Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add tsai09495/matt-pocock-engineering --skill setup-matt-pocock-skillsgit clone --depth 1 https://github.com/tsai09495/matt-pocock-engineeringWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/tsai09495/matt-pocock-engineering/setup-matt-pocock-skills)<a href="https://agentmods.dev/skills/tsai09495/matt-pocock-engineering/setup-matt-pocock-skills"><img src="https://agentmods.dev/badge/skills/tsai09495/matt-pocock-engineering/setup-matt-pocock-skills/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/tsai09495/matt-pocock-engineering/setup-matt-pocock-skills"><img src="https://agentmods.dev/badge/skills/tsai09495/matt-pocock-engineering/setup-matt-pocock-skills.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00040 | $0.01013 |
| Opus 5 | $0.00020 | $0.00507 |
| Sonnet 5 | $0.00008 | $0.00203 |
| Haiku 4.5 | $0.00004 | $0.00101 |
Grade A, and why
setup-matt-pocock-skills scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 120 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Setup Matt Pocock Skills
This explicit-only, normally one-time workflow configures the repository conventions consumed by Matt Engineering. Explore first, present a complete preview, and write only after approval.
Outputs
- an
## Agent skillsblock in the repository's existingCLAUDE.mdorAGENTS.md; docs/agents/issue-tracker.md;docs/agents/domain.md;docs/agents/triage-labels.mdonly whentriageis available.
Do not create application code, issues, labels, Wayfinder maps, or ADRs during setup.
1. Explore
Read without mutation:
- repository guidance and
git remote -v/.git/config; - existing
CLAUDE.md,AGENTS.md, and any## Agent skillsblock; CONTEXT.md,CONTEXT-MAP.md, relevantdocs/adr/, anddocs/agents/;.scratch/and existing tracker conventions;- whether
triageis available; - genuine monorepo signals such as workspace configuration or independently structured packages.
Default to a single context. Ask about multi-context only when the repository provides real monorepo or bounded-context evidence.
2. Resolve configuration one section at a time
Lead each question with a recommendation and one-line consequence.
A. Issue tracker
Recommend the tracker already used by the repository:
- GitHub when a GitHub remote and
ghworkflow exist; - GitLab when a GitLab remote and
glabworkflow exist; - local Markdown under
.scratch/for local or solo work; - another tracker when the user describes its operations.
Explain that to-spec, to-tickets, triage, and explicit Wayfinder need read, publish, dependency, and claim conventions. The GitHub/GitLab templates keep external PR/MR triage disabled by default.
B. Triage labels
Skip this section when triage is unavailable. Otherwise recommend the canonical labels and ask one question: keep defaults?
needs-triageneeds-infoready-for-agentready-for-humanwontfix
Collect overrides only when the repository already uses another vocabulary.
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 120 lines · 40 tokens per session scan A 9d1b9656cf36
setup-matt-pocock-skills is a skill published in the GitHub repository tsai09495/matt-pocock-engineering (2 stars, last pushed 16d ago), licensed MIT. It adds 40 tokens to every session and 1,013 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
manage-taskboard
Manage Codex Taskboard / e-taskboard work with taskctl. Use for taskboard issue IDs, status sync, comments, or taskctl cloud setup—not for unrelated product docs.
merge-review
Reviews pending fleet worktree merges before they're accepted. Reads the merge-check queue, detects file-level conflicts between branches, proposes a safe merge order, and surfaces reconciliation plans for overlapping changes.
workspace
Multi-repo campaign coordinator. Same lifecycle as fleet -- scope claims, discovery relay, wave-based execution -- but the unit of work is a repo, not a file. Coordinates campaigns across repositories with shared context.
decision-map
Turn a loose idea into a git-tracked, session-resumable map of typed investigation tickets, then drive them to resolution one at a time. The planning-loop engine for work that is still being figured out — too fuzzy for a campaign, too big for a single intake item. Resolved tickets graduate into .planning/intake/ for…
unharness
Safely leave Citadel using the active adoption receipt. Produces a no-write, reviewable plan, preserves a portable archive, removes only exact owned material, and reports modified or externally registered surfaces as retained or unknown. Legacy installs must be imported before exact leave is claimed.
to-issues
A planning aid that breaks a PRD or technical specification into small implementation issues, each covering a complete, demonstrable piece of work.