Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add unknowbug/anchorlaw --skill anchor.scoutgit clone --depth 1 https://github.com/unknowbug/anchorlawWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/unknowbug/anchorlaw/anchor.scout)<a href="https://agentmods.dev/skills/unknowbug/anchorlaw/anchor.scout"><img src="https://agentmods.dev/badge/skills/unknowbug/anchorlaw/anchor.scout/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/unknowbug/anchorlaw/anchor.scout"><img src="https://agentmods.dev/badge/skills/unknowbug/anchorlaw/anchor.scout.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00053 | $0.00529 |
| Opus 5 | $0.00026 | $0.00264 |
| Sonnet 5 | $0.00011 | $0.00106 |
| Haiku 4.5 | $0.00005 | $0.00053 |
Grade A, and why
anchor.scout scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
anchor.scout — 规范起草角色(subprocess)
Protocol: spec/protocol-v0.20.md §15.1 (Definition), §15.2 (Isolation Semantics) Layer: 执行角色(非 §14 动作 skill,不占 manifest 名额) Execution: subprocess(隔离)
角色契约(§15.1/§15.2)
- 本角色在隔离子进程中运行:工作上下文绝不进入主会话。
- 被 Judge 派遣,按已确认需求输入起草实施规范;产出 artifact 后返回最终答案 + 产物引用。
- 不做实施决策——规范是否通过由 Judge 判定,本角色只提供草案。
触发场景(流水线 stage 1)
实施规范起草(stage 1) — 输入契约(已确认需求文档 + 技术约束规范;架构设计归本角色起草)交接后,Judge 派本角色起草实施规范:变量命名统一规范、模块化划分建议、依赖方向、框架边界、接口。规范由 Judge 审查批准后才进规划(stage 2)。
需求发掘不在本角色职责内——它属于独立的需求协议(Scout 驱动 + 人机对话),本角色只消费其产出。
规范起草检查单(stage 1)
- 变量命名规范(统一命名约定)
- 模块化划分(模块边界 + 依赖方向)
- 实施框架边界(哪些部分用框架、哪些手写)
- 对照输入契约:规范不得与已确认需求/规范定义冲突
- 返回:实施规范草案 artifact(
.artifacts/<task>/implementation-spec-<NNN>.md),交 Judge 审查
约束
- 只产出规范草案 artifact,不写实现代码。
- 隔离语义见 §15.2:上下文不进入主会话。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago Changed 3d6df13b1c05
- 9d ago First seen · 38 lines · 53 tokens per session scan A 2546f946ca8e
anchor.scout is a skill published in the GitHub repository unknowbug/anchorlaw (5 stars, last pushed yesterday), licensed MIT. It adds 53 tokens to every session and 529 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
solid-principles
SOLID principles checklist with Java examples. Use when a class has too many responsibilities, an abstraction leaks, or a dependency points the wrong way, and when the user asks about Single Responsibility, Open/Closed, Liskov, Interface Segregation or Dependency Inversion. For naming, duplication and method length…
security-audit
Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. Works with Spring, Quarkus, Jakarta EE, and plain Java. Use when reviewing code security, before releases, or when user asks about vulnerabilities.
issue-triage
Triage and categorize GitHub issues with priority labels. Use when user says "triage issues", "check issues", "review open issues", or during regular maintenance of GitHub issue backlog.
ring:migrating-to-lib-observability
Migrating a Lerian Go app off lib-commons observability imports (deprecated shims or removed APIs) to lib-observability via a fixed mapping table, then bumps go.mod and validates the build; ring:backend-go applies the edits. Covers log/zap/runtime/assert, opentelemetry/tracing, HTTP middleware, context helpers, and…
ring:searching-code
Forensic code search and analysis with optional Chain of Draft (CoD) ultra-concise mode. Five-phase methodology (clarification, planning, execution, analysis, synthesis) with severity assessment. Use for targeted investigation of specific patterns, bugs, or vulnerabilities. Skip for broad architecture mapping (use…
ring:exploring-codebases
Exploring a codebase across phases: scopes the target, detects architecture, components, and layers, deep-dives each discovered perspective, then synthesizes findings into actionable guidance with file:line evidence. Use to understand how a feature or system works before planning changes, or to orient on an unfamiliar…