Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add skyfox675/agents-skills --skill jira-issue-lockinggit clone --depth 1 https://github.com/skyfox675/agents-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/skyfox675/agents-skills/jira-issue-locking)<a href="https://agentmods.dev/skills/skyfox675/agents-skills/jira-issue-locking"><img src="https://agentmods.dev/badge/skills/skyfox675/agents-skills/jira-issue-locking/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/skyfox675/agents-skills/jira-issue-locking"><img src="https://agentmods.dev/badge/skills/skyfox675/agents-skills/jira-issue-locking.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Excessive Agency · line 251 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00191 | $0.05413 |
| Opus 5 | $0.00096 | $0.02707 |
| Sonnet 5 | $0.00038 | $0.01083 |
| Haiku 4.5 | $0.00019 | $0.00541 |
Grade A, and why
jira-issue-locking scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 267 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Locking Jira Issues: Claim, Coordinate, Release
Multiple orchestrator sessions — run by different humans, on different machines, at the same time — work the same Jira issue queue. Without a claim protocol, two agents silently pick up the same issue, burn duplicate work, and open conflicting PRs. This skill is the claim protocol: how to lock a Jira issue before dispatching work, how to recognize and respect (or reclaim) someone else's lock, and how to release cleanly on every exit path.
All Jira reads and writes here go through the Atlassian MCP server (the official Atlassian Remote MCP); operations are referenced by their canonical tool names (getJiraIssue, editJiraIssue, searchJiraIssuesUsingJql, addCommentToJiraIssue, transitionJiraIssue, lookupJiraAccountId, atlassianUserInfo). Exact tool names depend on the connected server. An adopter without the Atlassian MCP can substitute the Jira REST v3 API or a Jira CLI for the same operations — the protocol is identical, only the call surface changes.
Related skills: pick what to claim with the jira-issue-filing and jira-issue-fields skills; dispatch the work with the dispatching-subagents skill; run the surrounding loop with the orchestrating-slots skill; drive the resulting PR with the driving-prs-to-merge skill.
Project bindings
These values are project policy, not protocol. The adopting project defines them in its own CLAUDE.md; this skill refers to them by placeholder.
| Binding | Meaning | Illustrative default |
|---|---|---|
<jira-project-key> |
Project key for JQL project = ... scoping (e.g. PROJ) |
— |
<jira-site>/cloudId |
The Jira site the MCP targets | — |
<integration-branch> |
Branch agent PRs merge into | dev (default branch was main) |
<jira-done-status> |
Workflow status meaning "resolved/closed" | Done |
<jira-inprogress-status> |
Workflow status meaning "an agent is on it" | In Progress |
<jira-ready-status> |
Workflow status for queued, dispatchable work | Ready |
<claim-label> |
Site-wide "an automation holds this" label | agent-claimed — created on first use, no bootstrap needed |
<lock-marker> |
Stable greppable token in every lock comment | claude-lock: |
<hold-label> |
Operator-held "humans only, never dispatch" label | do-not-dispatch — Jira label-name comparisons are case-sensitive; pick one casing and let every filter assume it (lowercase, single-token, no spaces) |
<stale-window> |
Lock age threshold before reclaim is considered | 24h (tune to typical PR cycle time) |
<worktree-dir> |
Where agent worktrees live | see the dispatching-subagents skill |
<chat-channel> |
Team real-time channel for urgent pings | Slack |
<bot-trigger> |
The project's human-only AI-mention trigger | @claude |
| Operator identities | Informational roster of known operators | resolve dynamically — see below |
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 267 lines · 191 tokens per session scan A 2b94b06f9959
jira-issue-locking is a skill published in the GitHub repository skyfox675/agents-skills (10 stars, last pushed 9d ago), licensed MIT. It adds 191 tokens to every session and 5,413 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
recipe-create-meet-space
Create a Google Meet meeting space and share the join link.
workthreads
SpecStory Workthreads - a weekly work-thread rollup across a team's repos from SpecStory coding histories (any agent - Claude Code, Codex, Cursor, Gemini, and more). It groups the window's sessions into threads of work per project and labels each new / open / recently closed, so a lead sees what shipped, what is still…
atmos-config
Atmos root configuration: atmos.yaml discovery, precedence, deep merging, basepath, imports, minimal bootstrap, and routing to narrower Atmos skills.
story-readiness
Validate that a story file is implementation-ready. Checks for embedded GDD requirements, ADR references, engine notes, clear acceptance criteria, and no open design questions. Produces READY / NEEDS WORK / BLOCKED verdict with specific gaps. Use when user says 'is this story ready', 'can I start on this story', 'is…
autotask-creator
Rules for automation CRUD from the group-chat commander. The commander does not call mutation tools and does not edit cloud/autotasks files directly. It emits one or more top-level ... containers in its final text; the bus parses and applies them after the turn.
projects
List all managed projects with status, branch, open PRs, and open issue counts — portfolio-level view.