Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add WaterplanAI/agentic-config --skill mux-ospecgit clone --depth 1 https://github.com/WaterplanAI/agentic-configWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/waterplanai/agentic-config/mux-ospec)<a href="https://agentmods.dev/skills/waterplanai/agentic-config/mux-ospec"><img src="https://agentmods.dev/badge/skills/waterplanai/agentic-config/mux-ospec/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/waterplanai/agentic-config/mux-ospec"><img src="https://agentmods.dev/badge/skills/waterplanai/agentic-config/mux-ospec.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00034 | $0.00541 |
| Opus 5 | $0.00017 | $0.00270 |
| Sonnet 5 | $0.00007 | $0.00108 |
| Haiku 4.5 | $0.00003 | $0.00054 |
Grade A, and why
mux-ospec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 36 lines — stays where its author put it; the contents beside it link to each section on GitHub.
mux-ospec
This skill is a package-owned trigger alias for ac-workflow-mux-ospec. It is not an independent spec-stage workflow definition.
Delegate workflow semantics to ../ac-workflow-mux-ospec/SKILL.md and runtime semantics to ../../extensions/pimux/docs/.
Mandatory trigger behavior
If the user explicitly triggers mux-ospec, keep work in the tmux-backed stage lane.
Required sequence:
- after spawn, do not poll pimux or use Bash sleep/wait loops; wait for delivered child bridge activity
- pass through an explicit spec path unchanged when the user provides one; if the target is valid but missing, let the authoritative
pimuxruntime create it instead of blocking - if the user provides an inline prompt without a spec path, let the authoritative
pimuxruntime derive/create the next current-branch spec path by following recent current-branch spec-path patterns and the spec skill convention - use
AskUserQuestiononly when the user provided neither a spec path nor an inline prompt that is sufficient to spawn - let the authoritative
pimuxextension enforce the fail-closed parent control-plane lock - spawn the stage-owning
pimuxchild before substantive stage work - after spawn, run notify-first rather than poll-first: do not call
status,capture,tree,list, oropenon the happy path - after a child progress report, use at most one
send_messageif input is needed, then wait again - use
status/capture/tree/list/openonly for explicit live inspection, suspected stall/protocol violation/failure, or the inactivity watchdog - after terminal settlement, do one final
pimux statusverification and then advance
Do not run spec-stage execution directly in the parent while this skill is active.
Do not use parent-side Read, Bash, or manual repo discovery to figure out the spec before spawn.
Do not poll pimux or use Bash sleep/wait loops; wait for delivered child activity, and treat status / capture / tree / list / open as recovery-only.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 36 lines · 34 tokens per session scan A 9addf4689df4
mux-ospec is a skill published in the GitHub repository WaterplanAI/agentic-config (30 stars, last pushed 1mo ago), licensed MIT. It adds 34 tokens to every session and 541 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
vfx-text-cursor
A video or hero-frame effect where a cursor reveals a sentence character by character with coloured trails, light streaks, and a final shimmer.
curate-a-team-library
Use when building a managed team skills library for a real stack. Map work to shelves, browse before curating, write meaningful whyHere notes, and create a starter pack once the first pass is solid.
migrate-skills-between-libraries
Use when moving skills between library workspaces or upgrading from a personal library to a team library. Export from one workspace, import into another.
audit-library-health
Use when checking the overall health of a skills library. Run doctor, validate, check for stale skills, and verify generated docs are in sync.
browse-and-evaluate
Use when exploring the ai-agent-skills catalog to find, compare, and evaluate skills before installing. Always use --fields to limit output size and --dry-run before committing to an install.
install-from-remote-library
Use when installing skills from a shared ai-agent-skills library repo. Inspect with --list first, prefer --collection, and preview with --dry-run before installing.