Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add yaojingang/yao-geo-skills --skill yao-geoflow-cligit clone --depth 1 https://github.com/yaojingang/yao-geo-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/yaojingang/yao-geo-skills/yao-geoflow-cli)<a href="https://agentmods.dev/skills/yaojingang/yao-geo-skills/yao-geoflow-cli"><img src="https://agentmods.dev/badge/skills/yaojingang/yao-geo-skills/yao-geoflow-cli/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/yaojingang/yao-geo-skills/yao-geoflow-cli"><img src="https://agentmods.dev/badge/skills/yaojingang/yao-geo-skills/yao-geoflow-cli.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00095 | $0.00470 |
| Opus 5 | $0.00048 | $0.00235 |
| Sonnet 5 | $0.00019 | $0.00094 |
| Haiku 4.5 | $0.00010 | $0.00047 |
Grade A, and why
yao-geoflow-cli scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Yao GEOFlow Operations
Operate a running GEOFlow instance. Prefer supported bin/geoflow, then API v1 for exposed content operations, then authenticated admin web for management workflows absent from API v1.
Boundary
- Owns operational CLI/API/admin work, CSRF/session handling, idempotency, readback verification, high-risk confirmation, and secret/personal-data redaction.
- Excludes product-code edits, migrations, direct SQL, frontend design, route invention, auth bypass, and secret exposure.
- Use
yao-geoflow-designfor homepage/design payload planning.
Checks
- Confirm
artisanorbin/geoflow. - Run
scripts/geoflow_preflight.sh "<workspace>" [config] [checks]before first mutation. - Inspect CLI help,
routes/api.php, orphp artisan route:listbefore choosing a surface. - API fallback uses bearer auth, JSON,
Accept: application/json, andX-Idempotency-Key. - Admin web reads the target page first, keeps CSRF/cookies, posts the owning route, then verifies readback.
- Require explicit target/action for destructive, secret-revealing, package-download, theme-publish, bulk sync, lead export, or update-center operations.
References
operation-boundary.md, command-map.md, laravel-api-v1-docker.md, geoflow-current-capability-map.md, trigger_cases.json, upgrade report.
What ships with it
15 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- agents/interface.yaml 1.1 KB
- agents/openai.yaml 620 B
- evals/expected_artifacts.json 1.9 KB
- evals/semantic_config.json 2.7 KB
- evals/trigger_cases.json 6.9 KB
- examples/README.md 526 B
- manifest.json 526 B
- README.md 3.0 KB
- references/command-map.md 22 KB
- references/geoflow-current-capability-map.md 8.4 KB
- references/laravel-api-v1-docker.md 7.5 KB
- references/operation-boundary.md 5.4 KB
- reports/geoflow-skill-upgrade-2026-07-05.md 2.3 KB
- scripts/geoflow_preflight.sh 7.4 KB runs code
- templates/brief-template.md 471 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 28 lines · 95 tokens per session scan A 84dabc033e7f
yao-geoflow-cli is a skill published in the GitHub repository yaojingang/yao-geo-skills (742 stars, last pushed 1mo ago), licensed MIT. It adds 95 tokens to every session and 470 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
pipefy-process-intelligence
Use this skill when the user wants to analyze an existing pipe for improvement opportunities — automation gaps, manual bottlenecks, missing AI agents, field conditions, or adjacent processes. Acts as a process analyst: investigates, diagnoses, and improves the pipe in progressive rounds — each round delivers visible…
c
OpenPaw coordinator — routes requests to skills, manages memory, knows what's installed. Use /c for any task.
-21risk-automation
Automate 21risk tasks via Rube MCP (Composio). Always search tools first for current schemas.
-2chat-automation
Automate 2chat tasks via Rube MCP (Composio). Always search tools first for current schemas.
ably-automation
Automate Ably tasks via Rube MCP (Composio). Always search tools first for current schemas.
abstract-automation
Automate Abstract tasks via Rube MCP (Composio). Always search tools first for current schemas.