Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/snapsynapse/skill-provenance/closenpx skills add snapsynapse/skill-provenance --skill closegit clone --depth 1 https://github.com/snapsynapse/skill-provenanceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/snapsynapse/skill-provenance/close)<a href="https://agentmods.dev/skills/snapsynapse/skill-provenance/close"><img src="https://agentmods.dev/badge/skills/snapsynapse/skill-provenance/close.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00083 | $0.00834 |
| Opus 5 | $0.00042 | $0.00417 |
| Sonnet 5 | $0.00017 | $0.00167 |
| Haiku 4.5 | $0.00008 | $0.00083 |
Grade A, and why
close scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 87 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill Provenance: Close
Update all version-tracking artifacts when finishing a skill editing session. This ensures the bundle leaves the session in a consistent, verifiable state.
When to use
Run /skill-provenance:close after you've finished editing files in a skill
bundle and before committing, packaging, or handing off.
Protocol
-
Validate before mutation. Run verify-only
validate.shfirst when available. Resolve structural grammar, unsafe or duplicate paths, symlink components, and missing files before updating hashes. Hash mismatches and missing or malformed hashes may then be repaired with an explicitvalidate.sh --updateworkflow;hash: nullremains an intentional opt-out. -
Update internal version headers. For each changed file that carries YAML frontmatter with version metadata:
- Increment
versionby 1. - Set
version_dateto today. - Set
previous_versionto the old version number. - Write a
change_summary(1-3 sentences describing what changed, not just that something changed).
- Increment
-
Update MANIFEST.yaml. For every changed versioned file:
- Update
versionto match the new internal version. - Recompute and update
hash. - For files that don't carry internal headers (JSON, scripts, binaries),
the manifest
versionfield is authoritative — increment it there. - Bump
bundle_version(semver): PATCH for fixes/docs, MINOR for new features, MAJOR for breaking changes. - Update
bundle_dateto today. - If the user deployed or reinstalled the skill this session, update
relevant
deploymentsmetadata.
- Update
-
Update CHANGELOG.md. Add a new entry at the top:
- Use the new
bundle_versionand today's date as the heading. - Name every file that changed and what changed in it.
- Flag staleness explicitly. If a versioned file was changed but a dependent file was not updated (e.g., SKILL.md changed but evals.json wasn't updated to match), say so in the entry.
- Use the new
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 87 lines · 83 tokens per session scan A 7e248dc2dd43
close is a skill published in the GitHub repository snapsynapse/skill-provenance (7 stars, last pushed 5d ago), licensed MIT. It adds 83 tokens to every session and 834 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
docs-changelog
Generates and formats changelog files for a new release based on provided version and raw changelog data.
bump-version
Use when bumping the AionUi version: query AionCore release, verify artifacts, update package.json, generate CHANGELOG, branch, commit, push, create PR, auto-merge, tag release.
release
Use this skill for EVERY ClawRouter release. Enforces the full checklist — version sync, CHANGELOG, build, tests, npm publish, git tag, GitHub release. No step can be skipped.
changelog
Generate or update the CHANGELOG.md for a new release version. Use when the user says "generate changelog", "update changelog", "write release notes", or asks to prepare a changelog for a version like "changelog for 0.5.3".
version-bump
Skill "version-bump" from BenedictKing/ccx, covering 版本号升级技能, 指令, 中文触发条件, 参数说明 and 发布选项.
store-update
在 CCX Desktop 发布后下载 Store MSIX 并生成发布公告。用户提到 Store 上架、MSIX、从 GitHub Release 下载 store.msix、发布后同步 Windows Store、从 release 填写商店更新内容时必须使用此技能。该技能会下载最新 GitHub Release 的 amd64/arm64 MSIX,校验 sha256,从 Release body 生成 Store listing releaseNotes 预览,并输出手动上传指引。.