Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ulises-jeremias/agent-toolkit --skill gh-contribution-plannergit clone --depth 1 https://github.com/ulises-jeremias/agent-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ulises-jeremias/agent-toolkit/gh-contribution-planner)<a href="https://agentmods.dev/skills/ulises-jeremias/agent-toolkit/gh-contribution-planner"><img src="https://agentmods.dev/badge/skills/ulises-jeremias/agent-toolkit/gh-contribution-planner/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ulises-jeremias/agent-toolkit/gh-contribution-planner"><img src="https://agentmods.dev/badge/skills/ulises-jeremias/agent-toolkit/gh-contribution-planner.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Excessive Agency · line 44 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00063 | $0.01709 |
| Opus 5 | $0.00032 | $0.00855 |
| Sonnet 5 | $0.00013 | $0.00342 |
| Haiku 4.5 | $0.00006 | $0.00171 |
Grade A, and why
gh-contribution-planner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 161 lines — stays where its author put it; the contents beside it link to each section on GitHub.
GitHub Contribution Planner
Discover what to work on across your GitHub footprint, propose a prioritized
daily plan, and — on approval — fan out parallel sub-agents to open draft PRs.
The skill infers the current user from the authenticated gh CLI, so no
manual configuration is required.
When to use
- "Plan my GitHub contributions for today" / "what should I work on across my repos" / "give me a daily contribution plan".
- You want to maintain your own repositories and forks without manually scanning each one.
- You want to find low-friction openings (good first issues, stale PRs, outdated forks) in projects you have already contributed to.
Do not use this skill to operate on a specific PR you already picked — use
gh-fix-ci, gh-address-comments, or github-cli-workflow directly.
Prerequisites
ghinstalled and authenticated (gh auth statusexits 0). Scopes typically required:repo,read:org.doctorreports this under Integrations.python3for the bundled analyzer.- Network access to
api.github.com(or the host configured viaGH_HOST). - A host that supports parallel sub-agent dispatch (Claude Code's
Tasktool, OpenCode's subagent fan-out, etc.). Hosts without that primitive fall back to sequential execution.
Workflow
-
Verify auth. Run
gh auth status. If unauthenticated, ask the user to rungh auth loginand stop. Do not prompt for tokens. -
Resolve the current user.
gh api user --jq .login— never ask the user; always infer fromgh. -
Run the analyzer.
python3 ~/.local/share/agent-toolkit/skills/gh-contribution-planner/scripts/inspect_contributions.py \ --since 90d --max-per-bucket 5Useful flags:
--json— machine-readable output (recommended when composing with another agent).--user <login>— override the inferred login (useful for testing or planning for an organization the user maintains).--dry-run— print theghcalls the analyzer would make and exit; useful for sanity-checking before a live run.--max-per-bucket <n>— cap items per bucket (default 5).--since <window>— lookback window for recent contributions. Accepts30d,90d,180d, or an ISO date.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 161 lines · 63 tokens per session scan A dc7ae8e23af3
gh-contribution-planner is a skill published in the GitHub repository ulises-jeremias/agent-toolkit (16 stars, last pushed today), licensed MIT. It adds 63 tokens to every session and 1,709 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.
Other skills, from other repositories
github-navigator
GitHub operations via gh CLI. CRITICAL: Use instead of WebFetch for any github.com URL or GitHub repo path like owner/repo. Use when the user asks to inspect repositories, files, issues, pull requests, releases, Actions runs, or repository structure. Use when the user says 'show README', 'list issues', 'check PR'…
active-review
Use when the user wants to prepare for a manual PR code review and asks for help targeting it — a terse PR summary, ranked files to read first, and paste-ready inline comment drafts with GitHub deep-links. Triggers: "active review this PR", "walk me through this PR", "help me review this", "give me inline comments to…
bisect
Use when hunting a regression, phrases like "bisect", "find the commit that broke X", "this used to work", "regression in test Y", "when did start". Also use when escalated from ci-debug-loop because log analysis can't pinpoint the offending change, or when a previously-passing test/build/behavior is now failing and…
analyze-knowledge
Use when the user asks who knows specific code, who should review a PR or files, what the lottery factor is, whether knowledge is concentrated or spread, who to talk to about a code area, or when suggesting reviewers beyond GitHub's built-in suggestions.
fix-pr-conflict
Resolve merge conflicts on a pull request by rebasing onto the base branch. Use when a PR is not mergeable, has merge conflicts, or the user asks to fix conflicts on a PR.
create-pr
Use when creating a new GitHub pull request, opening a PR for the current branch, or when another skill (like ship-it) needs a PR created for a branch that does not have one yet.