tmb_skill-creator

A skill for creating a reusable project-local instruction file for coding agents and attaching it to selected agents.

In plain words
What is it for?
Use it to define a new skill, choose which agents receive it, set when it activates, and check the draft with the provided lint command.
Why use it?
It turns a repeatable behavior into documented instructions that can load automatically in the situations you choose.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/trustmybot/plugin/tmb_skill-creator
Any agent
npx skills add trustmybot/plugin --skill tmb_skill-creator
Clone the repo
git clone --depth 1 https://github.com/trustmybot/plugin

Made for: Claude Code, Codex.

Per session 125 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 786 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00125 $0.00786
Opus 5 $0.00063 $0.00393
Sonnet 5 $0.00025 $0.00157
Haiku 4.5 $0.00013 $0.00079

Measured 2d ago against content hash 18c6abecb3d4, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

tmb_skill-creator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

The scan reads SKILL.md. This mod also ships 1 executable file (scripts/prompt-author-lint.sh), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/tmb_skill-creator/SKILL.md · 48 lines

How it starts

The opening of the file, as written. The whole thing — 48 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Skill Creator

If the original ask depended on the new skill being in place, bro holds it until the skill exists + is attached + approved.

Discover the gap

Ask three questions in one AskUserQuestion batch: (1) what to call the skill — propose 1–3 names from context, lowercase with hyphens; (2) which agents to attach it to — list from .claude/agents/; (3) when it activates — always or path-scoped.

Draft

Author at <project>/.claude/skills/<name>/SKILL.md using this frontmatter template:

---
name: <name>
description: <one sentence — when this skill auto-loads. Be specific so the harness picks it up reliably; CC matches descriptions to context.>
allowed-tools: <optional, comma-separated — restricts tools the skill can invoke>
---

# <Title — Human-Readable>

[Body — concrete rules, checks, or patterns the agent should apply when this skill is loaded. Keep it focused.]

Skill structure: keep flat (single SKILL.md) — do not split into reference.md / forms.md / scripts/. Inline lookup tables and AUQ shapes; bundle scripts only when truly executable.

Then run ${CLAUDE_PLUGIN_ROOT}/scripts/prompt-author-lint.sh <draft-path>, surface findings via AUQ (user picks accept/decline per finding), and present the full drafted file in a fenced code block. Ask:

Do you want me to (a) write this skill at .claude/skills/<name>/SKILL.md, AND (b) extend the skills: frontmatter array of to include <name>? (yes / revise / no)

Write on approval

skill_register the name, then write the skill file, append the new name to each attach-list agent's skills: array (and only that array). If there's no open issue (free-floating skill creation — common), issue_create one scoping it. Record an audit event noting the skill and its carrying agents, and tell the Human in one line: skill landed at <path>; attached to <agents>.

Hard rules

  • Agent body is off-limits. The only allowed edit is appending to its skills: array.
  • Existing project skills require name collision resolution. Name collision = Human resolves.
  • Approval is non-negotiable. Write nothing without an explicit Yes.
  • Stay focused. A skill should encode one cohesive concern. If the body grows past ~80 lines, propose trimming or splitting.

Read the full file on GitHub · 48 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 48 lines · 125 tokens per session scan A 18c6abecb3d4

Subscribe to this mod's changes

tmb_skill-creator is a skill published in the GitHub repository trustmybot/plugin (6 stars, last pushed 2d ago), licensed MIT. It adds 125 tokens to every session and 786 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

skill-template

Template for creating new Agent Skills for context engineering. Use this template when adding new skills to the collection.

muratcankoylan/Agent-Skills-for-Context-Engineering · 24 tokens

create-skill

Guides users through creating effective Agent Skills for Cursor. Use when the user wants to create, write, or author a new skill, or asks about skill structure, best practices, or SKILL.md format.

xstongxue/best-skills · 46 tokens

creating-skills

Guide for creating Claude Code skills following Anthropic's official best practices. Use when user wants to create a new skill, build a skill, write SKILL.md, update an existing skill, or needs skill creation guidelines. Provides structure, frontmatter fields, naming conventions, and new features like dynamic context…

redai-infra/Relax · 70 tokens

aish-add-skills

Create new skills from documents, tutorials, or examples. Use when user wants to create a skill from learning materials or existing content.

AI-Shell-Team/aish · 32 tokens

master-debate

Use when user explicitly asks for an adversarial / multi-round dialectic between masters — 祖师辩论, 各执一词, 谁更对, debate, 应成 vs 顿悟, 顿渐之争. Differs from /compare-masters (parallel single-round) by being adversarial multi-round via fresh-subagent orchestration. Topics 空有 / 禅净 / 性相 / 戒律 vs 内观 — trigger is adversarial framing…

xr843/Master-skill · 127 tokens

skill-master

Guides skill creation and updates with specialized knowledge and workflows. Use when: "создай скилл", "измени скилл", "гайд по скиллам", "обнови скилл", "улучши скилл", "create skill", "update skill", "skill guide", "new skill", "how to write a skill".

pavel-molyanov/molyanov-ai-dev · 79 tokens