agent-toolkit: Skill for Claude Code

.agents/skills/ox-plan/SKILL.md

ox-plan is a skill for Claude Code, Codex from sageox/agent-toolkit. It costs 274 tokens per session (3,539 once invoked), scanned A, a copy of ox-cli-plan, Apache-2.0.

A planning workflow that creates a self-contained interactive HTML page as the main record of a plan, then saves and renders it with project context. It can also produce a simpler Markdown plan for small, low-risk tasks.

In plain words
What is it for?
Use it to investigate a topic, write material plans, save them in a project ledger, and serve them as viewable pages.
Why use it?
It keeps the detailed plan, supporting context, and generated Markdown tied to one saved source instead of scattered notes.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: mentions CLAUDE.md; installed under .agents/ (shared by several agents).

This is sageox/agent-toolkit's own configuration. It tells Claude Code and Codex how to work on agent-toolkit itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything agent-toolkit configures →

Reuse

Borrowing it

Nothing to install: this file belongs to sageox/agent-toolkit. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/sageox/agent-toolkit/main/.agents/skills/ox-plan/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/sageox/agent-toolkit

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ox-plan

README.md
[![agentmods](https://agentmods.dev/badge/skills/sageox/agent-toolkit/ox-plan/github.svg)](https://agentmods.dev/skills/sageox/agent-toolkit/ox-plan)
Your own site
<a href="https://agentmods.dev/skills/sageox/agent-toolkit/ox-plan"><img src="https://agentmods.dev/badge/skills/sageox/agent-toolkit/ox-plan/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for ox-plan

Your own site · 80×15
<a href="https://agentmods.dev/skills/sageox/agent-toolkit/ox-plan"><img src="https://agentmods.dev/badge/skills/sageox/agent-toolkit/ox-plan.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 274 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,539 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00274 $0.03539
Opus 5 $0.00137 $0.01769
Sonnet 5 $0.00055 $0.00708
Haiku 4.5 $0.00027 $0.00354

Measured yesterday against content hash d3ef61460eac, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

ox-plan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to ox-cli-plan — 2 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.agents/skills/ox-plan/SKILL.md · 153 lines

How it starts

The opening of the file, as written. The whole thing — 153 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Whether to render at all is decided by the ox plan JSON (signals.material, guidance) + the user's confirmation / the plan.html config setting — not by this skill. Do not nag on trivial plans; honor the command's signal.

You author the page. ox injects the chrome. For any material plan, author a rich, self-contained interactive HTML page — that page IS the plan of record. ox plan save --file plan.html stores it verbatim in the ledger, derives plan.md from it, and computes the deterministic badges itself. ox plan render --file plan.html serves it with the ox chrome injected (append-only, between <!-- ox-chrome:start/end --> markers — never wrapped, never rewritten). Contract + quality bar: docs/specs/plan-authoring-html.md. Markdown-first remains only the quick path for small, low-stakes plans.


Orchestration (what this skill does)

flowchart TB
  RUN["Run ox plan enrich --json on the topic or draft"] --> DET["ox returns DETERMINISTIC badges + context bundle (0 LLM tokens)"]
  DET --> READ["AI coworker reads the context bundle: murmurs, sessions, decisions, ADRs, expert artifacts"]
  READ --> PAGE["AI coworker authors plan.html: tabs, inspectors, data-driven viz, dark design register"]
  READ --> JUDGE["Optional: AI coworker authors JUDGMENT badges, CITED-ONLY (aligns / conflicts / expert-perspective)"]
  PAGE --> SAVE["ox plan save --file plan.html  (ox derives plan.md + deterministic badges; --annotations optional)"]
  JUDGE --> SAVE
  SAVE --> GATE{"Render confirmed? (user asked OR plan.html recommend + confirm)"}
  GATE -->|"no"| DONE["Saved to ledger; report slug"]
  GATE -->|"yes"| RENDER["ox plan render --file plan.html --open  (ox injects chrome, opens review loop)"]
  1. Get the deterministic signals + context bundle. Run:

    ox plan enrich --json --file <plan-file>   # or --topic "<subject>" before drafting
    

    This makes no LLM or network call. It returns a Result JSON:

    • annotations[] — deterministic, ox-computed badges: collision, prior-art, expert-routing. Each carries {section, kind:"deterministic", type, why, source_url, expert, files}. These are factual — keep them as-is, do not second-guess them. On save, ox computes these itself; you never re-author them.
    • context[] — the pre-retrieved bundle the AI coworker reasons over: {kind: murmur|session|decision|adr|commit|discussion, title, ref, snippet, score, author, when}.
    • signals{collisions, prior_art, expert_routes, material}. material is ox's call on whether a render is worth recommending.
  2. Author the page (the main event — see "Authoring the page" below). Build the rich, self-contained plan.html that carries the plan's whole argument: tabbed views, interactive inspectors, data-driven visualizations, the dark design register.

  3. Optionally author JUDGMENT badges (ox does NO inference). Read the context[] bundle and produce judgment annotations — additive, passed via --annotations:

    • aligns / conflicts — does the plan agree or clash with a cited ADR, decision, or convention?
    • expert-perspective — the synthesized stance of the area expert.

    CITED-ONLY is non-negotiable. Every judgment badge MUST point at a real artifact from the bundle (ref / source_url): a specific ADR, decision doc, session, commit, or discussion. Rules:

    • Never invent an opinion, a quote, or a conflict. Precision over recall.
    • When the evidence is thin or ambiguous, degrade to a routing nudgeexpert-perspective becomes "consult <name>" (naming the expert from annotations[].expert), NOT a fabricated stance. Putting words in a teammate's mouth is the one failure mode that destroys trust.
    • When unsure whether a conflict is real, downgrade to "Novel — no prior decision found," not a false conflicts.
    • Set kind:"judgment" on every badge you author so the chrome styles it distinctly from ox's deterministic ones (outlined vs. filled — ox owns that treatment).

Read the full file on GitHub · 153 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 153 lines · 274 tokens per session scan A d3ef61460eac

Subscribe to this mod's changes

ox-plan is a skill published in the GitHub repository sageox/agent-toolkit (10 stars, last pushed today), licensed Apache-2.0. It adds 274 tokens to every session and 3,539 once invoked, about $0.0014 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to ox-cli-plan, differing in 2 lines, and is treated as a copy.