gezhi-project-setup

gezhi-project-setup is a skill for Codex from SiyaoZheng/GEZHI. It costs 50 tokens per session (4,232 once invoked), scanned A, original, MIT.

A setup procedure for connecting an existing project to gezhi, including finding its finished output and creating a repeatable rebuild command. It also creates and checks a gezhi.toml configuration file.

In plain words
What is it for?
Use it to inspect a project, choose the artifact to review, configure gezhi, validate the setup, and identify the next command to run.
Why use it?
It helps non-experts turn a project into a repeatable build-and-review process without having to understand the build system first.

Skill for Codex

Written for Codex: runs codex exec. Also seen: positional $N argument; mentions Claude Code; mentions Codex.

Good fit Use it to inspect a project, choose the artifact to review, configure gezhi, validate the setup, and identify the next command to run.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/siyaozheng/gezhi/gezhi-project-setup
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add SiyaoZheng/GEZHI --skill gezhi-project-setup
Clone the repo
git clone --depth 1 https://github.com/SiyaoZheng/GEZHI

Made for: Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for gezhi-project-setup

README.md
[![agentmods](https://agentmods.dev/badge/skills/siyaozheng/gezhi/gezhi-project-setup/github.svg)](https://agentmods.dev/skills/siyaozheng/gezhi/gezhi-project-setup)
Your own site
<a href="https://agentmods.dev/skills/siyaozheng/gezhi/gezhi-project-setup"><img src="https://agentmods.dev/badge/skills/siyaozheng/gezhi/gezhi-project-setup/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for gezhi-project-setup

Your own site · 80×15
<a href="https://agentmods.dev/skills/siyaozheng/gezhi/gezhi-project-setup"><img src="https://agentmods.dev/badge/skills/siyaozheng/gezhi/gezhi-project-setup.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 50 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,232 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector warn 7 Sept 2026
SkillSpector: 1 finding, up to medium

These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →

  • medium Rogue Agent · line 176
    Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
    Fix: Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent.
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00050 $0.04232
Opus 5 $0.00025 $0.02116
Sonnet 5 $0.00010 $0.00846
Haiku 4.5 $0.00005 $0.00423

Measured 11d ago against content hash 4f39544d7977, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

gezhi-project-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/gezhi-project-setup/SKILL.md · 571 lines

How it starts

The opening of the file, as written. The whole thing — 571 lines — stays where its author put it; the contents beside it link to each section on GitHub.

gezhi Project Setup

Use this skill when a user wants an agent to make an existing project runnable under gezhi, especially when the user can judge the finished thing but does not want to configure the build loop by hand.

Role in the One-Prompt Flow

llms.txt is the public entrypoint and router. This skill is the execution runbook. When an agent arrives from llms.txt, inherit the user-facing contract from that file, then use this skill for the concrete setup decisions:

  • inspect the project;
  • choose the canonical artifact;
  • synthesize or select the producer;
  • write gezhi.toml;
  • validate the setup;
  • report the exact next command.

Do not send the user back to read this skill. The skill is for the agent to execute on the user's behalf.

The deliverable is not just a gezhi.toml. The deliverable is a repeatable thing loop:

stable rebuild -> finished thing -> review -> bounded source work

For a non-expert user, success means they can run one command after setup and understand what artifact to inspect. Do not leave them with a partial config that only works if they already know the build system.

When to Use

  • A user asks to "set up gezhi" for a project.
  • A user provides a repository and a desired output such as a PDF, site, workbook, report, model metric, or slide deck.
  • A user wants an agent to create the rebuild command and gezhi.toml.
  • A user has a finished thing they can inspect but does not know the build system.

Do not use this skill for generic task planning, ordinary code review, or a project that has no inspectable thing.

Operating Rules

  • Address the user by name if the host profile supplies one.
  • Prefer live project evidence over README claims.
  • Do not edit raw data, generated outputs, build products, .git/, or .gezhi/ unless the user explicitly asked for that exact operation.
  • Ask the user only when the finished thing cannot be inferred safely.
  • Keep the producer deterministic, idempotent, and easy to rerun.
  • Completion belongs to the rebuilt thing and tik verdict, not to the tok agent's explanation.
  • Treat every tok pass as source changes only. Tok must not declare the thing-level goal complete.
  • If a command fails, preserve the exact failing command and the relevant output in your final report. Do not describe a setup as ready when validation did not pass.
  • Do not edit unrelated README/docs/tests/source while setting up gezhi unless that file is directly required for the producer or goal config.

Read the full file on GitHub · 571 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 571 lines · 50 tokens per session scan A 4f39544d7977

Subscribe to this mod's changes

gezhi-project-setup is a skill published in the GitHub repository SiyaoZheng/GEZHI (40 stars, last pushed 12d ago), licensed MIT. It adds 50 tokens to every session and 4,232 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

figure-style

Publication-grade correctness and legibility rules for final-deliverable scientific figures, not exploratory plots. Use for a figure that will ship in a report, paper, export, or kept artifact. Covers data fidelity, label economy, color threading, chart choice, layout, and render-then-verify QA without imposing a…

aipoch/open-science · 91 tokens

remote-compute-ssh

Evaluate and use SSH Remote Compute before choosing where to run GPU, high-memory, parallel, batch, model-inference, bioinformatics, or other long-running scientific work; supports short remote commands and asynchronous jobs with automatic harvest and analysis.

aipoch/open-science · 53 tokens

paper-narrative

Judge and reshape the story told by an entire paper figure deck. Use when writing or revising a paper to derive a grounded brief from the manuscript and captions, review the full deck as a handling editor, and hand an ordered figure arc to figure-composer.

aipoch/open-science · 58 tokens

customize

Use when the user wants to create or manage a Specialist agent or create, revise, publish, or delete a Skill through the conversational /Customize entry. Routes Skill work to the internal skill-creator and handles Specialist work through the JavaScript host.agents SDK.

aipoch/open-science · 56 tokens

esmfold2

Biohub ESMFold2 / ESMFold2-Fast all-atom co-folding (Candido et al. 2026, github.com/Biohub/esm). Single-sequence and MSA modes; protein, DNA, RNA, ligand (CCD/SMILES), modified residues. FoldBench Ab-Ag 50-55%, PPI 70-77% DockQ-pass. Also covers the ESMC-{300M,600M,6B} protein language models from the same release…

aipoch/open-science · 223 tokens

literature-review

Find, verify, and synthesize scientific literature — from "what's the seminal paper for X" through full multi-source reviews. Covers grounding claims in real retrieved sources, avoiding fabricated citations, handling retractions, and calibrating confidence to evidence strength.

aipoch/open-science · 54 tokens