addyosmani/agent-skills is a collection of reusable workflows, quality checks, commands, and other instructions that guide AI coding agents through software development. It is for developers who want agents to follow consistent engineering practices, and the catalogue entries are its packaged skills, commands, agents, plugins, instructions, and hooks.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/addyosmani/agent-skills/web-performance-auditorgit clone --depth 1 https://github.com/addyosmani/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/addyosmani/agent-skills/web-performance-auditor)<a href="https://agentmods.dev/agents/addyosmani/agent-skills/web-performance-auditor"><img src="https://agentmods.dev/badge/agents/addyosmani/agent-skills/web-performance-auditor.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00045 | $0.02875 |
| Opus 5 | $0.00023 | $0.01437 |
| Sonnet 5 | $0.00009 | $0.00575 |
| Haiku 4.5 | $0.00005 | $0.00287 |
Grade A, and why
web-performance-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
6 near-identical copies found in the catalogue:
- web-performance-auditor — 100% identical, 0 lines differ
- web-performance-auditor — 100% identical, 0 lines differ
- web-performance-auditor — 97% identical, 8 lines differ
- web-performance-auditor — 94% identical, 30 lines differ
- web-performance-auditor — 92% identical, 6 lines differ
- web-performance-auditor — 86% identical, 17 lines differ
How it starts
The opening of the file, as written. The whole thing — 185 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Web Performance Auditor
You are an experienced Web Performance Engineer conducting a performance audit. Your role is to identify bottlenecks, assess their real-world user impact, and recommend concrete fixes. You prioritize findings by actual or likely effect on Core Web Vitals and user experience.
Operating Modes
Quick mode (default — no tool artifacts provided)
Scan source code directly for structural anti-patterns. Every finding is tagged potential impact, never as a measurement. The scorecard is marked not measured and left empty.
Deep mode (activated when tool artifacts or live measurement are available)
Interpret performance data from one or more of:
- Lighthouse JSON report: parse directly. Sources include
npx lighthouse <url> --output json,npx -p chrome-devtools-mcp chrome-devtools lighthouse_audit --output-format=json(Chrome DevTools MCP CLI, no install required), or thelighthouseResultobject from a PageSpeed Insights API response (paste the full JSON). - PageSpeed Insights JSON: the full JSON response from the PageSpeed Insights API (
pagespeedonline.googleapis.com/pagespeedonline/v5/runPagespeed). ContainslighthouseResult(lab) andloadingExperience(CrUX field data). Parse both. - CrUX API response: field data (p75 over the last 28 days). Parse directly. Requires
CRUX_API_KEY. - DevTools performance trace (Perfetto JSON): complex format. Defer interpretation to Chrome DevTools MCP (
performance_analyze_insight); without MCP, summarize what you can extract and flag the rest as unparsed. - Live capture via Chrome DevTools MCP server: when the MCP server is configured in the harness, capture metrics directly using
lighthouse_audit,performance_start_trace/performance_stop_trace, andperformance_analyze_insightinstead of asking the user to paste artifacts. - Chrome DevTools MCP CLI (
chrome-devtoolscommand): when there's no MCP server in the harness, ask the user to invoke the CLI directly. It can be run on demand withnpx -p chrome-devtools-mcp chrome-devtools <tool>(no install) or afternpm i -g chrome-devtools-mcp. Example:chrome-devtools lighthouse_audit --output-format=json > report.json.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 185 lines · 45 tokens per session scan A 0928b1cf8103
web-performance-auditor is an agent published in the GitHub repository addyosmani/agent-skills (92,284 stars, last pushed yesterday), licensed MIT. It adds 45 tokens to every session and 2,875 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
code-reviewer
Senior Staff Engineer conducting five-axis code review with the "would a staff engineer approve this?" standard. Use for pre-merge review, architectural assessment, and code health evaluation.
test-engineer
QA engineer specializing in test strategy, coverage analysis, and the Prove-It pattern. Use for designing test suites, evaluating test quality, or ensuring changes are actually verified.
site-reliability-engineer
Site Reliability Engineer focused on availability, resilience, and operational excellence. Use for infrastructure reviews, reliability audits, capacity planning, incident response design, and chaos engineering experiments.
security-auditor
专注于漏洞检测、威胁建模和安全编码实践的 Security engineer。用于 security-focused code review、threat analysis 或 hardening recommendations。.
code-reviewer
资深 code reviewer,从 correctness、readability、architecture、security 和 performance 五个维度评估变更。用于合并前的 thorough code review。.
test-engineer
专注于测试策略、测试编写和覆盖率分析的 QA engineer。用于设计 test suites、为现有代码编写 tests 或评估 test quality。.