Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/weklund/fiduciary/sync-datanpx skills add weklund/fiduciary --skill sync-datagit clone --depth 1 https://github.com/weklund/fiduciaryWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00045 | $0.00168 |
| Opus 5 | $0.00023 | $0.00084 |
| Sonnet 5 | $0.00009 | $0.00034 |
| Haiku 4.5 | $0.00005 | $0.00017 |
Grade A, and why
sync-data scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Instructions
Run the sync script to pull fresh data from all linked Plaid accounts:
bash scripts/sync.sh
After syncing, confirm what was updated and note the date. If the sync fails because Plaid CLI is not installed or not logged in, tell the user the setup steps:
brew install plaid/plaid-cli/plaidplaid login(orplaid registerfor new accounts)plaid link(to connect bank accounts)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 23 lines · 45 tokens per session scan A 18f415e79e7b
sync-data is a skill published in the GitHub repository weklund/fiduciary (10 stars, last pushed 1mo ago), licensed MIT. It adds 45 tokens to every session and 168 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
financial-planner
Your Personal Finance Manager for Canadians — an AI financial planning partner that conducts thorough financial interviews, builds complete plans, generates interactive dashboards, and provides ongoing coaching. Use this skill whenever someone asks about budgeting, saving, investing, debt strategy, retirement…
generated-assets
Keep the README GIF and social preview card truthful by re-rendering them whenever a code change alters what they show.
live-api-verification
Verify response models and MCP transports against the real YNAB API before claiming a tool works.
ynab-platform-compliance
Keep this project compliant with YNAB's API terms, OAuth requirements, naming rules, and branding restrictions.
architecture-boundaries
Preserve clean system layering and prevent logic from smearing across handlers, services, persistence, integrations, and agent runtime.
agent-runtime-guardrails
Keep autonomous runtime behavior observable, bounded, and separate from durable business logic.