Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/saadshahd/moo.md/provocationnpx skills add saadshahd/moo.md --skill provocationgit clone --depth 1 https://github.com/saadshahd/moo.mdWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/saadshahd/moo.md/provocation)<a href="https://agentmods.dev/skills/saadshahd/moo.md/provocation"><img src="https://agentmods.dev/badge/skills/saadshahd/moo.md/provocation.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00023 | $0.00708 |
| Opus 5 | $0.00012 | $0.00354 |
| Sonnet 5 | $0.00005 | $0.00142 |
| Haiku 4.5 | $0.00002 | $0.00071 |
Grade A, and why
provocation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 52 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Extract
From the conversation/context/user:
- The obvious answer — the answer that has ended the thinking: settled, uncontested, in the words it settled in.
- The cost — what the settling is costing: the option no longer weighed, the question no longer asked, the work shaped by not looking.
Gate
Proceed only when: the answer has settled — nobody in the conversation doubts it — and the settling is costing something.
Anything else, say which in one plain line — never provoke anyway:
- Someone already disagrees or feels uneasy → the doubt is the movement, already live — take it as it stands, name what it forces into view, and proceed with the work; no false statement needed.
- The answer is correct and the settling costs nothing → leave it settled and proceed with the work.
- The statement you would write is one you would defend — a position you hold, not a falsehood → that is a proposal: make it plainly and proceed with the work; if a claim about it then needs a committed verdict → use judge skill; if the user needs something to react to before they can choose → use draft skill.
- The question is still undecided — no answer has ended the thinking → there is nothing to unsettle; proceed with the work on the undecided question; if the user holds an answer they cannot yet put into words → use elicit skill.
Deny
Everything from writing the statement through delivering the movement runs inside this one turn — nothing waits on the user.
Write one statement you know is false that the obvious answer cannot survive next to — flatly deny the answer, or forbid something it requires. The statement is written knowing it is false: label it false out loud, never let it stand as something believed.
Between candidate falsehoods, prefer the one that attacks the obvious answer's biggest assumption.
Walk
Walk toward the statement: ask what would have to be true for it to work. Name each thing the walking forces into view — an assumption the obvious answer smuggled in, an option it closed. The named list is the movement.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 52 lines · 23 tokens per session scan A ffed33109ad8
provocation is a skill published in the GitHub repository saadshahd/moo.md (34 stars, last pushed 18d ago), licensed MIT. It adds 23 tokens to every session and 708 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
session-recap
Document Claude Code sessions by extracting knowledge into cross-referenced documentation. Triggers on "recap the session", "summarize the work", or after significant code changes.
knowledge-bank-lookup
Delegates knowledge bank lookups to Explore subagents with reflections-first strategy that learns from past mistakes. Checks /reflections/ directory before documentation to extract documented failures to avoid and proven approaches to apply. Automatically triggers when user mentions services ([project-a], [project-b]…
kb-ingest
Ingest external sources into the knowledge bank through interactive study or quick filing. Two modes — Quick (summarize → file) and Study (theme-by-theme deep dive with online research and personal notes → multi-layer KB output → optional blog/slack synthesis). Triggers on "ingest this", "study this article", "add to…
session-manager
Manage current Claude Code session metadata — set project, tags, and summary on session.md via Obsidian CLI. Use this skill whenever the user wants to tag, categorize, name, label, summarize, or organize the current session. Triggers on phrases like "tag this session", "this was about X", "mark this as", "session…
lark-openapi-explorer
飞书/Lark 原生 OpenAPI 探索:从官方文档库中挖掘未经 CLI 封装的原生 OpenAPI 接口。当用户的需求无法被现有 lark- skill 或 lark-cli 已注册命令满足,需要查找并调用原生飞书 OpenAPI 时使用。.
lark-workflow-standup-report
日程待办摘要:编排 calendar +agenda 和 task +get-my-tasks,生成指定日期的日程与未完成任务摘要。适用于了解今天/明天/本周的安排。.