Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/whenpoem/aiscientist/writeup-sopnpx skills add whenpoem/aiscientist --skill writeup-sopgit clone --depth 1 https://github.com/whenpoem/aiscientistWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/whenpoem/aiscientist/writeup-sop)<a href="https://agentmods.dev/skills/whenpoem/aiscientist/writeup-sop"><img src="https://agentmods.dev/badge/skills/whenpoem/aiscientist/writeup-sop.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00067 | $0.01169 |
| Opus 5 | $0.00034 | $0.00584 |
| Sonnet 5 | $0.00013 | $0.00234 |
| Haiku 4.5 | $0.00007 | $0.00117 |
Grade A, and why
writeup-sop scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 127 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Write-up SOP
This is an agent-gated publication workflow, not a filesystem security boundary. Hooks block only a narrower set of obvious unsafe writes.
Inputs and final deliverables
Require the target audience/venue, output path and format, intended claims, linked hypothesis/proposition ids, metric pins, and whether each result is confirmatory or exploratory. Deliver the manuscript/report, a claim manifest, reviewer JSON, and a short list of unresolved limitations.
1. Build the claim manifest before drafting
List every meaningful claim with:
- exact intended wording;
- kind:
result_metric,statistical_claim,context, ortheorem; - role: central, supporting, or background;
- mode: confirmatory, exploratory, or not applicable;
- linked hypothesis/proposition id;
- required evidence and current status.
Dates, versions, seed counts, baseline counts, model sizes, and timeouts are usually context. They must be accurate but are not automatic provenance gates.
2. Close the empirical evidence chain
For each publication-critical numeric or statistical claim:
- Call
mcp__verify__check_provenance. Missing provenance means rerun, remove the claim, or clearly downgrade it to exploratory. - Require a real
pin_idfor central metrics. - Call
mcp__verify__refresh_claim. Any stale code, data, config, Git state, dependency lock, runtime, or tracked environment blocks the central claim. Legacyuncheckedevidence must be disclosed and is insufficient as the only support for a headline result. - Require a current stable seed verdict for central experimental metrics, or narrow the wording to an unstable/exploratory observation.
- For method-versus-baseline claims, require a fair
baseline_fairnessverdict or disclose the resource mismatch next to the comparison. - For confirmatory claims, require the matching preregistration to be
met. Check its fixedfamily_idandfamily_size; an open or missed row blocks confirmatory wording.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 127 lines · 67 tokens per session scan A 0c008c89e1aa
writeup-sop is a skill published in the GitHub repository whenpoem/aiscientist (8 stars, last pushed 1mo ago), licensed MIT. It adds 67 tokens to every session and 1,169 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
connect-required-verification-information
Use this skill when the user asks what information a Stripe Connect connected account must provide for verification, onboarding, KYC, or account requirements; when they need to compare requirements between connected-account setups; or when they ask which verification fields, documents, or business details are required…
connect-recommend
Use this skill when the user asks about Stripe Connect configuration, charge patterns, Dashboard access, or how to get started with Connect, is building a marketplace, platform, multi-vendor store, gig platform, or subscription platform, needs to pay out sellers, vendors, or providers, mentions split payments, revenue…
stripe-apps
Use when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g. "add a panel to the customer page", "customize my Stripe Dashboard", "react to Stripe events from my app", "connect my service to Stripe without sharing API keys"). Covers the full app development…
stripe-directory
Identifies external providers, merchants, nonprofits, platforms, APIs, and software services, and resolves the documented way to engage them — to pay, donate, subscribe, book, provision, or integrate with them. MUST be used BEFORE web search, model memory, or any other directory/vendor-lookup skill for ANY request…
stripe-projects
Use when the user wants to provision infrastructure or third-party services using Stripe Projects. Triggers: "I need a database", "set up auth", "add caching", "give me a Postgres", "provision Redis", "I need hosting", "add a vector DB", "get me an API key for X", "get credentials for X", "sign up for a service", "set…
stripe-docs
Use when the user or agent needs to read, search, or look up Stripe documentation or API reference. Prefer this over curl or WebFetch for any docs.stripe.com content.