Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add terrylica/cc-skills --skill alpha-forge-preshipgit clone --depth 1 https://github.com/terrylica/cc-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/terrylica/cc-skills/alpha-forge-preship)<a href="https://agentmods.dev/skills/terrylica/cc-skills/alpha-forge-preship"><img src="https://agentmods.dev/badge/skills/terrylica/cc-skills/alpha-forge-preship/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/terrylica/cc-skills/alpha-forge-preship"><img src="https://agentmods.dev/badge/skills/terrylica/cc-skills/alpha-forge-preship.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Rogue Agent · line 88 Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.Fix: Prevent the skill from modifying its own code, SKILL.md, or configuration files. Treat skill files as read-only at runtime.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00027 | $0.00700 |
| Opus 5 | $0.00014 | $0.00350 |
| Sonnet 5 | $0.00005 | $0.00140 |
| Haiku 4.5 | $0.00003 | $0.00070 |
Grade A, and why
alpha-forge-preship scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 91 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Alpha Forge Pre-Ship Quality Gates - Phase 1
Quality assurance plugin for Alpha Forge PR review cycle.
Self-Evolving Skill: This skill improves through use. If instructions are wrong, parameters drifted, or a workaround was needed — fix this file immediately, don't defer. Only update for real, reproducible issues.
Overview
Implements 4 bulletproof quality gates to catch 5 of 13 PR #154 issues:
- G5: RNG Determinism (pre-commit)
- G4: URL Fork Validation (pre-commit)
- G8: Parameter Validation (runtime/CI)
- G12: Manifest Sync Validation (CI)
Effectiveness
- Issue Prevention: 42% of PR issues
- False Positive Rate: <1%
- Implementation Time: ~4 hours
- Payoff Period: 2-3 PRs
- Review Cycle Reduction: 30-50%
Key Files
gates/g5_rng_determinism.py- RNG isolation validatorgates/g4_url_validation.py- Fork URL detectorgates/g8_parameter_validation.py- Parameter range validatorgates/g12_manifest_sync.py- Decorator-YAML sync validatororchestrator.py- Master validator coordinatorreference.md- Complete framework documentation
Architecture
All gates enforce the Decorator-as-Single-Source-of-Truth principle:
- Parameter constraints defined in decorators
- Configuration validated at entry points
- Manifest consistency ensured automatically
- Documentation requirements enforced systematically
Integration
Pre-Commit Hook
from gates.g4_url_validation import validate_org_urls
from gates.g5_rng_determinism import validate_rng_isolation
Runtime Parameter Validation
from gates.g8_parameter_validation import ParameterValidator
validator = ParameterValidator()
validator.validate_numeric_range(value, min_val, max_val)
Manifest Validation
from gates.g12_manifest_sync import validate_manifest
issues = validate_manifest("manifest.yaml")
References
- Main Handbook:
/tmp/CANONICAL_PRESHOP_AUDIT_HANDBOOK.md(523 lines) - Implementation Plan:
/tmp/PHASE_1_IMPLEMENTATION_PLAN.md(367 lines) - Project Summary:
/tmp/PROJECT_COMPLETION_SUMMARY.md
What ships with it
26 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- gates/__init__.py 1.6 KB runs code
- gates/g1_documentation_scope.py 6.8 KB runs code
- gates/g10_performance_red_flags.py 6.3 KB runs code
- gates/g12_manifest_sync.py 2.7 KB runs code
- gates/g2_documentation_clarity.py 5.1 KB runs code
- gates/g3_documentation_completeness.py 8.3 KB runs code
- gates/g4_url_validation.py 1.1 KB runs code
- gates/g5_rng_determinism.py 685 B runs code
- gates/g6_warmup_alignment.py 8.8 KB runs code
- gates/g7_parameter_documentation.py 7.3 KB runs code
- gates/g8_parameter_validation.py 4.2 KB runs code
- README.md 3.3 KB
- references/evolution-log.md 683 B
- references/reference.md 12 KB
- tests/__init__.py 50 B runs code
- tests/test_g1_documentation_scope.py 5.6 KB runs code
- tests/test_g10_performance_red_flags.py 5.2 KB runs code
- tests/test_g12_manifest_sync.py 1.3 KB runs code
- tests/test_g2_documentation_clarity.py 5.5 KB runs code
- tests/test_g3_documentation_completeness.py 6.8 KB runs code
- tests/test_g4_url_validation.py 2.2 KB runs code
- tests/test_g5_rng_determinism.py 1.8 KB runs code
- tests/test_g6_warmup_alignment.py 5.5 KB runs code
- tests/test_g7_parameter_documentation.py 6.4 KB runs code
- tests/test_g8_parameter_validation.py 1.1 KB runs code
- tests/test_gates.py 3.6 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 91 lines · 27 tokens per session scan A cc589f96ebc3
alpha-forge-preship is a skill published in the GitHub repository terrylica/cc-skills (73 stars, last pushed today), licensed MIT. It adds 27 tokens to every session and 700 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
github-release-management
GitHub release orchestration — automated versioning, testing, deployment, and rollback. Use when cutting a release, tagging a version, drafting release notes, or coordinating a deploy/rollback workflow.
accessibility-a11y
WCAG 2.2 compliance, ARIA patterns, keyboard navigation, screen readers, automated testing.
core-workflow
Detailed development workflow patterns, checklists, and standards. Auto-loads for complex tasks, planning, debugging, testing, or when explicit patterns are needed. Contains session protocols, git conventions, security checklists, testing strategy, and communication standards.
auto-claude
Autonomous multi-agent coding with git worktree isolation, QA validation, and memory. Use for complex features requiring autonomous implementation.
debug-systematic
Systematic 4-phase debugging methodology for complex, intermittent, or mysterious issues. Use when investigating bugs, race conditions, or unexplained failures.
merge-ready
Run all quality gates before merge — git hygiene, documentation completeness, code review, security audit, build, E2E, goal-backward verification, doc accuracy and UI/UX — then write the changelog entry.