Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/aznatkoiny/zai-skills/validate-profilegit clone --depth 1 https://github.com/Aznatkoiny/zAI-SkillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/aznatkoiny/zai-skills/validate-profile)<a href="https://agentmods.dev/commands/aznatkoiny/zai-skills/validate-profile"><img src="https://agentmods.dev/badge/commands/aznatkoiny/zai-skills/validate-profile.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00015 | $0.00478 |
| Opus 5 | $0.00008 | $0.00239 |
| Sonnet 5 | $0.00003 | $0.00096 |
| Haiku 4.5 | $0.00002 | $0.00048 |
Grade A, and why
validate-profile scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 42 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Validate the user's career profile and turn the findings into an action plan.
Arguments
$ARGUMENTS
Optional path to the profile file; default is career-profile.json in the project root.
Protocol
1. Run the validator
python3 "${CLAUDE_PLUGIN_ROOT}/scripts/validate-profile.py" career-profile.json
(substitute the path from the arguments if one was given). The script is advisory — it always exits 0 and reports findings as a completeness scorecard plus WARN lines. It checks the rules from ${CLAUDE_PLUGIN_ROOT}/skills/resume-updater/references/career-profile-schema.md:
- Required fields (
personal.name,personal.email, at least one experience entry) - Dates in
YYYY-MMformat (education graduation may beYYYY) - Experience in reverse-chronological order
- Maximum 5 target roles
- Every achievement has a non-empty
metric(listed per role when missing)
2. Interpret the results
Don't just paste the output. Summarize:
- The completeness score and what it means
- Blocking issues (missing required fields, malformed dates) — these break resume generation and job matching; fix them first
- Quality issues (achievements without metrics) — these are the difference between a responsibilities list and a resume; for each flagged achievement, show the current statement and ask the user the quantification question from the resume-updater skill ("Can you put a number on that? Percentage? Revenue? Time saved? Scale?")
3. Offer fixes
- For mechanical issues (date formats, ordering, trimming target roles), offer to fix
career-profile.jsondirectly with Edit — show the change before applying. - For missing metrics or empty sections, offer to run the resume-updater skill's interview flow to fill them properly rather than inventing numbers. Never fabricate metrics.
- After any edits, re-run the validator to confirm the score improved. (Edits to
career-profile.jsonalso trigger the plugin's validation hook automatically, so warnings will resurface on save if anything regressed.)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 42 lines · 15 tokens per session scan A 52ea6aaf83e1
validate-profile is a command published in the GitHub repository Aznatkoiny/zAI-Skills (9 stars, last pushed 1mo ago), licensed MIT. It adds 15 tokens to every session and 478 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
composite-actions
Generate, review, secure, and test composite GitHub Actions following best practices — full repo scaffold, interview-driven generation, PR creation on existing repos, SHA pinning, secrets-as-inputs, job summaries, and actionlint validation.
github-actions
Design, review, secure, and debug GitHub Actions workflows — reusable workflows, OIDC federation, SHA pinning, token scoping, promotion orchestration, and CI failure diagnosis.
datadog
Set up and troubleshoot Datadog — Agent deployment on Kubernetes, APM instrumentation, Log Management, Monitors, Dashboards, SLOs, Synthetic tests, and live incident investigation using the Datadog MCP server. Covers Terraform-managed Datadog resources.
fluxcd
FluxCD entry point — routes to the right workflow based on what you need. Live cluster issue → structured 5-workflow debug trace. Repo health check → 6-phase audit (discovery, validation, API compliance, best practices, security). Helm chart review → helmchart. Starts by asking one question to confirm the right mode.
terraform
Runs through the full Terraform validation pipeline — fmt, validate, tflint, security scan — and reviews a module or plan for blast radius, IAM risk, and state impact.
announce
Draft X/Twitter announcement post (or thread) for the latest plugin release.