Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/striderza/opencodegamestudios/create-control-manifestnpx skills add striderZA/OpenCodeGameStudios --skill create-control-manifestgit clone --depth 1 https://github.com/striderZA/OpenCodeGameStudiosWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/striderza/opencodegamestudios/create-control-manifest)<a href="https://agentmods.dev/skills/striderza/opencodegamestudios/create-control-manifest"><img src="https://agentmods.dev/badge/skills/striderza/opencodegamestudios/create-control-manifest.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00063 | $0.02144 |
| Opus 5 | $0.00032 | $0.01072 |
| Sonnet 5 | $0.00013 | $0.00429 |
| Haiku 4.5 | $0.00006 | $0.00214 |
Grade A, and why
create-control-manifest scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
94% identical to create-control-manifest — 22 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 277 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Create Control Manifest
The Control Manifest is a flat, actionable rules sheet for programmers. It answers "what do I do?" and "what must I never do?" — organized by architectural layer, extracted from all Accepted ADRs, technical preferences, and engine reference docs. Where ADRs explain why, the manifest tells you what.
Output: docs/architecture/control-manifest.md
When to run: After /architecture-review passes and ADRs are in Accepted
status. Re-run whenever new ADRs are accepted or existing ADRs are revised.
1. Load All Inputs
ADRs
- Glob
docs/architecture/adr-*.mdand read every file - Filter to only Accepted ADRs (Status: Accepted) — skip Proposed, Deprecated, Superseded
- Note the ADR number and title for every rule sourced
Technical Preferences
- Read
docs/framework/technical-preferences.md - Extract: naming conventions, performance budgets, approved libraries/addons, forbidden patterns
Engine Reference
- Read
docs/engine-reference/[engine]/VERSION.mdfor engine + version - Read
docs/engine-reference/[engine]/deprecated-apis.md— these become forbidden API entries - Read
docs/engine-reference/[engine]/current-best-practices.mdif it exists
Report: "Loaded [N] Accepted ADRs, engine: [name + version]."
2. Extract Rules from Each ADR
For each Accepted ADR, extract:
Required Patterns (from "Implementation Guidelines" section)
- Every "must", "should", "required to", "always" statement
- Every specific pattern or approach mandated
Forbidden Approaches (from "Alternatives Considered" sections)
- Every alternative that was explicitly rejected — why it was rejected becomes the rule ("never use X because Y")
- Any anti-patterns explicitly called out
Performance Guardrails (from "Performance Implications" section)
- Budget constraints: "max N ms per frame for this system"
- Memory limits: "this system must not exceed N MB"
Engine API Constraints (from "Engine Compatibility" section)
- Post-cutoff APIs that require verification
- Verified behaviours that differ from default LLM assumptions
- API fields or methods that behave differently in the pinned engine version
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 277 lines · 63 tokens per session scan A d87bc8d20ad7
create-control-manifest is a skill published in the GitHub repository striderZA/OpenCodeGameStudios (83 stars, last pushed 24d ago), licensed MIT. It adds 63 tokens to every session and 2,144 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 94% identical to create-control-manifest, differing in 22 lines, and is treated as a copy.
Other skills, from other repositories
generated-raster-asset-pipeline
Define acceptance, validation, and runtime integration rules for raster assets generated with image models before they become real project content.
tilemap-pipeline
Define tileset creation, auto-tile rules, collision shapes, and tilemap configuration for 2D levels.
game-feel-design
Design moment-to-moment feedback — hit-stop, screen shake, tweening, and response timing — so actions feel readable and satisfying.
combat-design
Design combat verbs, enemy pressure, resource economy, readability, and tuning hooks.
level-design
Shape level flow, pacing, navigation, encounter staging, and spatial teaching.
monetization-design
Design monetization systems that fit the product, respect player trust, and remain technically and legally manageable.