Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add vfarcic/dot-ai --skill dot-ai-worktree-prdgit clone --depth 1 https://github.com/vfarcic/dot-aiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/vfarcic/dot-ai/dot-ai-worktree-prd)<a href="https://agentmods.dev/skills/vfarcic/dot-ai/dot-ai-worktree-prd"><img src="https://agentmods.dev/badge/skills/vfarcic/dot-ai/dot-ai-worktree-prd.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Agent Snooping · line 35 Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.Fix: Remove all code or instructions that access agent configuration directories (.claude/, .codex/, .gemini/). If configuration values are needed, pass them explicitly as parameters or environment variabl
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00032 | $0.00418 |
| Opus 5 | $0.00016 | $0.00209 |
| Sonnet 5 | $0.00006 | $0.00084 |
| Haiku 4.5 | $0.00003 | $0.00042 |
Grade B, and why
dot-ai-worktree-prd scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
cp .claude/settings.local.json [worktree_path]/.claude/settings.local.json What it actually says
Create Git Worktree for PRD
Create a git worktree with a descriptive branch name based on the PRD title.
Workflow
Step 1: Identify the PRD
Infer the PRD number from the current conversation. Look for references like "PRD 353", "PRD #353", or "prd-353".
If not found, ask the user: "Which PRD should I create a worktree for? (e.g., 353)"
Step 2: Create the Worktree
If the PRD title is already known from conversation context, pass both number and title:
bash .claude/skills/dot-ai-worktree-prd/create.sh [number] "[title]"
Otherwise let the script look it up from prds/:
bash .claude/skills/dot-ai-worktree-prd/create.sh [number]
Step 3: Copy Local Settings
Copy .claude/settings.local.json from the main repo to the new worktree so local settings (which are not tracked in git) are available:
cp .claude/settings.local.json [worktree_path]/.claude/settings.local.json
If the source file doesn't exist, skip this step silently.
Step 4: Handle Result
- If
SUCCESS=true: report the branch name, worktree path, and suggestcd [worktree_path] - If
ERROR=true: show the errors to the user and ask how to proceed
Guidelines
- Descriptive names: Branch names describe the feature, not just the PRD number
- Base on main: Always branches from
mainfor new feature work - Clean names: The script keeps branch names concise and URL-safe
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 51 lines · 32 tokens per session scan B 583237f66c8e
dot-ai-worktree-prd is a skill published in the GitHub repository vfarcic/dot-ai (336 stars, last pushed today), licensed MIT. It adds 32 tokens to every session and 418 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
prowler-commit
Creates professional git commits following conventional-commits format. Trigger: When creating commits, after completing code changes, when user asks to commit.
gh-auth-isolation
Safely manage multiple GitHub identities (EMU + personal) in agent workflows.
comet-github
A routing guide for Comet-related GitHub work. It directs requests about pull requests, issues, CI failures, ideas, and fixes to the appropriate review or implementation process.
github-skill
Work with GitHub via the gh CLI — clone repositories, create/list/merge pull requests, create/list issues, and run any other gh command (API calls, workflow runs, releases, repo administration). List operations return parsed JSON.
re0-merge
Review and land an external contribution the way this suite does: gate it against the thesis, land it with the author's credit intact, complete a new skill rather than merging it raw, then approve, credit, and explain before closing. Use when reviewing a pull request, as any collaborator or maintainer, not only the…
codex-autoresearch
Run autonomous, measurable experiments in a Git repository: change one hypothesis, verify a numeric metric, keep improvements, and revert failures. Use when the user wants Codex to keep iterating toward a numeric target in the foreground or as a detached background run. Do not use for ordinary one-shot coding…