Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/ofcskn/mobile-automation-plugin/msd-permissionsgit clone --depth 1 https://github.com/ofcskn/mobile-automation-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/ofcskn/mobile-automation-plugin/msd-permissions)<a href="https://agentmods.dev/commands/ofcskn/mobile-automation-plugin/msd-permissions"><img src="https://agentmods.dev/badge/commands/ofcskn/mobile-automation-plugin/msd-permissions.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00025 | $0.00445 |
| Opus 5 | $0.00013 | $0.00222 |
| Sonnet 5 | $0.00005 | $0.00089 |
| Haiku 4.5 | $0.00003 | $0.00044 |
Grade A, and why
msd-permissions scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Validate app permissions for store submission.
Usage
/msd-permissions {appId} — validates and offers to fix issues interactively
Steps
- Read
.msd/memory/apps.jsonto find the app's path (or ask user for path) - Run:
node skills/managing-app-permissions/scripts/validate-permissions.js {appPath} - For each ❌ error (empty iOS description):
- Load
skills/managing-app-permissions/references/ios-permissions.md - Show what the permission is for and a suggested description
- Ask: "Use this description? (yes/edit/skip)"
- If yes: read
{appPath}/app.json, update the description, write back
- Load
- For each ⚠️ warning (generic description, deprecated Android permission):
- Explain the risk and suggested fix
- Ask: "Fix this? (yes/skip)"
- After fixes: re-run the validator to confirm all pass
- Show final summary: "X permissions validated, Y fixed, Z warnings remaining"
Detecting missing permissions from code
If the user says "check what permissions my code uses", scan the app source:
grep -r "expo-camera\|Camera\|expo-location\|Location\|expo-av\|Audio\|expo-contacts\|Contacts\|expo-image-picker\|ImagePicker" {appPath}/app {appPath}/components {appPath}/screens 2>/dev/null | grep -v node_modules | head -30
Then cross-reference with declared permissions.
Common fixes
| Issue | Fix |
|---|---|
| Empty NSCameraUsageDescription | Add: "Used to scan QR codes and take profile photos" |
| Generic "Camera access" | Replace with specific use case |
| WRITE_EXTERNAL_STORAGE | Replace with READ_MEDIA_IMAGES if only reading photos |
| Missing NSMicrophoneUsageDescription with expo-av | Add microphone description |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 42 lines · 25 tokens per session scan A 12c9eb253715
msd-permissions is a command published in the GitHub repository ofcskn/mobile-automation-plugin (2 stars, last pushed 2mo ago), licensed MIT. It adds 25 tokens to every session and 445 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
mobile-verify
Run automated verification loops with pass@k metrics for mobile testing. Executes tests multiple times to detect flakiness.
preflight
Run pre-submission checks — automated gates + manual checklist.
feature-build
Build a complete mobile feature from description to running code with E2E tests. Orchestrates 6 phases - planning, implementation, testing, build-fix, quality gate, and verification. Auto-detects platform.
android-build
Build Android project with Gradle, fix errors, generate APK/AAB. Invokes android-build-resolver for issues.
compose-test
Run Compose UI tests with Espresso. Verify critical user flows.
decompile
Decompile an Android APK/XAPK/AAB/DEX/JAR/AAR and analyze its structure.