Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add svy04/ballast --skill pingit clone --depth 1 https://github.com/svy04/ballastWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/svy04/ballast/pin)<a href="https://agentmods.dev/skills/svy04/ballast/pin"><img src="https://agentmods.dev/badge/skills/svy04/ballast/pin.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Rogue Agent · line 43 Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.Fix: Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00057 | $0.01134 |
| Opus 5 | $0.00028 | $0.00567 |
| Sonnet 5 | $0.00011 | $0.00227 |
| Haiku 4.5 | $0.00006 | $0.00113 |
Grade A, and why
pin scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Pin — corrections become rules
A correction that lives only in the conversation dies with the conversation. Pinning it writes it into the ballast rule catalog, so the rules hook delivers it with every future message it applies to.
When the correction follows an incident, classify first
Before writing the rule, name which net failed — the remedy differs by type:
- default regression — the rule existed but wasn't in front of the generating moment → fix delivery: keywords that will actually match future messages
- propagation miss — one surface got fixed, its copies didn't → sweep the remaining surfaces now, then pin; when a ledger decision changed, decision-ledger's supersede sweep is the same move
- delegation leak — the work went through a subagent or external tool the hook never reaches → the rule belongs in the brief, not only the catalog
- variant evasion — only the literal wording was watched and a rephrasing walked through → pin
patterns, not just keywords - compression loss — shortening or re-toning a text dropped something the text had already settled → diff the trimmed version against the one before it, part by part; a rule pinned here belongs in the editing brief, not the keyword catalog
- substitute illusion — something adjacent to what the rule asked for got done, and that was scored as compliance → check that the artifact the rule names actually exists, rather than that the work felt covered
The last two are worth separating from the first: they happen with the rule already in view, so better delivery does not reduce them. One clause in the entry's parenthetical is enough ("propagation miss: fixed README, missed plugin.json"). An apology without a classification fixes nothing. These six types are one owner's working taxonomy, and it grew — it started at four. When an incident fits none of them, that's the next type worth naming.
Steps
- Extract the rule. One imperative sentence, at most two. The user's own wording beats your paraphrase. If the correction references a specific incident, keep the incident as a short parenthetical — future-you needs the why.
- Propose the entry in one compact block and ask nothing else:
id: short kebab-casetitle: a few words — this is the label shown when the rule is injectedwhen.keywords: 4–8 keywords likely to appear in future messages where this rule matters (case-insensitive substring match) — in the language(s) the user actually types. Too-generic keywords ("please", "make") spam every turn; too-narrow ones never fire. For shapes keywords can't catch, addwhen.patterns(regex, case-insensitive).when.always: truefires on every message — reserve it for 1–2 rules at most.body: the rule textaction: omit it (inject is the default) or "block" if the user wants matching requests stopped outright
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 57 lines · 57 tokens per session scan A b3d3987fd3c0
pin is a skill published in the GitHub repository svy04/ballast (71 stars, last pushed 13d ago), licensed MIT. It adds 57 tokens to every session and 1,134 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
alive:save
The human wants to checkpoint. Or: the stash has grown heavy — 5+ items, 30+ minutes, a natural pause in the work. The squirrel doesn't decide when to save. It surfaces the need and lets the human pull the trigger. Runs the full save protocol: confirms stash, writes log, updates state, generates projections…
alive:capture-context
Use when external content arrives in the session — emails, transcripts, screenshots, documents, files, or in-session research worth keeping. Also use when there's nothing obvious to capture — the skill checks 03Inbox/ for unrouted files and enters inbox scan mode. Stores raw content, routes to bundles, extracts tasks…
alive:load-context
The human mentions a walnut to work on, asks about a specific venture/experiment/project, or wants to check status — not just explicit 'load X'. Load the brief pack (3 files), resolve the people involved, check the active bundle — then surface one observation and ask what to work on. Context loads in tiers: walnut and…
alive:session-history
Revive sessions (quick or heavy), browse, and search — 'what happened recently?', 'find the session where we discussed X', 'revive yesterday's session'. For single-session recall and multi-session browsing. If the human needs to merge multiple sessions into one working context or detect conflicts between parallel…
alive:mine-for-context
Deep context extraction from source material. Creates reference bundles, builds extraction plans, tracks what's been extracted, and discovers new targets — people, subjects, patterns, connections. The archaeologist that turns raw sources into structured knowledge. Can be invoked by alive:session-history for targeted…
alive:my-context-graph
Render an interactive map of your world. Generates the world index from all walnut and bundle frontmatter, then produces a force-directed graph showing connections between walnuts, people, bundles, and tags. Opens in the browser.