Borrowing it
Nothing to install: this file belongs to sageox/agent-toolkit. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/sageox/agent-toolkit/main/.agents/skills/ox-plan/SKILL.mdgit clone --depth 1 https://github.com/sageox/agent-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/sageox/agent-toolkit/ox-plan)<a href="https://agentmods.dev/skills/sageox/agent-toolkit/ox-plan"><img src="https://agentmods.dev/badge/skills/sageox/agent-toolkit/ox-plan/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/sageox/agent-toolkit/ox-plan"><img src="https://agentmods.dev/badge/skills/sageox/agent-toolkit/ox-plan.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00274 | $0.03539 |
| Opus 5 | $0.00137 | $0.01769 |
| Sonnet 5 | $0.00055 | $0.00708 |
| Haiku 4.5 | $0.00027 | $0.00354 |
Grade A, and why
ox-plan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to ox-cli-plan — 2 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 153 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Whether to render at all is decided by the ox plan JSON (signals.material, guidance) + the user's confirmation / the plan.html config setting — not by this skill. Do not nag on trivial plans; honor the command's signal.
You author the page. ox injects the chrome. For any material plan, author a rich, self-contained interactive HTML page — that page IS the plan of record. ox plan save --file plan.html stores it verbatim in the ledger, derives plan.md from it, and computes the deterministic badges itself. ox plan render --file plan.html serves it with the ox chrome injected (append-only, between <!-- ox-chrome:start/end --> markers — never wrapped, never rewritten). Contract + quality bar: docs/specs/plan-authoring-html.md. Markdown-first remains only the quick path for small, low-stakes plans.
Orchestration (what this skill does)
flowchart TB
RUN["Run ox plan enrich --json on the topic or draft"] --> DET["ox returns DETERMINISTIC badges + context bundle (0 LLM tokens)"]
DET --> READ["AI coworker reads the context bundle: murmurs, sessions, decisions, ADRs, expert artifacts"]
READ --> PAGE["AI coworker authors plan.html: tabs, inspectors, data-driven viz, dark design register"]
READ --> JUDGE["Optional: AI coworker authors JUDGMENT badges, CITED-ONLY (aligns / conflicts / expert-perspective)"]
PAGE --> SAVE["ox plan save --file plan.html (ox derives plan.md + deterministic badges; --annotations optional)"]
JUDGE --> SAVE
SAVE --> GATE{"Render confirmed? (user asked OR plan.html recommend + confirm)"}
GATE -->|"no"| DONE["Saved to ledger; report slug"]
GATE -->|"yes"| RENDER["ox plan render --file plan.html --open (ox injects chrome, opens review loop)"]
-
Get the deterministic signals + context bundle. Run:
ox plan enrich --json --file <plan-file> # or --topic "<subject>" before draftingThis makes no LLM or network call. It returns a
ResultJSON:annotations[]— deterministic, ox-computed badges:collision,prior-art,expert-routing. Each carries{section, kind:"deterministic", type, why, source_url, expert, files}. These are factual — keep them as-is, do not second-guess them. On save, ox computes these itself; you never re-author them.context[]— the pre-retrieved bundle the AI coworker reasons over:{kind: murmur|session|decision|adr|commit|discussion, title, ref, snippet, score, author, when}.signals—{collisions, prior_art, expert_routes, material}.materialis ox's call on whether a render is worth recommending.
-
Author the page (the main event — see "Authoring the page" below). Build the rich, self-contained
plan.htmlthat carries the plan's whole argument: tabbed views, interactive inspectors, data-driven visualizations, the dark design register. -
Optionally author JUDGMENT badges (ox does NO inference). Read the
context[]bundle and produce judgment annotations — additive, passed via--annotations:aligns/conflicts— does the plan agree or clash with a cited ADR, decision, or convention?expert-perspective— the synthesized stance of the area expert.
CITED-ONLY is non-negotiable. Every judgment badge MUST point at a real artifact from the bundle (
ref/source_url): a specific ADR, decision doc, session, commit, or discussion. Rules:- Never invent an opinion, a quote, or a conflict. Precision over recall.
- When the evidence is thin or ambiguous, degrade to a routing nudge —
expert-perspectivebecomes "consult<name>" (naming the expert fromannotations[].expert), NOT a fabricated stance. Putting words in a teammate's mouth is the one failure mode that destroys trust. - When unsure whether a conflict is real, downgrade to "Novel — no prior decision found," not a false
conflicts. - Set
kind:"judgment"on every badge you author so the chrome styles it distinctly from ox's deterministic ones (outlined vs. filled — ox owns that treatment).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 153 lines · 274 tokens per session scan A d3ef61460eac
ox-plan is a skill published in the GitHub repository sageox/agent-toolkit (10 stars, last pushed today), licensed Apache-2.0. It adds 274 tokens to every session and 3,539 once invoked, about $0.0014 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to ox-cli-plan, differing in 2 lines, and is treated as a copy.
Other skills, from other repositories
hive.colony-progress-tracker
Claim tasks, record step progress, and verify SOP gates in the colony SQLite queue. Applies when your spawn message includes a dbpath field.
operator-scorecard
Three recap modes - default synthesizes agent health, community growth, and economic activity into a was-it-worth-it verdict; ops recaps what shipped and failed; push ranks push impact.
github-monitor
Watch your GitHub repos across four views - a combined urgency monitor (stale PRs, new issues, releases), a new-issue triage queue, a release upgrade digest, or your own opened-PR tracker.
heartbeat
Ambient fleet-health check that surfaces anything worth attention (default), or an on-demand priority brief - the 3 things to focus on, why now, and what moved (var=brief).
shiplog
Recap of everything shipped since the last run - cross-repo PRs, security fixes, star deltas, and X traction, synthesized into a digest article and a ready-to-post shiplog in your voice.
idea-pipeline
Execution-gap audit - cross-references the startup idea backlog against shipped skills, prototypes, and cross-repo PRs, surfacing the top 3 ideas to build next by narrative and operator fit.