Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/saski/arnesto/github-host-aliasnpx skills add saski/arnesto --skill github-host-aliasgit clone --depth 1 https://github.com/saski/arnestoWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00040 | $0.00607 |
| Opus 5 | $0.00020 | $0.00303 |
| Sonnet 5 | $0.00008 | $0.00121 |
| Haiku 4.5 | $0.00004 | $0.00061 |
Grade A, and why
github-host-alias scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 65 lines — stays where its author put it; the contents beside it link to each section on GitHub.
GitHub Host Alias
Goal
Ensure every GitHub SSH operation in this environment uses the single configured account: saski.
Use This Skill When
- Cloning a repository from GitHub.
- Adding or modifying a git remote.
- Suggesting or running
gitcommands that involve fetching, pulling, pushing, or cloning over SSH. - Troubleshooting GitHub auth where SSH aliases and
gh auth loginare being conflated.
SSH Host Alias Context
All GitHub access should use:
[email protected]:
Do not use bare [email protected]: in this environment. If a command, remote, or example uses bare GitHub SSH, rewrite it to [email protected]:.
GitHub CLI Caveat
github.com-saskiis an SSH alias from~/.ssh/config, not a separate GitHub CLI host.- Do not use
gh auth loginto choose Git-over-SSH identity. - Only use
gh auth loginwhen a GitHub CLI command ongithub.comtruly requires API authentication. - Before suggesting
gh auth login, inspect whetherGITHUB_TOKENis set. - If
GITHUB_TOKENis set,gh auth loginwill authenticate from that environment variable and will not store interactive credentials. For a stored login, runenv -u GITHUB_TOKEN gh auth loginor unsetGITHUB_TOKENin that shell first. - Confirm CLI auth separately with
gh auth status.
Workflow
- Check whether the target URL is a GitHub SSH URL.
- Normalize bare GitHub SSH URLs:
[email protected]:owner/repo.git- becomes
[email protected]:owner/repo.git
- Leave already-correct
[email protected]:URLs unchanged. - For HTTPS GitHub remotes that should use SSH, replace them with
[email protected]:owner/repo.git.
Example: Cloning
git clone [email protected]:saski/my-repo.git
Example: Fixing an Existing Remote
If a repository was cloned with the default GitHub SSH host or HTTPS and authentication fails, update the remote URL:
git remote set-url origin [email protected]:owner/repository-name.git
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 65 lines · 40 tokens per session scan A 436366dedcba
github-host-alias is a skill published in the GitHub repository saski/arnesto (5 stars, last pushed 6d ago), licensed Unlicense. It adds 40 tokens to every session and 607 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
pixir-delegate
Use Pixir as a headless subagent runtime from Claude Code or any harness with skill ! preprocessing (Codex roots and other no-hydration hosts use pixir-delegate-codex instead) — one-shot workers (pixir --json), parallel fan-out to N children (pixir delegate --spec), resumable steering (pixir resume), evidence…
pixir-delegate-codex
Use when a Codex CLI/Desktop root should fan out subagents, delegate to Pixir workers, run parallel workers, or manage a resident delegation daemon via Pixir Delegate; covers Codex preflight, AGENTS.md, approvals/sandbox, dry-run, daemon start/status/attach/cancel, closure evidence, and audited single-run execution…
pixir-diagnostics
Diagnose Pixir and T3 Code Pixir incidents from local canonical evidence. Use when a Pixir run, ACP/T3 thread, subagent/workflow, provider replay, or daily-driver dogfood session appears stuck, inconsistent, missing tool output, or hard to classify.
readonly-review
Run a no-network read-only review practice with two explorer steps and one synthesis step.
pixir-delegate-native
Delegate work to subagents from INSIDE a Pixir session using the native Subagent tools (spawnagent, waitagent, closeagent, listagents, sendinput) instead of shelling out to the pixir CLI. Use when you are a Pixir session that needs to fan out parallel workers, steer a child, or run skill-backed workflow templates …
repo-contracts-and-boundaries
Use when turning architecture, layering, ownership, dependency direction, schemas, structural metrics, quality thresholds, baselines, allowlists, or generated quality snapshots into repository checks.