Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add sublimecoder/aios --skill ai-tellsgit clone --depth 1 https://github.com/sublimecoder/aiosWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/sublimecoder/aios/ai-tells)<a href="https://agentmods.dev/skills/sublimecoder/aios/ai-tells"><img src="https://agentmods.dev/badge/skills/sublimecoder/aios/ai-tells/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/sublimecoder/aios/ai-tells"><img src="https://agentmods.dev/badge/skills/sublimecoder/aios/ai-tells.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00104 | $0.02388 |
| Opus 5.5 | $0.00042 | $0.00955 |
| Sonnet 5.5 | $0.00021 | $0.00478 |
| Haiku 4.5 | $0.00010 | $0.00239 |
Grade A, and why
ai-tells scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 20d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 169 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AI tells
A tell is an involuntary giveaway. Not a rule violation, a habit that leaks the writer's nature. You are hunting tells, not scoring "AI-ness": detectors are unreliable, humans score near chance on this task, and no single tell is proof. Density is the signal. Three tells in a paragraph is a rewrite. One em dash is nothing.
Distilled from Wikipedia:Signs of AI writing (read 2026-07-24), filtered to what applies to first-person prose. Its wikitext, DOI/ISBN, category, template, and edit-summary sections are Wikipedia-specific and deliberately dropped.
Run order
- Grep pass — mechanical, catches the lexical tells.
- Read pass — the structural tells no grep sees (§ Read pass).
- Rewrite, then re-grep. Fixing one tell routinely plants another: killing repetition invites synonym-churn, killing "serves as" invites "functions as".
Done when: grep is clean or every surviving hit is a named deliberate keep, every Read-pass item has been walked one at a time, and the prose still sounds like its author rather than like nobody.
Grep pass
Two passes, because hard-wrapped prose splits multi-word phrases across
newlines — in a file wrapped at ~70 characters, rather than is invisible
to a line-based grep about half the time. Run pass B whenever the target is
wrapped; skip it only when the file is one paragraph per line.
F=path/to/draft.md # set to the file under audit
# A1. Model junk markers. Any hit is unconditional deletion.
grep -noE 'contentReference|oai_?citation|oaicite|turn[0-9]+(search|view|image)|attributableIndex|\[cite: |grok_(card|render)|ppl-ai-file-upload|attached_file|:::writing' "$F"
# A2. Lexical tells, as a frequency table. Read the counts, not the list.
grep -nioE '\b(serves? as|stands? as|functions? as|operates? as|boasts?|underscor(es?|ing)|showcas(es?|ing)|emphasiz(es?|ing)|highlight(s|ing)|foster(s|ing)|enhanc(es?|ing)|leverag(es?|ing)|pivotal|crucial|vital role|testament|tapestry|delve|intricate|meticulous|vibrant|robust|seamless(ly)?|enduring|realm of|landscape|navigat(e|ing|ion))\b' "$F" \
| cut -d: -f2- | tr 'A-Z' 'a-z' | sort | uniq -c | sort -rn
# A3. Vague attribution. Collides with fact-grounding; treat every hit as a sourcing bug.
grep -niE '\b(experts? (say|argue|agree|note)|industry reports?|observers have|some critics|studies show|research shows|widely (held|regarded|considered))\b' "$F"
# A4. Typography. Count em dashes against the deliberate keeps below.
printf 'em dashes: %s\n' "$(grep -o '—' "$F" | wc -l | tr -d ' ')"
grep -nE $'[‘’“”]' "$F" # curly quotes/apostrophes: match the file's own convention
# B. De-wrapped phrase pass. No line numbers, so it answers "is it in here",
# then you locate it by searching the phrase.
tr '\n' ' ' < "$F" | grep -oiE \
"not (only|just|merely|simply)[^.]{0,60}\bbut\b|\b(it|this|that)(.s not|( i)?sn.t) [^.]{0,40}[.,] +it.s|\bnot a [^.]{0,40}, not a\b|\brather than\b|despite (its|the|this)[^.]{0,80}(challenge|obstacle|hurdle)|faces (several|numerous|various)|\bnavigate the landscape\b|in today.s [^.]{0,20}world|it.s worth noting|in conclusion" \
| sort | uniq -c | sort -rn
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 20d ago First seen · 169 lines · 104 tokens per session scan A e52a0a5b4e46
ai-tells is a skill published in the GitHub repository sublimecoder/aios (2 stars, last pushed 21d ago), licensed MIT. It adds 104 tokens to every session and 2,388 once invoked, about $0.0004 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-19.
Other skills, from other repositories
pos-verify
Use this immediately after files are created, edited, moved, deleted, or materially rewritten inside PersonalOS. Verifies that new truth was routed to the correct owner, written in the correct file shape, and still follows POS conventions. Do NOT use for whole-vault deep audits; use system-health-check.
skillify
Use this when {{username}} asks to skillify a repeated workflow, determine whether it deserves a reusable PersonalOS skill, or harden an existing workflow into a tested resolver-reachable capability. Do NOT use for one-off notes, ordinary execution, or already-specified skill authoring; use write-skill.
write-skill
Use this when the user wants to create a new shared PersonalOS skill under skills/ or revise a specified PersonalOS skill and the scope is already clear. Do NOT use for raw workflow capture or deciding whether work should become a skill; use skillify first. Do NOT use for repo-local or agent-local skills unless…
priority-dashboard
Use this to rebuild, inspect, or temporarily steer {{username}}'s current PersonalOS priority dashboard from canonical Actions, Attention Triggers, and owner context. Do NOT use it to create, complete, or independently manage tasks; use task-manager for Action and Trigger lifecycle changes.
log
Use this when a PersonalOS work session, chat outcome, personal reflection, or provided source should be persisted into the modular Daily context and any already-owned canonical files. Do NOT use for single-call processing, single-source knowledge ingestion, Gmail/WhatsApp propagation, or Lexware booking.
task-manager
Use this when {{username}} or an agent wants to add, review, prioritize, complete, defer, park, or inspect todos, open loops, confirmed actions, waiting states, or attention triggers. Maintains atomic records under operations/actions/ and operations/attention-triggers/ as the only local action truth. Do NOT use for…