwei…
autogpt-agents
Autonomous AI agent platform for building and deploying continuous agents. Use when creating visual workflow agents, deploying persistent autonomous agents, or building complex multi-step AI automation systems.
autocontext-consumer
Use when an agent needs to USE knowledge Autocontext already produced - find which scenarios have knowledge, read the playbook and lessons for one, understand the on-disk file and folder layout, and move knowledge between checkouts. Host-agnostic; requires only the autoctx CLI and the filesystem.
autocontext-creator
Use when an agent needs to CREATE knowledge with Autocontext - run a scenario or plain-language task through the improvement loop, judge or improve a single output, and inspect what the run produced. Host-agnostic; requires only the autoctx CLI.
autocontext
Iterative strategy generation and evaluation system. Use when the user wants to evaluate agent output quality, run improvement loops, queue tasks for background evaluation, check run status, inspect runtime artifacts and session branch lineage, or discover available scenarios. Provides LLM-based judging with…
codex-autoresearch
Triage improvement work and run or resume accepted measured loops in a local project. Architecture, documentation, UX, product study, open research, taste, and one-shot fixes stay direct unless the user explicitly requests repeated measurement with a complete experiment contract.