Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/xcrft/mastermind/mastermind-codegraph-researchnpx skills add xcrft/mastermind --skill mastermind-codegraph-researchgit clone --depth 1 https://github.com/xcrft/mastermindWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00045 | $0.01247 |
| Opus 5 | $0.00023 | $0.00624 |
| Sonnet 5 | $0.00009 | $0.00249 |
| Haiku 4.5 | $0.00005 | $0.00125 |
Grade A, and why
mastermind-codegraph-research scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 104 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Codegraph research — discover structure with mmcg
The shared structural discovery layer for Mastermind. Claims about symbol existence, indexed callers, imports, and bounded blast radius come from a fresh mmcg result rather than memory. Exact source contracts and runtime behavior come from source reads and tests.
The graph is syntactic evidence: name resolution, dynamic dispatch, reflection, generated code, re-exports, and cross-language edges can reduce precision.
Never name a symbol, file, caller, or blast radius from memory. "I think X exists" is not evidence; mmcg_search X returning a hit is. A spec, audit, or critique built on a guessed symbol fails at the first step that touches real code.
Structural vs literal
- Bounded orientation (relevant changes, symbols, callers, tests, and history
for a role) → one
mmcg_briefbefore broad discovery. - Concept discovery (the intent is known but the exact symbol is not) →
mmcg_concept, then an exact structural query on the selected candidate. - Structural discovery (symbols, indexed callers/callees, imports, bounded blast radius) → mmcg first. It understands syntax better than literal text search, but remains name-based and bounded.
- Literal (string contents, log messages, comments, config values) →
Grep/Read. mmcg doesn't index strings. - Runtime contract (dynamic dispatch, reflection, generated code, re-exports, cross-language edges, exact branch behavior) → read source and run focused tests.
Query decision table
| Question | Tool |
|---|---|
| What bounded context does this planner/executor/auditor need? | mmcg_brief |
| Which local symbols match this natural-language concept? | mmcg_concept |
Does symbol X exist? (get file:line + signature) |
mmcg_search |
What calls X? |
mmcg_callers |
What does X call? |
mmcg_callees |
If I change/rename X, what breaks? (transitive) |
mmcg_impact |
| What does file Y import? | mmcg_imports |
Who imports X / this path? |
mmcg_imported_by |
| Does this file path exist in the index? | mmcg_files |
| Is the index ready / how stale is it? | mmcg_status |
| String contents / comments / log lines | Grep |
| File-name / extension globs | Glob |
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 104 lines · 45 tokens per session scan A 5bdf75ed9da8
mastermind-codegraph-research is a skill published in the GitHub repository xcrft/mastermind (11 stars, last pushed 7d ago), licensed MIT. It adds 45 tokens to every session and 1,247 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
roam
Codebase comprehension via roam-code CLI. Use when exploring codebases, planning modifications, debugging failures, assessing PR risk, or checking architecture health. Triggers on: understanding project structure, pre-change safety checks, finding symbols/files, blast radius analysis, affected tests, health scoring…
orchestrate
Tree-aware multi-agent GitHub-issue pool. Conductor manages task-tree from task-splitting-evaluation, executing depth-first per branch while parallelizing roots/orphans. Each worker agent owns its subtree lifecycle. Conductor tracks state (pending/started/in-progress/completed/halted) in GitHub +…
bonsai-ninja
Use bonsai-ninja as compiler-backed structural evidence when mapping a codebase, finding symbols, tracing behavior, inspecting dataflow, debugging across files, reviewing change impact, exporting graph facts, or running SAST.
task-splitting-evaluation
Recursive pre-implementation GitHub task splitting and evaluation flow. Use when the user wants Claude agents to evaluate unhandled tasks, skip already-processed tasks, mark easy leaves with detailed executor-ready comments, split broad tasks into GitHub subtasks, and keep recursing until every leaf is well described…
gh-task
Run a GitHub issue end-to-end in this repository using the committed isolated-worktree workflow. Use when the user invokes $gh-task, asks to run a GitHub task, or provides a GitHub issue number.
stacklit-navigator
Use stacklit.json to navigate codebases without burning tokens on file exploration.