Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/wlvh/coding-workflow/workflow-docs-syncnpx skills add wlvh/coding-workflow --skill workflow-docs-syncgit clone --depth 1 https://github.com/wlvh/coding-workflowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00119 | $0.04610 |
| Opus 5 | $0.00060 | $0.02305 |
| Sonnet 5 | $0.00024 | $0.00922 |
| Haiku 4.5 | $0.00012 | $0.00461 |
Grade A, and why
workflow-docs-sync scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
The source is not reproduced here
No licence file
A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 266 lines · 119 tokens per session scan A c86bb157dcb5
workflow-docs-sync is a skill published in the GitHub repository wlvh/coding-workflow (5 stars, last pushed 2d ago), with no licence file. It adds 119 tokens to every session and 4,610 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
female-portrait-director
Generate, visually expand, optimize, diagnose, and route structured AI image prompts for adult female portraits. Use for lifestyle, curve-focused, fashion, oriental, fantasy, realism, beauty, CCD, low-key cinematic, studio, sport, travel, and e-commerce portrait requests; onboarding or usage help; parameter…
git-guardrails-claude-code
设置 Claude Code 钩子,在危险 Git 命令(push、reset --hard、clean、branch -D 等)执行前将其拦截。当用户想要防止破坏性 Git 操作、添加 Git 安全钩子或在 Claude Code 中阻止 git push/reset 时使用。.
gpt-image-2-prompt-engine
面向电商设计师、海报美工、品牌视觉、UI设计师、信息图编辑、商业摄影师、内容创作者等需要高质量可控出图的角色,在需要用 GPT-Image-2 生成电商主图、电影海报、信息图、品牌视觉、UI截图、古籍国风、角色IP等场景时,通过「Prompt as Code」原子化Schema+20+工业JSON模板+四步工作流,产出结构化、可复用、可批量的生图提示词,再调用 imagegeneration 出图。不适用于随意生图或简单风景照。.
cro-audit
Use when reviewing a landing page, homepage, signup page, pricing page, checkout, form, onboarding screen, popup, or paywall for conversion blockers.
ecommerce-app-cro
Use when improving ecommerce product pages, collection pages, carts, checkout, subscriptions, app store listings, screenshots, reviews, or mobile conversion surfaces.
agent-reach-wrapper
Thin wrapper around Panniantong/Agent-Reach for live web, YouTube transcripts, RSS, GitHub, Bilibili, Exa search, and optional login-state platforms (X, Reddit, Facebook, Instagram, Xiaohongshu, LinkedIn). Triggered by agent-reach, reach this URL, YouTube transcript, Reddit thread, Bilibili, Xiaohongshu, RSS feed, or…