Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add 45ck/skill-harness --skill html-review-artifactgit clone --depth 1 https://github.com/45ck/skill-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/45ck/skill-harness/html-review-artifact)<a href="https://agentmods.dev/skills/45ck/skill-harness/html-review-artifact"><img src="https://agentmods.dev/badge/skills/45ck/skill-harness/html-review-artifact.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00018 | $0.00638 |
| Opus 5 | $0.00009 | $0.00319 |
| Sonnet 5 | $0.00004 | $0.00128 |
| Haiku 4.5 | $0.00002 | $0.00064 |
Grade A, and why
html-review-artifact scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 60 lines — stays where its author put it; the contents beside it link to each section on GitHub.
HTML Review Artifact
Use this skill when a human needs to scan, compare, inspect, or interact with a rich generated view.
Default Constraints
- Generate one self-contained
.htmlfile. - Use inline CSS only by default.
- Prefer CSS/HTML interaction: radio tabs, details/summary, anchor navigation, and inline SVG states.
- Do not use inline JavaScript. The reviewed inline-JS lane is reserved until manifest metadata, CSP/checker support, and human approval requirements are implemented together.
- Do not load external scripts, fonts, images, analytics, or network resources.
- For Mermaid, C4, UML-style, and architecture diagrams, embed pre-rendered inline SVG or static markup by default.
- Use Mermaid, Vega-Lite, Observable Plot, D3, Graphviz, Apache ECharts, RAWGraphs, and Chart.js as source/spec or generation-time renderers only. Do not load their browser runtimes in the generated HTML.
- Prefer
artifact-infographicJSON fences or manifestinfographicsentries for non-model charts and graphs so the review page can regenerate static SVG/HTML panels. - For product, business, data, research, UX, and mockup review, render the source into a visual surface such as a dashboard, evidence board, state board, journey map, schema map, or high-fidelity prototype.
- For discovery, planning, and research intended for human review, produce an infographic-style HTML surface with summary metrics, charts or diagrams, evidence/freshness panels, source links, and clear review verdicts.
- For UI and customer-facing workflow review, prefer high-fidelity states with realistic copy, data density, errors, loading states, and accessibility affordances.
- Label synthetic user, simulated customer, or agent-generated evidence separately from real user or customer evidence.
- Do not include secrets, tokens, credentials, private logs, or customer data.
- Link to the canonical source artifact and issue.
- Use semantic headings, landmarks, meaningful link text, and alt text for embedded images.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 60 lines · 18 tokens per session scan A c92678d03ece
html-review-artifact is a skill published in the GitHub repository 45ck/skill-harness (15 stars, last pushed 2mo ago), licensed MIT. It adds 18 tokens to every session and 638 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
do-it-architecture
Use when authority, ownership, contracts, dependency boundaries, migration, recovery, or structural deletion can change a design.
do-it-code-quality
Use when designing, changing, or debugging code to locate causal ownership and close the affected behavior.
do-it-core
Use when repository work needs a shared baseline for intent, facts, causal changes, and honest evidence.
do-it-decide
Use when uncertainty about a choice, plan, dependency, or handoff could materially change what gets built.
do-it-review
Use to assess requirements and implementation quality independently, or to resolve a batch of review findings.
do-it-skill-authoring
Use when creating or revising a do-it skill so its trigger and unique professional judgment are useful without prescribing ceremony.