Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add WaterplanAI/agentic-config --skill ac-workflow-specgit clone --depth 1 https://github.com/WaterplanAI/agentic-configWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/waterplanai/agentic-config/ac-workflow-spec)<a href="https://agentmods.dev/skills/waterplanai/agentic-config/ac-workflow-spec"><img src="https://agentmods.dev/badge/skills/waterplanai/agentic-config/ac-workflow-spec.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00057 | $0.00373 |
| Opus 5 | $0.00028 | $0.00187 |
| Sonnet 5 | $0.00011 | $0.00075 |
| Haiku 4.5 | $0.00006 | $0.00037 |
Grade A, and why
ac-workflow-spec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Spec Workflow Engine
/skill:ac-workflow-spec STAGE SPEC: strictly follow bundled stage instructions at ../../assets/agents/spec/{STAGE}.md.
Supported public stages
- CREATE
- GATHER (compatibility alias to RESEARCH)
- RESEARCH
- CONSOLIDATE
- SUCCESS_CRITERIA
- CONFIRM_SC
- PLAN
- IMPLEMENT
- REVIEW
- FIX
- TEST
- DOCUMENT
- SENTINEL
- SELF_VALIDATION
Compatibility/internal only: PLAN_REVIEW, VALIDATE, VALIDATE_INLINE, AMEND.
Repository and commit contract
- default project convention:
.specs/specs/<YYYY>/<MM>/<branch>/<NNN>-<title>.md - modify only AI section in spec files
- each stage must commit every changed repo
- if both repos changed, commit root repo first and spec repo second
- include repo-scoped commit evidence in stage outputs:
repo_scope,root_commit,spec_commit
Bundled assets
Use package-bundled assets:
../../assets/agents/spec/{STAGE}.md../../assets/scripts/spec-resolver.sh../../assets/scripts/external-specs.sh../../assets/scripts/lib/config-loader.sh../../assets/scripts/lib/source-helpers.sh
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 53 lines · 57 tokens per session scan A ca6116f568a4
ac-workflow-spec is a skill published in the GitHub repository WaterplanAI/agentic-config (30 stars, last pushed 1mo ago), licensed MIT. It adds 57 tokens to every session and 373 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
curate-a-team-library
Use when building a managed team skills library for a real stack. Map work to shelves, browse before curating, write meaningful whyHere notes, and create a starter pack once the first pass is solid.
audit-library-health
Use when checking the overall health of a skills library. Run doctor, validate, check for stale skills, and verify generated docs are in sync.
install-from-remote-library
Use when installing skills from a shared ai-agent-skills library repo. Inspect with --list first, prefer --collection, and preview with --dry-run before installing.
review-a-skill
Use when evaluating whether a skill belongs in a library. Preview content, check frontmatter, validate structure, and decide whether to keep, curate, or remove.
share-a-library
Use when a managed library is ready to publish to GitHub and hand to teammates as an install command. Run the GitHub publishing steps, then return the exact shareable install command.
update-installed-skills
Use when syncing or updating previously installed skills to their latest version. Always dry-run updates before applying, and check for breaking changes.