Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/sapiom/sapiom-js/open-prnpx skills add sapiom/sapiom-js --skill open-prgit clone --depth 1 https://github.com/sapiom/sapiom-jsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00084 | $0.01332 |
| Opus 5 | $0.00042 | $0.00666 |
| Sonnet 5 | $0.00017 | $0.00266 |
| Haiku 4.5 | $0.00008 | $0.00133 |
Grade A, and why
open-pr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 94 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Opening a pull request that passes the labeler
Every PR to main is classified by .github/workflows/pr-labeler.yml running
scripts/pr-label-classifier.mjs against the PR body. A body that doesn't
follow .github/pull_request_template.md gets the contribution: incomplete
label (the workflow logs say which check failed). The classifier re-runs on
edited/synchronize, so the fix is always: repair the body, never close the PR.
The contract (what the classifier actually checks)
Start from .github/pull_request_template.md verbatim and fill it in. The
checker is prefix-matching and structural, so keep the template's own wording:
- All nine
##sections present (heading text must match): Problem and motivation · Summary and scope · Related work · Validation · Tests and documentation (a###under Validation counts) · Compatibility and release impact · Security · AI assistance · Checklist. - Primary change type: all six checkboxes present, exactly one checked
(
[x]). This also drives the type label (Feature →enhancement, …). - Prose sections non-empty after comments are stripped: Problem and motivation, Summary and scope. HTML comments don't count as content.
- Related work: the line after
Related issue or discussion:must be non-empty; a bareN/Ais allowed for a direct PR. - Validation: must contain real commands/results — the untouched
```textblock with only the# command — resultplaceholder counts as empty. - Tests and documentation: non-empty, or
N/Awith a reason. - Compatibility and release impact: both bullets must have a value after
the colon —
- Breaking or externally visible changes: <something>and- Changeset: <Added …>(orN/Awith a reason). A changed published package really does need a.changeset/*.md(see #599's for the format). - Security: both checkboxes present and both checked.
- AI assistance: both checkboxes present, exactly one checked. If "I used AI assistance" is the one, there must be a non-empty description below the checkboxes (tool, what it did, how you verified).
- Checklist: all seven checkboxes present and all checked — check them honestly, which means the repo gates below actually ran.
The flow
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 94 lines · 0 tokens per session scan A a336712f76a5
open-pr is a skill published in the GitHub repository sapiom/sapiom-js (19 stars, last pushed 2d ago), licensed MIT. It adds 84 tokens to every session and 1,332 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…