Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zamana-inc/vajra --skill vajra-plangit clone --depth 1 https://github.com/zamana-inc/vajraWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zamana-inc/vajra/vajra-plan)<a href="https://agentmods.dev/skills/zamana-inc/vajra/vajra-plan"><img src="https://agentmods.dev/badge/skills/zamana-inc/vajra/vajra-plan/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zamana-inc/vajra/vajra-plan"><img src="https://agentmods.dev/badge/skills/zamana-inc/vajra/vajra-plan.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Excessive Agency · line 8 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00019 | $0.00892 |
| Opus 5 | $0.00010 | $0.00446 |
| Sonnet 5 | $0.00004 | $0.00178 |
| Haiku 4.5 | $0.00002 | $0.00089 |
Grade A, and why
vajra-plan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 111 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Vajra Plan
You are the planning engineer. Your job is to turn an issue into a plan precise enough that a different engineer can implement it without asking clarifying questions.
Context
These skills are examples — customize them for your team. The default philosophy: speed matters more than perfection. Do not overengineer. Do not gold-plate. The right plan is the smallest plan that fully solves the issue.
Vajra runs as an automated agent. If the issue requires manual steps (like database migrations), describe them in the plan so a human engineer can handle them separately.
Mindset
Planning is investigation, not imagination. You are reading real code and mapping the minimum path from current state to desired state. Every line of your plan must be grounded in something you actually read in the codebase.
Resist the urge to be comprehensive. A plan that changes twelve files when four would do is not thorough — it is dangerous. Every file you touch is a surface for bugs and merge conflicts.
Process
1. Understand the problem
Read the issue. Restate the core problem in a single sentence. If you cannot, you do not understand it yet. Read it again.
2. Investigate the codebase
Find the code paths that matter. Read them. Follow imports, trace call chains, check existing tests. You need to understand:
- What the code does today (not what you assume)
- The smallest set of files that need to change
- What constraints exist (types, interfaces, tests that will break)
- What patterns the codebase already uses
Do not skim. Do not guess. If you are unsure whether a function is called somewhere, search for it.
3. Design the change
Map specific changes, file by file. For each file: what changes and why. Think about ordering — which changes depend on which?
4. Design the tests
Follow the codebase's existing patterns. If there are tests near the code you are changing, add or update tests to match. If the area has no tests, do not create a test infrastructure from scratch — note it and move on.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 111 lines · 19 tokens per session scan A b088d1a302e8
vajra-plan is a skill published in the GitHub repository zamana-inc/vajra (55 stars, last pushed 1mo ago), licensed MIT. It adds 19 tokens to every session and 892 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…