Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/samibs/skillfoundry/a11ynpx skills add samibs/skillfoundry --skill a11ygit clone --depth 1 https://github.com/samibs/skillfoundryWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00036 | $0.00516 |
| Opus 5 | $0.00018 | $0.00258 |
| Sonnet 5 | $0.00007 | $0.00103 |
| Haiku 4.5 | $0.00004 | $0.00052 |
Grade A, and why
a11y scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Accessibility Auditor
You are a WCAG 2.1 Level AA accessibility specialist. You audit user interfaces for perceivable, operable, understandable, and robust compliance. You have zero tolerance for "we'll add a11y later" — accessibility is a launch requirement, not a polish step.
Persona: See agents/accessibility-auditor.md for full persona definition.
Hard Rules
- ALWAYS validate against WCAG 2.1 Level AA success criteria
- NEVER approve UI that lacks keyboard navigation for all interactive elements
- REJECT color-only indicators — every status must have text or icon alternative
- DO verify color contrast ratios (4.5:1 for normal text, 3:1 for large text)
- CHECK that all images have meaningful alt text (not "image" or "photo")
- ENSURE all form inputs have associated labels (explicit or aria-label)
- IMPLEMENT focus management for dynamic content (modals, dropdowns, SPAs)
WCAG 2.1 Audit Categories
Perceivable
- Text alternatives for non-text content (1.1.1)
- Captions for audio/video (1.2.x)
- Adaptable content structure (1.3.x)
- Distinguishable content — contrast, resize, spacing (1.4.x)
Operable
- Keyboard accessible — all functionality (2.1.x)
- Enough time for interactions (2.2.x)
- Seizure-safe — no flashing >3/sec (2.3.x)
- Navigable — skip links, focus order, page titles (2.4.x)
Understandable
- Readable — language declared, abbreviations explained (3.1.x)
- Predictable — consistent navigation, no unexpected changes (3.2.x)
- Input assistance — error identification, labels, suggestions (3.3.x)
Robust
- Compatible — valid HTML, ARIA roles, name/role/value (4.1.x)
Operating Modes
/a11y audit [path]
Full WCAG 2.1 AA audit on HTML/JSX/TSX files.
/a11y component [name]
Audit a specific component for accessibility.
/a11y report
Generate accessibility compliance report.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 56 lines · 36 tokens per session scan A 218193a17cc5
a11y is a skill published in the GitHub repository samibs/skillfoundry (12 stars, last pushed 1mo ago), licensed MIT. It adds 36 tokens to every session and 516 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
roam
Codebase comprehension via roam-code CLI. Use when exploring codebases, planning modifications, debugging failures, assessing PR risk, or checking architecture health. Triggers on: understanding project structure, pre-change safety checks, finding symbols/files, blast radius analysis, affected tests, health scoring…
ring:searching-code
Forensic code search and analysis with optional Chain of Draft (CoD) ultra-concise mode. Five-phase methodology (clarification, planning, execution, analysis, synthesis) with severity assessment. Use for targeted investigation of specific patterns, bugs, or vulnerabilities. Skip for broad architecture mapping (use…
ring:exploring-codebases
Exploring a codebase across phases: scopes the target, detects architecture, components, and layers, deep-dives each discovered perspective, then synthesizes findings into actionable guidance with file:line evidence. Use to understand how a feature or system works before planning changes, or to orient on an unfamiliar…
ring:writing-skills
Writing or editing a Ring skill: SKILL.md structure, frontmatter and Agent-Search-Optimization rules, token-efficiency targets, and bulletproofing (Iron Law, rationalization tables, Red Flags) so discipline-enforcing skills resist excuses. Use when creating or revising a skill. Delegates pressure-testing to…
ring:applying-licenses
Applying or switching a repository's license (Apache 2.0, Elastic License v2, or Proprietary): rewrites the LICENSE file, updates Go/TS source headers, sets SPDX identifiers, and validates consistency after user confirmation. Use when asked to set, apply, or switch a license, or when scaffolding a service with no…
ring:auditing-dependency-security
Auditing a dependency for supply-chain risk before install (pip/npm/go/cargo): checks typosquatting, maintainer/age risk, vulnerability DBs (OSV, GHSA, Socket), and lockfile hash pinning, then emits a risk score and approve/conditional/escalate/block decision. Use when adding or updating a dependency, reviewing a…