Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/trystan-sa/postkit/postkit-releasenpx skills add Trystan-SA/postkit --skill postkit-releasegit clone --depth 1 https://github.com/Trystan-SA/postkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00078 | $0.01605 |
| Opus 5 | $0.00039 | $0.00803 |
| Sonnet 5 | $0.00016 | $0.00321 |
| Haiku 4.5 | $0.00008 | $0.00161 |
Grade A, and why
postkit-release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 169 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/postkit-release — cut a new postkit release
You are a release manager for the postkit npm package. Your job is to take
the current main branch, bump the version, tag it, publish a GitHub
Release, and publish to npm — in that exact order, with verification at
every step.
This skill operates on the postkit repo itself, not on a user's
scaffolded project. If the working directory isn't the postkit repo
(check that package.json has "name": "postkit"), stop and tell the
user.
Before you start — preflight
Run these checks in parallel and bail if any fails:
git status— working tree must be clean. No uncommitted changes, no untracked files that should be committed.git rev-parse --abbrev-ref HEAD— must be onmain.git fetch origin && git status -sb— local must be up to date withorigin/main(noahead/behind).gh auth status—ghmust be authenticated. If not, tell the user to rungh auth loginand stop.npm whoami— npm must be authenticated. If it errors, tell the user to runnpm loginand stop.- Read
package.jsonand note the current version (X.Y.Z).
If preflight fails, surface the specific failure and stop. Do not attempt to "fix" by stashing, force-pushing, or skipping checks.
Step 1 — Ask which kind of bump
Ask the user one question with three concrete options, showing the resulting version for each:
"Current version is
X.Y.Z. Which bump?
- patch →
X.Y.(Z+1)(bug fixes, doc tweaks, internal changes)- minor →
X.(Y+1).0(new skill, new feature, backwards-compatible additions)- major →
(X+1).0.0(breaking change to the scaffolder contract or skill APIs)"
Wait for the answer. If the user picks something ambiguous, ask again. Do not assume.
While you're at it, ask: "Anything specific you want highlighted in the release notes?" — short answer is fine, can be skipped.
Step 2 — Summarize the changes since last release
Find the previous tag and gather the commits since:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 169 lines · 78 tokens per session scan A 7d817d9cea42
postkit-release is a skill published in the GitHub repository Trystan-SA/postkit (4 stars, last pushed 4mo ago), licensed MIT. It adds 78 tokens to every session and 1,605 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…