Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add yaojingang/yao-geo-skills --skill yao-geoflow-templategit clone --depth 1 https://github.com/yaojingang/yao-geo-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/yaojingang/yao-geo-skills/yao-geoflow-template)<a href="https://agentmods.dev/skills/yaojingang/yao-geo-skills/yao-geoflow-template"><img src="https://agentmods.dev/badge/skills/yaojingang/yao-geo-skills/yao-geoflow-template/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/yaojingang/yao-geo-skills/yao-geoflow-template"><img src="https://agentmods.dev/badge/skills/yaojingang/yao-geo-skills/yao-geoflow-template.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00094 | $0.00379 |
| Opus 5 | $0.00047 | $0.00189 |
| Sonnet 5 | $0.00019 | $0.00076 |
| Haiku 4.5 | $0.00009 | $0.00038 |
Grade A, and why
yao-geoflow-template scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Yao GEOFlow Template Legacy Router
Compatibility entrypoint for old GEOFlow PHP template-package notes. Current frontend work belongs in yao-geoflow-design.
Boundary
- Owns legacy output review, old PHP contract explanation, and handoff notes to
yao-geoflow-design. - Excludes new Laravel Blade themes, homepage builder,
lead_form, theme editor, channel sync, target-package mapping, backend changes, and activation. - Old
index.php,article.php,category.php,archive.php, andincludes/*.phpare legacy assumptions, not current preconditions.
Routing
- Current GEOFlow frontend design or reference-site cloning: use
yao-geoflow-design. - Explicit “legacy template skill” or “旧 PHP 模板包”: continue here.
- Read template-boundary.md and theme-package-contract.md before interpreting old files.
References
template-boundary.md, theme-package-contract.md, geoflow-frontend-map.md, trigger_cases.json, upgrade report.
What ships with it
24 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- agents/interface.yaml 901 B
- agents/openai.yaml 437 B
- evals/expected_artifacts.json 1.1 KB
- evals/semantic_config.json 2.7 KB
- evals/trigger_cases.json 2.2 KB
- examples/README.md 885 B
- manifest.json 528 B
- preview/qiaomu-editorial-20260418/archive.html 2.1 KB
- preview/qiaomu-editorial-20260418/article.html 3.2 KB
- preview/qiaomu-editorial-20260418/assets/app.js 686 B runs code
- preview/qiaomu-editorial-20260418/assets/theme.css 5.5 KB
- preview/qiaomu-editorial-20260418/category.html 2.3 KB
- preview/qiaomu-editorial-20260418/index.html 3.7 KB
- README.md 1.2 KB
- references/geoflow-frontend-map.md 1.3 KB
- references/template-boundary.md 1.5 KB
- references/theme-package-contract.md 1.2 KB
- reports/geoflow-skill-upgrade-2026-07-05.md 2.0 KB
- reports/intent-dialogue.md 970 B
- reports/iteration-directions.md 695 B
- reports/qiaomu-blog-mapping-2026-04-18.md 10 KB
- reports/reference-scan.md 1.3 KB
- scripts/serve_preview.py 914 B runs code
- templates/brief-template.md 384 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 25 lines · 94 tokens per session scan A 4310629e6eb2
yao-geoflow-template is a skill published in the GitHub repository yaojingang/yao-geo-skills (742 stars, last pushed 1mo ago), licensed MIT. It adds 94 tokens to every session and 379 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
php
PHP development environment. Use when the project needs this capability or the user / team manifest asks for it. Use for specialized php work when listed in TEAM.yaml or explicitly requested.
rust-crate-ci
Load before editing any Rust crate in this repo (currently runners/swarm-sandbox-runner). Covers the mandatory local validation gate, common rustfmt/clippy pitfalls, and Windows-specific Rust correctness patterns that CI enforces but are hard to catch locally without a Windows toolchain.
widen-return-type
When delegating a task affected by this skill, include.
auditing-php-applications
Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash auth bypass, LFI/RFI through php:// and phar:// wrappers, dynamic includes and extract()/superglobal trust, SQL injection…
migration
A step-by-step guide for upgrading programming languages, frameworks, and libraries while checking for breaking changes. A breaking change is an update that requires existing code to be modified.
laravel
Use when building or extending a Laravel 11/12 app — Eloquent models, migrations and relationships, routing with controllers and Form Requests, queues and background jobs, framework-native security (validation, mass-assignment, policies, signed URLs, rate limiting), and Pest/PHPUnit feature tests. NOT pure PHP…