Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add xonika9/agent-skills --skill x9-architecture-scoutgit clone --depth 1 https://github.com/xonika9/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/xonika9/agent-skills/x9-architecture-scout)<a href="https://agentmods.dev/skills/xonika9/agent-skills/x9-architecture-scout"><img src="https://agentmods.dev/badge/skills/xonika9/agent-skills/x9-architecture-scout/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/xonika9/agent-skills/x9-architecture-scout"><img src="https://agentmods.dev/badge/skills/xonika9/agent-skills/x9-architecture-scout.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00085 | $0.00644 |
| Opus 5 | $0.00043 | $0.00322 |
| Sonnet 5 | $0.00017 | $0.00129 |
| Haiku 4.5 | $0.00009 | $0.00064 |
Grade A, and why
x9-architecture-scout scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 27 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Architecture scout
Produce a read-only architecture report for a repository or user-named subsystem. This skill is model-invoked in Claude Code and Codex; its portable claim is structural Agent Skills compatibility only. Evidence tier: static.
Inspect component boundaries, dependency direction, ownership of data and behavior, coupling, duplication, change hotspots, and seams. Treat source, configuration, tests, and version history as evidence; distinguish observed facts from inferences. Do not edit production code, refactor, install dependencies, copy an external skill, or change external systems.
Method
Discover codebase-design from the live current-runtime catalog before any project or user/plugin roots that runtime declares. Resolve candidate paths symlink-aware, read the live skill version when one is found, and do not retain, reproduce, or hard-code its machine path. Use its method only to enrich the audit.
If no readable live codebase-design is found, perform the direct baseline audit and mark the method status DEGRADED. If the user requires Matt's exact method, stop with method status BLOCKED; do not substitute an invented version. Read the report contract before creating an HTML report; read x9-diagrams' Mermaid and design references when a diagram is needed.
Follow the repository's report-location convention. When it has none, write one HTML file at docs/architecture-reviews/YYYY-MM-DD-<stable-slug>.html. A same-day fallback audit must not silently replace a prior report: re-read and replace a named existing report only for an explicit update; otherwise choose a non-colliding stable suffix or path, or ask one short question when the report identity matters. The report may recommend a candidate, but it does not implement it; after a selection, hand the decision to ce-plan when available or provide a portable planning handoff.
Evidence and handoff
Run python3 scripts/validate_report.py <report.html> from this skill directory against the actual report. It proves structural and accessibility-contract compliance only. Keep the validator result separate from the actual render status: only a browser check at 1280px and 390px can make rendering PASS; otherwise state DEGRADED or NOT_PROVEN with the missing evidence.
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 27 lines · 85 tokens per session scan A 439fa54ef2f7
x9-architecture-scout is a skill published in the GitHub repository xonika9/agent-skills (4 stars, last pushed 6d ago), licensed MIT. It adds 85 tokens to every session and 644 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
agy-delegate
Delegate coding tasks to the Google Antigravity CLI (agy) only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.
luna
Reviews code for objective correctness, security, and reliability.
max
Cleans up and improves existing code without changing behavior.
andrej-karpathy
Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.
address-github-comments
Use when you need to address review or issue comments on an open GitHub Pull Request using the gh CLI.
architect-review
Master software architect specializing in modern architecture.