Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/zeenie-ai/opencompany/github-skillnpx skills add zeenie-ai/OpenCompany --skill github-skillgit clone --depth 1 https://github.com/zeenie-ai/OpenCompanyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zeenie-ai/opencompany/github-skill)<a href="https://agentmods.dev/skills/zeenie-ai/opencompany/github-skill"><img src="https://agentmods.dev/badge/skills/zeenie-ai/opencompany/github-skill.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00051 | $0.01429 |
| Opus 5 | $0.00026 | $0.00714 |
| Sonnet 5 | $0.00010 | $0.00286 |
| Haiku 4.5 | $0.00005 | $0.00143 |
Grade A, and why
github-skill scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 136 lines — stays where its author put it; the contents beside it link to each section on GitHub.
GitHub Skill
Wrapper over the official GitHub CLI.
Typed operations for the core flows plus a custom passthrough that
covers the entire gh surface.
Tool: github
Operations
| Operation | Purpose | Key fields |
|---|---|---|
repo_clone |
Clone a repository into the workflow workspace | clone_repo (OWNER/REPO or URL), clone_dir, path |
pr_create |
Open a pull request; returns its URL | title, body, base, head, draft, fill, repo, path |
pr_list |
List pull requests (parsed JSON) | repo, state, limit |
pr_merge |
Merge a PR | pr (number/URL/branch), merge_method (squash/merge/rebase), delete_branch, repo |
issue_create |
Open an issue; returns its URL | title, body, labels, repo |
issue_list |
List issues (parsed JSON) | repo, state, limit |
custom |
Any other gh command | command — exactly what you would type after gh |
Response
{
"operation": "pr_list",
"success": true,
"url": null,
"result": [{ "number": 42, "title": "Fix login", "state": "OPEN", "url": "https://github.com/o/r/pull/42", "author": {"login": "octocat"}, "headRefName": "fix-login", "baseRefName": "main", "createdAt": "…" }],
"stdout": "…raw output…",
"stderr_tail": null
}
pr_list / issue_list return parsed JSON in result (via gh's
--json). pr_create / issue_create put the new item's URL in
url. custom commands that emit JSON (api …, … --json fields)
come back parsed in result too.
On failure the tool raises an error carrying gh's own message — surface it verbatim; gh's errors are precise (including "not logged in", which tells the user exactly how to authenticate).
Repository targeting
Inside a cloned checkout (after repo_clone, with path pointing at
it) gh infers OWNER/REPO from the git remote. Everywhere else, set the
repo field explicitly:
{ "operation": "pr_list", "repo": "octocat/hello-world", "state": "open" }
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 136 lines · 51 tokens per session scan A 9841a07d85e5
github-skill is a skill published in the GitHub repository zeenie-ai/OpenCompany (854 stars, last pushed today), licensed MIT. It adds 51 tokens to every session and 1,429 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
release-openclaw-maintainer
Prepare or verify OpenClaw stable, beta, and extended-stable releases, including backport discovery, changelogs, release notes, publish commands, and artifacts.
openclaw-testing
Choose, run, rerun, or debug OpenClaw tests, CI checks, Docker E2E lanes, release validation, and the cheapest safe verification path.
release-openclaw-ci
Run, watch, debug, and summarize OpenClaw full release CI, release checks, live provider gates, install/update proofs, and release-secret preflights.
openclaw-ci-limits
Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe ramp-down/ramp-up changes. Use when tuning .github/workflows/, docs/ci.md, CI runner labels, matrix max-parallel…
auto-qa
Continuously audit, live-test, and stress-test the current OpenClaw codebase across at least ten independently scoped subsystem lanes; default to 100 independently verified, landed root-cause fixes, maintain an evidence-backed report, and announce each merged pull request immediately. Use for OpenClaw-wide autonomous…
openclaw-changelog-update
Regenerate OpenClaw release changelog sections from git history before beta, stable, or extended-stable releases.