Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/skilletmd/skillet/commit-messagenpx skills add skilletmd/skillet --skill commit-messagegit clone --depth 1 https://github.com/skilletmd/skilletWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00042 | $0.00554 |
| Opus 5 | $0.00021 | $0.00277 |
| Sonnet 5 | $0.00008 | $0.00111 |
| Haiku 4.5 | $0.00004 | $0.00055 |
Grade A, and why
commit-message scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
commit-message
The diff shows what changed. The commit message exists to say why — the context that isn't in the code and won't be in anyone's head in six months. This skill writes that.
When to use
Any commit worth more than git commit -m "fix". Especially before committing a change whose reason isn't obvious from the diff.
Read what you're committing
git diff --staged
Commit one logical change at a time. If the staged diff does two unrelated things, that's two commits — git restore --staged <file> to split them.
The format
<type>: <subject, imperative, under 50 chars>
<body: why this change, what it affects, wrapped at 72 chars>
Subject line:
- Imperative mood: "add", "fix", "remove" — not "added" or "fixes". It completes the sentence "If applied, this commit will ___."
- Under 50 characters. If it won't fit, the commit is probably too big.
- No trailing period.
Type (conventional commits — optional, but be consistent):
feat, fix, refactor, docs, test, chore, perf.
Body (skip it only when the subject is genuinely complete on its own):
- Explain why, not what — the diff already shows what.
- Note side effects, migrations, or anything a future reader would be surprised by.
- Reference the issue:
Closes #123.
Example
fix: stop double-charging on retried checkout
The payment client retried on a 504 without checking whether the
first request had already succeeded, charging some customers twice.
Make the charge idempotent, keyed on the order ID.
Closes #482
The diff alone would show a reviewer a new idempotency_key parameter. The message is where the why lives.
What to avoid
"fix bug","update","wip","changes"— these cost a future engineer agit blameand a guess.- Restating the diff: "changed line 42 in auth.js" — they can see that.
- Bundling unrelated changes so the subject has to list three things with "and".
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 64 lines · 42 tokens per session scan A 2160c5c12d01
commit-message is a skill published in the GitHub repository skilletmd/skillet (3 stars, last pushed 2d ago), licensed Apache-2.0. It adds 42 tokens to every session and 554 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
auth-web-cloudbase
CloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked. Provides concise and practical Web authentication solutions with multiple login methods and complete user management.
fix-codesign-error
Slash command that inspects a macOS signing or entitlement failure and explains the minimum fix path. Invoke explicitly with /fix-codesign-error — this skill never self-triggers.
browse-and-evaluate
Use when exploring the ai-agent-skills catalog to find, compare, and evaluate skills before installing. Always use --fields to limit output size and --dry-run before committing to an install.
specflow-use
To connect Rosetta with Grid Dynamics SpecFlow MCP; only when SpecFlow is mentioned and the MCP is installed.
loop-engineering
Shared loop-engineering reference for COG skills - the agent loop, deterministic verifiers, termination conditions, in-loop context management, and named patterns. Invoke when designing or debugging a skill that iterates (search-verify-retry, scan-until-dry, fetch-retry-gate).
telnyx-messaging-hosted-curl
Set up hosted SMS numbers, toll-free verification, and RCS messaging. Use when migrating numbers or enabling rich messaging features. This skill provides REST API (curl) examples.