Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/mentilead/shopify-app-skillWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/mentilead/shopify-app-skill/add-billing-plan)<a href="https://agentmods.dev/commands/mentilead/shopify-app-skill/add-billing-plan"><img src="https://agentmods.dev/badge/commands/mentilead/shopify-app-skill/add-billing-plan/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/mentilead/shopify-app-skill/add-billing-plan"><img src="https://agentmods.dev/badge/commands/mentilead/shopify-app-skill/add-billing-plan.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00465 |
| Opus 5 | $0.00000 | $0.00233 |
| Sonnet 5 | $0.00000 | $0.00093 |
| Haiku 4.5 | $0.00000 | $0.00047 |
Grade A, and why
add-billing-plan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Add Billing Plan
Add a new subscription plan with trial support, plan gating, and pricing UI.
Arguments
$ARGUMENTS = plan name and optional details (e.g., "pro $29/month with 14-day trial", "enterprise")
Instructions
- Parse the plan name, price, and trial days from
$ARGUMENTS. If missing, ask the user for plan name, monthly price, and trial length. - Read
.claude/skills/shopify-app/references/billing-patterns.mdfor the full billing flow,billing.request()throw behavior, andisDevelopmentStorepattern. - Read
.claude/skills/shopify-app/SKILL.mdgotchas #7 (Plus dev stores can't approve test charges) and #8 (Custom apps cannot use Billing API). - Add the plan definition to
app/shopify.server.tsin thebillingconfig:- Plan name, amount, currencyCode, interval
trialDaysif trial was specified
- Create or update the billing service function in
app/services/billing.server.ts:syncBillingToDb(shopDomain, admin)— checks active subscription and writes to DynamoDBloadShopBilling(shopDomain)— reads current plan from DynamoDB- Feature gating helper that maps plans to feature sets
- Update the layout loader in
app/routes/app.tsxto sync billing on page load using thecharge_idredirect pattern from the skill (gotcha #5). - Create or update the pricing page at
app/routes/app.pricing.tsx:- Show plan cards with features and pricing
- Use
useFetcherfor the upgrade action (notuseActionData— gotcha #3) - Handle
isDevelopmentStorefor test charges
- If the plan gates specific features, add the gating check to relevant loaders/actions.
- Remind the user to:
- Test with a non-Plus Basic dev store (gotcha #7)
- Verify the app is Public or Unlisted distribution (gotcha #8)
- Test the full flow: trial start → approval → redirect → plan display
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 31 lines · 0 tokens per session scan A 046ecf583dd3
add-billing-plan is a command published in the GitHub repository mentilead/shopify-app-skill (5 stars, last pushed 6mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 465 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
dev
Runs Vendure in development mode. By default it starts three processes: the GraphQL server (ts-node ./src/index.ts), the worker (ts-node ./src/index-worker.ts), and the dashboard (a Vite dev server).
cti-report
Render case deliverables — relationship graph (PNG/SVG/Mermaid) and a polished PDF/DOCX assessment. Usage: /cti-report [--graph|--pdf].
eval-merge
Use the Read tool to load .skill-compass/{skill-name}/manifest.json. Verify.
enum-udp
UDP scan + service follow-up — top ports first, full sweep only when justified.
kerberos
Kerberos attacks — AS-REP roasting and Kerberoasting.
check
Run TYPO3 conformance check on current extension.