Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/ykorovko/dotagents/hownpx skills add ykorovko/dotagents --skill howgit clone --depth 1 https://github.com/ykorovko/dotagentsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00039 | $0.00854 |
| Opus 5 | $0.00019 | $0.00427 |
| Sonnet 5 | $0.00008 | $0.00171 |
| Haiku 4.5 | $0.00004 | $0.00085 |
Grade A, and why
how scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 55 lines — stays where its author put it; the contents beside it link to each section on GitHub.
How
Explore the codebase and give the user a working mental model of how something operates. Explain mechanics and architecture, not historical motivation. When why is also loaded, incorporate its evidence about historical motivation. Installation alone does not load or invoke another skill.
Treat this as a read-only investigation unless the user also asks for changes.
Choose the mode
- Explain is the default. Trace the implementation and describe it clearly.
- Critique applies only when the user asks about architectural problems, tradeoffs, or improvements. Explain the current design before judging it.
Explore
- State the scope you inferred from the request. If it is ambiguous, use the surrounding context and make the assumption visible.
- Find the real entry point. Trace callers, callees, data transformations, state changes, and side effects through the implementation. Read code rather than guessing from names.
- Identify the types, services, modules, or processes that carry the design. Note who owns each responsibility and where system boundaries sit.
- Check configuration, feature flags, generated code, persistence, queues, external APIs, and tests when they affect the flow.
- Follow the path until you can connect the trigger to its outcome without hand-waving. Record gaps instead of filling them with plausible behavior.
For a narrow question, investigate directly. For a large subsystem, split the exploration into independent slices only when the harness supports delegation and the user permits it. When delegating, read references/explorer-prompt.md and adapt its template for each distinct slice. Keep delegated work read-only and verify the findings against the code before using them.
Explain
Adapt the response to the question rather than forcing every section. A useful explanation usually contains:
- Overview. What the subsystem does and where it fits.
- Key concepts. Only the types and abstractions needed to follow the flow.
- How it works. The trigger, sequence, data movement, decisions, and side effects, with concrete
file:linereferences. - Where it lives. A short map of the files a maintainer would open first.
- Gotchas and gaps. Surprising behavior, sharp edges, and anything you could not verify.
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 55 lines · 39 tokens per session scan A 1a733b92f925
how is a skill published in the GitHub repository ykorovko/dotagents (0 stars, last pushed 2d ago), licensed MIT. It adds 39 tokens to every session and 854 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
greenfield
Parallel persona planning for new projects. Research agent runs first to build domain context, then Architect, PM, and Security agents run in parallel. Synthesis agent combines all perspectives into a detailed GSD-style PLAN.md with Tensions section.
brownfield-drift
Enforces architecture boundaries defined in PLAN.md. Use when a PR crosses module/service boundaries, when the dev asks "are we following the architecture?", or as a scheduled architecture health check. Not for querying what a module does — use brownfield-chat for that.
pr-review
Fix engine for PR review comments. Fetches review comments (Gemini bot or human), categorizes by impact, posts a prioritized fix queue, and applies fixes on dev approval. Called directly for quick fixes, or internally by pr-review-agent as part of full PR review.
wednesday-git
Unified Git workflow. Manages the entire task lifecycle: branch creation (sprint), atomic commits (git-os), and PR opening (pr-create).
standards-kit
Unified development and design standards. Enforces code quality (complexity < 8), strict naming conventions, and the mandatory use of approved UI component libraries.
codebase-intel
Unified codebase intelligence. Handles all questions about structure, logic, risk, and dependencies. Combines natural-language Q&A with deterministic lookups and pre-edit blast radius checks.