Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/vibeic/vibe-icnpx agentmods add skills/vibeic/vibe-ic/flow-change-acceptanceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/vibeic/vibe-ic/flow-change-acceptance)<a href="https://agentmods.dev/skills/vibeic/vibe-ic/flow-change-acceptance"><img src="https://agentmods.dev/badge/skills/vibeic/vibe-ic/flow-change-acceptance/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/vibeic/vibe-ic/flow-change-acceptance"><img src="https://agentmods.dev/badge/skills/vibeic/vibe-ic/flow-change-acceptance.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 2 findings, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Prompt Injection · line 26 Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.Fix: Audit all comments and invisible characters. Remove any instructions that direct the agent to perform unauthorized actions. Use plain, reviewable content.
- high Prompt Injection · line 52 Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.Fix: Audit all comments and invisible characters. Remove any instructions that direct the agent to perform unauthorized actions. Use plain, reviewable content.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00067 | $0.03202 |
| Opus 5 | $0.00034 | $0.01601 |
| Sonnet 5 | $0.00013 | $0.00640 |
| Haiku 4.5 | $0.00007 | $0.00320 |
Grade A, and why
flow-change-acceptance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 262 lines — stays where its author put it; the contents beside it link to each section on GitHub.
flow-change-acceptance — the standard for changing the flow itself
A fix to one cell is judged by that cell. A change to the flow is judged by every cell that will ever run through it, including the ones nobody is watching.
That asymmetry is the whole reason this skill exists:
| a fix to one design | a change to the flow | |
|---|---|---|
| blast radius | that design | every design, and every future design |
| failure mode | that design fails | every design agrees, and every design is wrong |
| who notices | whoever ran it | nobody — a flow that lies is indistinguishable from a flow that works |
Every criterion below is written from a measured failure in this repo. None of them is a style preference.
Choose the smallest sufficient verification change
Verification protects a product contract; its growth is a cost, not a product outcome. A past incident does not automatically justify another permanent gate.
Before adding machinery, identify the actual failed behavior and its consumer. Prefer fixing the producer or removing duplicate state, then extending the existing behavioral test for that contract. One maintained test implementation can cover many data cases; do not copy a checker or test module for each issue.
Separate these scopes:
- A local regression case proves a specific failure is repaired. Keep it with the responsible component and use the existing selection mechanism.
- A global release gate is justified only by a cross-cutting risk that cannot be covered at its owning boundary. Review its applicability, existing overlap, expected execution cost and maintenance owner before making it mandatory.
- Report-format advice and documentation lint are not evidence that a design, simulation, verifier or repair actually worked. Do not promote a preferred heading or prose pattern into a product-admission requirement.
When equivalent checks already exist, consolidate their implementation and retain the discriminating cases. Changing one declaration should not require hand-synchronizing its copies or adding a new checker to check their equality. Prove that genuine bad inputs still fail and legitimate changes no longer cause representation-only failures. Do not use blanket test deletion, assertion caps, weaker thresholds, hidden skips or rewritten baselines as substitutes.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +19 lines · -177 tokens per session 7522b4c92865
- 10d ago First seen · 243 lines · 244 tokens per session scan A ee9cfa5a4235
flow-change-acceptance is a skill published in the GitHub repository vibeic/vibe-ic (23 stars, last pushed today), licensed Apache-2.0. It adds 67 tokens to every session and 3,202 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
analog-netlist-crawl
Crawl and analyze post-layout parasitic netlists without running SPICE. Answers "what's the effective resistance from node A to node B across this massive R mesh?", "inside the VREFN mesh, which device pins are electrically farthest apart?", "which nets have the worst coupling?", "where does settling bottleneck?" — by…
analog-verify
Pre-simulation review and Spectre simulation verification for analog circuits. Reviews circuit netlist and testbench, runs simulation, produces margin report. Use after analog-design completes a netlist.
analog-design
Transistor-level circuit design for one analog sub-block. Produces Spectre netlist with hand-calculation rationale. Use when designing a specific circuit block after architecture is defined.
analog-pipeline
MANDATORY — MUST load this skill when the user mentions: OTA, ADC, PLL, comparator, bandgap, LDO, amplifier, opamp, or any analog/mixed-signal IC design task. Full analog design pipeline: spec -> architecture -> design -> verify -> deliver. Orchestrates analog-decompose, analog-behavioral, analog-design…
analog-evolve
Self-evolution engine for analog-agents. Reviews completed design sessions to extract lessons, discover new anti-patterns, propose checklist additions, and refine agent prompts. Run after design convergence or project completion. TRIGGER on: "evolve", "what did we learn", "improve skills", "meta-review"…
analog-audit
Audit analog circuit netlists for correctness, quality, and risks. Supports both pre-layout (schematic) and post-layout (extracted) netlists. Post-layout mode filters massive parasitic netlists before auditing. Works without EDA. TRIGGER on: "audit", "review netlist", "check this circuit", "design review"…