Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/takubii/smithy/forgenpx skills add takubii/smithy --skill forgegit clone --depth 1 https://github.com/takubii/smithyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/takubii/smithy/forge)<a href="https://agentmods.dev/skills/takubii/smithy/forge"><img src="https://agentmods.dev/badge/skills/takubii/smithy/forge.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00041 | $0.00368 |
| Opus 5 | $0.00020 | $0.00184 |
| Sonnet 5 | $0.00008 | $0.00074 |
| Haiku 4.5 | $0.00004 | $0.00037 |
Grade A, and why
forge scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
forge
Produce a reviewable plan before implementation.
Flow
- Understand the intent and acceptance criteria.
- Research the codebase and collect code facts.
- Identify existing patterns and reference implementations.
- Draft the approach, target files, alternatives, risks, todos, and verification plan.
- Return unresolved product/design questions separately.
Implementation gate
Before the plan is approved:
- Do not edit tracked source files.
- Do not start implementation.
- Return a plan, not a code change.
Research
Record facts, not speculation:
- Relevant files and why they matter.
- Existing patterns to follow.
- APIs, data flow, tests, and constraints.
- Primary sources: code, docs, issues, or external references when used.
Do not ask the user questions that can be answered from the codebase.
Output format
Return:
## Research
- <code facts and references>
## Plan
- Intent:
- Acceptance criteria:
- Non-goals:
- Target files:
- Approach:
- Reference implementations:
- Alternatives rejected:
- Risks:
## Todos
- [ ] <granular implementation step>
## Verification
- Commands:
- Expected checks:
## Open questions
- <only questions requiring user judgment>
Escalation
Ask the user only for decisions that affect product behavior, scope, acceptance criteria, risk, or non-goals. For implementation mechanics, follow the codebase unless the choice has user-visible consequences.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 75 lines · 41 tokens per session scan A 3f076b2168ae
forge is a skill published in the GitHub repository takubii/smithy (2 stars, last pushed 2mo ago), licensed MIT. It adds 41 tokens to every session and 368 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
flow-next-interview
In-depth Q&A to refine a spec, task, or spec file before building. Use when asked to flesh out, refine, or interrogate requirements.
flow-next-audit
Audit .flow/memory/ entries against current code and keep, update, consolidate, replace, delete, or harden each. Use when asked to audit memory or graduate a recurring lesson into a gate.
flow-next-drive
Drive any UI surface like a real user - a web app, a Chromium-backed desktop app (Electron / WebView2, reached over CDP), or a genuinely native app (macOS AppKit/SwiftUI, or a non-CDP webview) reached via the Cua Driver / Computer Use. Detects the surface, picks the best available driver, degrades gracefully. Use to…
flow-next-impl-review
Carmack-level implementation review of changes via the configured backend. Use when asked to review code or a diff in a flow-next repo.
flow-next-make-pr
Open a PR with a cognitive-aid body rendered from flow-next spec state via gh. Use whenever asked to make or open a PR in a flow-next repo.
flow-next-pilot
Single-tick autonomous build-loop conductor. One spec or the backlog, one stage per tick (pipeline.chainStages chains qa into make-pr), emits PILOTVERDICT. Use when asked to pilot a spec or backlog.