Borrowing it
Nothing to install: this file belongs to takeshy/obsidian-gemini-helper. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/takeshy/obsidian-gemini-helper/master/.agents/skills/gemini-best-practices/SKILL.mdgit clone --depth 1 https://github.com/takeshy/obsidian-gemini-helperWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/takeshy/obsidian-gemini-helper/gemini-best-practices)<a href="https://agentmods.dev/skills/takeshy/obsidian-gemini-helper/gemini-best-practices"><img src="https://agentmods.dev/badge/skills/takeshy/obsidian-gemini-helper/gemini-best-practices/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/takeshy/obsidian-gemini-helper/gemini-best-practices"><img src="https://agentmods.dev/badge/skills/takeshy/obsidian-gemini-helper/gemini-best-practices.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00040 | $0.01069 |
| Opus 5 | $0.00020 | $0.00535 |
| Sonnet 5 | $0.00008 | $0.00214 |
| Haiku 4.5 | $0.00004 | $0.00107 |
Grade A, and why
gemini-best-practices scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- gemini-best-practices — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 110 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Gemini API Best Practices
When reviewing or modifying Gemini API integration code, ensure compliance with Google's official best practices from google-gemini/gemini-skills.
SDK and Package
- Correct SDK:
@google/genai(npm) - NEVER use deprecated:
@google/generative-ai(old package) - Prefer environment variables for API keys over hard-coding
Safety Settings
All API calls (generateContent, generateContentStream, chats.create) MUST include safetySettings in the config:
import { HarmCategory, HarmBlockThreshold, type SafetySetting } from "@google/genai";
const DEFAULT_SAFETY_SETTINGS: SafetySetting[] = [
{ category: HarmCategory.HARM_CATEGORY_HARASSMENT, threshold: HarmBlockThreshold.BLOCK_MEDIUM_AND_ABOVE },
{ category: HarmCategory.HARM_CATEGORY_HATE_SPEECH, threshold: HarmBlockThreshold.BLOCK_MEDIUM_AND_ABOVE },
{ category: HarmCategory.HARM_CATEGORY_SEXUALLY_EXPLICIT, threshold: HarmBlockThreshold.BLOCK_MEDIUM_AND_ABOVE },
{ category: HarmCategory.HARM_CATEGORY_DANGEROUS_CONTENT, threshold: HarmBlockThreshold.BLOCK_MEDIUM_AND_ABOVE },
];
Response Validation (finishReason)
Always check finishReason on response candidates:
SAFETY- Response blocked by safety filters; inform user to rephraseRECITATION- Blocked due to potential copyrighted content recitationMAX_TOKENS- Output truncated; consider informing userSTOP- Normal completion
import { FinishReason } from "@google/genai";
// Check candidates[0].finishReason after each response
if (candidate.finishReason === FinishReason.SAFETY) {
// Handle blocked response
}
For non-streaming: check response.candidates[0].finishReason before using response.text.
For streaming: check finishReason in chunk candidates.
System Instructions
- Pass via
systemInstructionin config (not as a chat message) - System instructions are interaction-scoped; re-specify on each chat session creation
Tool / Function Calling
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 110 lines · 40 tokens per session scan A 2b2c7c0be2d4
gemini-best-practices is a skill published in the GitHub repository takeshy/obsidian-gemini-helper (114 stars, last pushed 2d ago), licensed MIT. It adds 40 tokens to every session and 1,069 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
dev-loop
Research → Execute → Dual-Review Loop (Code Quality + Issue Resolution) bis beide Reviews bestanden.
review-loop
Iterative code review — fix P1+P2 until clean, report P3 as an offer.
critical-review
Radical-honesty architectural review — questions code, methodology, design, and operational fitness.
mem0-status
Diagnoses mem0 connectivity, API key validity, and memory read/write functionality. Use when memory operations fail, searches return empty, addmemory errors occur, or to verify the plugin is working correctly.
status
Show whether Mem0 memory is working in this repository, covering configuration, capture state, pending flushes, and whether the Mem0 API key is valid. Use when the user asks whether memory is on, why a memory is missing, or anything looks broken.
mem0-test-integration
Verify a Mem0 integration produced by /mem0-integrate. Runs in the same workspace on the same branch (loose coupling) — installs dependencies, runs the repo's native test suite, then exercises a real end-to-end smoke flow against the user's API key. Produces a scorecard. TRIGGER when: user has just run /mem0-integrate…