Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/xobotyi/cc-foundry/zognpx skills add xobotyi/cc-foundry --skill zoggit clone --depth 1 https://github.com/xobotyi/cc-foundryWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/xobotyi/cc-foundry/zog)<a href="https://agentmods.dev/skills/xobotyi/cc-foundry/zog"><img src="https://agentmods.dev/badge/skills/xobotyi/cc-foundry/zog.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00045 | $0.03023 |
| Opus 5 | $0.00023 | $0.01511 |
| Sonnet 5 | $0.00009 | $0.00605 |
| Haiku 4.5 | $0.00005 | $0.00302 |
Grade B, and why
zog scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Strips warnings and disclaimersmediumAnti-refusal
Omitting safety caveats hides risk from the user and is a common jailbreak preamble.
When **reviewing** Zog, cite the violation and show the fix inline. Do not lecture. Treat a `.Required()` on a value How it starts
The opening of the file, as written. The whole thing — 186 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Zog is a Zod-shaped API over Go semantics, and the two disagree in ways that still compile. Import as
z "github.com/Oudwins/zog". Three biases decide most calls:
- A remembered Zod default is a defect until checked. Fields are optional by default,
z.Enumdoes not exist, and a schema key names a Go struct field rather than an input key. ParseandValidatedisagree about what missing means, and that disagreement decides which tests in a chain run at all.- Zog panics on a schema its author built wrong, and never on input data. A panic is a defect in the schema definition, fixed there.
Schema Shape
- A
z.Shapekey names a Go struct field, never an input key. The first letter is case-corrected, so"name"and"Name"both bind toName. A key matching no field panics withStruct Schema Definition Error ... missing expected schema key. - Struct tags map input keys and nothing else. Resolution runs
json,form,query, orenvfor the source in use, thenzog, then the schema key as written. z.Struct(...).Required()and.Optional()compile and do nothing. An optional nested struct needsz.Ptr(z.Struct(...)).NotNil().- Wrap the schema in
z.Ptrwherever the destination field is a pointer. Az.Slice(...)against a*[]Tfield panics with a type-cast error. z.Ptrcarries only.NotNil(). PutRequired,Default,Catch,Test, andTransformon the inner schema.- Declare every schema once, at package level. A schema rebuilt per call costs roughly twice the time and several times the memory of a reused one, and the gap widens with the number of fields.
Pick,Omit,Extend, andMergereturn shallow copies and are not type-checked. A key naming no struct field panics at execution rather than failing to compile.
Read [${CLAUDE_SKILL_DIR}/references/schema-catalog.md] when reaching for a constructor, a validator, a test option,
or an issue code that is not already in the chain — it carries every schema type with its full method set and
signatures, the three option families, and the issue-code and type constants.
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 186 lines · 45 tokens per session scan B 715be7da2655
zog is a skill published in the GitHub repository xobotyi/cc-foundry (20 stars, last pushed 3d ago), licensed MIT. It adds 45 tokens to every session and 3,023 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 1 finding (strips warnings and disclaimers). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
golang-pro
Implements concurrent Go patterns using goroutines and channels, designs and builds microservices with gRPC or REST, optimizes Go application performance with pprof, and enforces idiomatic Go with generics, interfaces, and robust error handling. Use when building Go applications requiring concurrent programming…
golang-graphql
Implements GraphQL APIs in Golang using gqlgen or graphql-go. Apply when building GraphQL servers, designing schemas, writing resolvers, handling subscriptions, or integrating GraphQL with existing Go HTTP services. Also apply when the codebase imports github.com/99designs/gqlgen or github.com/graph-gophers/graphql-go.
layered-architecture-types
Enforce primitive-at-edges / strong-types-in-Business layering and the toBus/fromBusResponse/toDB converter pattern. Use when writing, editing, or auditing Go files under app/, business/domain/, or .../stores/db.
golang-grpc
Provides gRPC usage guidelines, protobuf organization, and production-ready patterns for Golang microservices. Use when implementing, reviewing, or debugging gRPC servers/clients, writing proto files, setting up interceptors, handling gRPC errors with status codes, configuring TLS/mTLS, testing with bufconn, or…
golang-swagger
Golang OpenAPI/Swagger documentation with swaggo/swag — annotation comments (@Summary, @Param, @Success, @Router, @Security), swag init code generation, framework integrations (gin, echo, fiber, chi, net/http), security definitions (Bearer/JWT, OAuth2, API key), and struct tags (swaggertype, enums, example…
goframe-v2
GoFrame development skill. TRIGGER when writing/modifying Go files, implementing services, creating APIs, or database operations. DO NOT TRIGGER for frontend/shell scripts.