Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/sofiahernandes/margaret/margaret-scannpx skills add sofiahernandes/margaret --skill margaret-scangit clone --depth 1 https://github.com/sofiahernandes/margaretWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/sofiahernandes/margaret/margaret-scan)<a href="https://agentmods.dev/skills/sofiahernandes/margaret/margaret-scan"><img src="https://agentmods.dev/badge/skills/sofiahernandes/margaret/margaret-scan.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00136 | $0.00804 |
| Opus 5 | $0.00068 | $0.00402 |
| Sonnet 5 | $0.00027 | $0.00161 |
| Haiku 4.5 | $0.00014 | $0.00080 |
Grade A, and why
margaret-scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 58 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Hunt exclusively for complexity that doesn't earn its keep. One finding per line: where it lives, what to remove, what stands in its place. Success looks like a smaller tree, not a longer report.
Two scopes:
- diff (default): only the current change is in play.
- repo (pass
repo, or the user asks for an "audit"/"whole codebase"): walk the full tree instead, biggest win listed first. Look for: packages duplicating stdlib or platform behavior, interfaces with exactly one implementer, factories manufacturing a single product, pass-through wrappers that add no behavior, single-export files, unused flags/config, and homegrown reimplementations of stdlib functions.
Reporting shape
L<line>: <tag> <finding>. <fix>. — prefix with <file>: for anything spanning multiple files (diffs with several files, or a repo scan).
Tags:
cut:unreachable code, unused flexibility, a feature nobody asked for. Fix: remove it, nothing replaces it.builtin:custom code duplicating what the standard library already ships. Name the stdlib call.platform:a dependency or handwritten code standing in for a platform capability. Name the capability.overbuilt:one-implementation interface, a config knob nobody flips, a layer with a single caller.condense:identical behavior expressible in fewer lines. Show the shorter version.
Examples
❌ "This SlugGenerator class seems like it might be handling more cases than strictly necessary — worth double-checking whether every branch is needed?"
✅ L18-45: builtin: 30-line slug class reimplementing string normalization. str.lower().replace(' ', '-') plus a regex strip, 2 lines.
✅ L7: platform: left-pad package pulled in for one call. "x".padStart(5, "0"), 0 deps.
✅ store.py:L61: overbuilt: PaymentGatewayInterface with one implementer (Stripe). Inline the Stripe class until a second gateway is real.
✅ L40-58: cut: exponential backoff wrapper around a call that's already idempotent and fast. Nothing replaces it.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 58 lines · 136 tokens per session scan A 399aed50c75b
margaret-scan is a skill published in the GitHub repository sofiahernandes/margaret (2 stars, last pushed 22d ago), licensed MIT. It adds 136 tokens to every session and 804 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
review-local-changes
Review your local uncommitted working-tree changes (git diff plus untracked files) and return actionable improvement suggestions. Use before committing, when nothing has been pushed yet.
attach-review-to-pr
Add line-specific review comments to pull requests using GitHub CLI API.
resolve-fixed-pr-comments
Verify what PR review comments have been addressed (committed/pushed OR uncommitted local changes) and resolve the threads that are genuinely fixed or no longer relevant.
review-pr
Review an existing GitHub pull request and post inline review comments on its diff. Use when the changes are on an opened PR rather than your local working tree.
critique
Comprehensive multi-perspective review using specialized judges with debate and consensus building.
load-pr-comments
Use to load open/unresolved PR review comments then aggregate them as tasks in .specs/comments/.md for parallel agents to fix.