Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/shelizi/coding-tools-mcp/goalnpx skills add shelizi/coding-tools-mcp --skill goalgit clone --depth 1 https://github.com/shelizi/coding-tools-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/shelizi/coding-tools-mcp/goal)<a href="https://agentmods.dev/skills/shelizi/coding-tools-mcp/goal"><img src="https://agentmods.dev/badge/skills/shelizi/coding-tools-mcp/goal.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00052 | $0.00799 |
| Opus 5 | $0.00026 | $0.00400 |
| Sonnet 5 | $0.00010 | $0.00160 |
| Haiku 4.5 | $0.00005 | $0.00080 |
Grade A, and why
goal scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/goal — 开发直到完成
开始开发吧,直到完成。
架构约束
- 工具共用底层:MCP 与 Actions 必须且只能调用
tools::call_tool(一点不能差);策略校验在call_tool内统一完成。 - Actions 暴露层:
validate_actions_exposure仅判断工具是否在 OpenAPI 白名单,不得重复做 exec/patch 参数校验。 - 旧版对齐:工具名、schema、ALLOWED_TOOLS、行为以
old/coding_tools_mcp/server.py与old/coding_tools_actions/policies.py为准。 - exec_command:禁止默认「整条命令丢进 bash/sh」;优先 argv 直启(
Command::new(exe).args(...)),扩大白名单(pytest/python/cargo/npm/go/msbuild/dotnet/gradle…),与旧版 allowlist 一致并覆盖 Windows 可执行名。 - 单文件 <500 行;用
platformtrait,禁止 PowerShell。 - 双端口:MCP 与 Actions 默认 28766,用户可改;占用时弹窗提醒。
完成定义(按 tasks.md)
优先级:底层逻辑 > 能跑通 > 测试(可选)
- 阶段 2(核心):
tools/与旧版行为对齐;MCP/Actions 共用;P0 工具逻辑完整(exec 直启、session、git 全家桶、patch、文件工具)。 - 阶段 3:隧道 FRP + Cloudflare 监督;健康检查 MVP;与 runtime 集成。
- 阶段 4:隧道/认证配置 UI(非旧版布局)。
- 验收:
cargo build+npm run check通过即可手工验证主路径。
测试(低优先级,用户不要求则不做):不主动移植 old/tests/compliance/;仅在为修 bug 时补最小单测。cargo test 有则用,无则不强求全绿。
执行流程
- 读
docs/specs/rust-desktop-client/tasks.md找下一项[ ]。 - 读
old/对应证据块,再改 Rust。 - 每完成一项:
cargo build(必须);测试仅在有回归风险或用户要求时跑。 - 未
cargo build绿不停止;阻塞则记到docs/specs/rust-desktop-client/blockers.md并继续其他项。 - 多 agent 时按目录分工:
tools/、mcp/、actions/、tunnel/、src/UI,集成冲突由主 agent 合并。
参考路径
| 主题 | 旧版 |
|---|---|
| 工具注册表 | old/coding_tools_mcp/server.py TOOL_REGISTRY |
| Actions 白名单 | old/coding_tools_actions/policies.py |
| exec 策略 | old/coding_tools_mcp/server.py exec_command / _check_command_policy |
| 合规测试 | old/tests/compliance/ |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 50 lines · 52 tokens per session scan A bd8e11d21cef
goal is a skill published in the GitHub repository shelizi/coding-tools-mcp (0 stars, last pushed 13d ago), licensed Apache-2.0. It adds 52 tokens to every session and 799 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
chronicle
Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…