Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add 02loveslollipop/OpenCROW --skill netcat-asyncgit clone --depth 1 https://github.com/02loveslollipop/OpenCROWWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/02loveslollipop/opencrow/netcat-async)<a href="https://agentmods.dev/skills/02loveslollipop/opencrow/netcat-async"><img src="https://agentmods.dev/badge/skills/02loveslollipop/opencrow/netcat-async.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00067 | $0.00755 |
| Opus 5 | $0.00034 | $0.00378 |
| Sonnet 5 | $0.00013 | $0.00151 |
| Haiku 4.5 | $0.00007 | $0.00076 |
Grade A, and why
netcat-async scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 85 lines — stays where its author put it; the contents beside it link to each section on GitHub.
OpenCROW I/O - Netcat Async
Runtime preflight
Probe required commands with command -v and Python modules with importlib.util.find_spec before use. Prefer a PATH-resolved OpenCROW MCP helper or the ctf/sage environment when available, then the managed helper or system Python. If a capability is missing, stop that path safely and report the exact missing command or module.
Prefer the opencrow-netcat-mcp server for session lifecycle, reads, and writes. Fall back to scripts/ncx only when you need to inspect or debug the backend directly.
MCP First
- Use
toolbox_info,toolbox_verify, andtoolbox_capabilitiesfirst. - Use the generic session tools:
session_startsession_listensession_sendsession_readsession_statussession_stop
- Keep one named session per target flow so the MCP server can report stable artifacts under
/tmp/opencrow-nc-async/<name>/.
Use scripts/ncx to manage long-lived TCP sessions instead of one-shot nc invocations when you are operating outside MCP.
Workflow
- Start a named outbound session, or listen for one inbound connection.
- Send one or more payloads while the daemon keeps receiving output asynchronously.
- Read logs (
tailfor recent data,followfor streaming). - Stop the session when done.
Commands
# Start session
scripts/ncx start --name demo --host 127.0.0.1 --port 9001
# Listen on loopback for one inbound connection (port 0 selects a free port)
scripts/ncx listen --name inbound --port 0
# Send text (append newline for line-oriented protocols)
scripts/ncx send --name demo --data 'ping' --newline
# Send exact bytes using hex or strict base64
scripts/ncx send --name demo --hex '00 03 ff'
# Read latest output
scripts/ncx read --name demo --tail 40
# Follow output live
scripts/ncx read --name demo --follow
# Check metadata and process state
scripts/ncx status --name demo
# Stop session
scripts/ncx stop --name demo
Operational Rules
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 85 lines · 67 tokens per session scan A 087324c46850
netcat-async is a skill published in the GitHub repository 02loveslollipop/OpenCROW (8 stars, last pushed today), licensed Apache-2.0. It adds 67 tokens to every session and 755 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
schema-guard
Check a proposed API or data contract against the current contract, real sample payloads, and a compatibility policy, and gate publication behind a refusable verdict with native digest evidence.
openapi-graph
OpenAPI front example; a graph whose step turns an OpenAPI operation into a sealed tool result.
openapi-adapter
External-adapter sub-skill; turns an OpenAPI operation into a sealed tool result.
thread-outbox-provider-push
Publish a fixture thread outbox entry through the Rust thread-outbox-provider front.
project-settings-cascade
Changing or adding a project setting / default value in RedAmon. A single setting is duplicated across Prisma, two separate Python settings modules, the orchestrator defaults endpoint, and the frontend fallback; miss a layer and the UI shows one value while the backend uses another, and existing projects keep the old…
redteam-api-detail-pack
Domain routing and boundary guidance for authorized API security testing, including BOLA/IDOR, authentication bypass, mass assignment, missing rate limits, and GraphQL issues. Use when a task belongs to the API testing domain and needs scope, evidence, pivot, or exit criteria.