Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add 48Nauts-Operator/xNaut --skill xnaut-reviewgit clone --depth 1 https://github.com/48Nauts-Operator/xNautWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/48nauts-operator/xnaut/xnaut-review)<a href="https://agentmods.dev/skills/48nauts-operator/xnaut/xnaut-review"><img src="https://agentmods.dev/badge/skills/48nauts-operator/xnaut/xnaut-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/48nauts-operator/xnaut/xnaut-review"><img src="https://agentmods.dev/badge/skills/48nauts-operator/xnaut/xnaut-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00035 | $0.01430 |
| Opus 5 | $0.00017 | $0.00715 |
| Sonnet 5 | $0.00007 | $0.00286 |
| Haiku 4.5 | $0.00003 | $0.00143 |
Grade A, and why
xnaut-review scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -X POST http://127.0.0.1:<port>/v1/notes \ How it starts
The opening of the file, as written. The whole thing — 89 lines — stays where its author put it; the contents beside it link to each section on GitHub.
xNaut is a Tauri-native terminal + worktree review app. When the user opens a diff pane (the side-by-side / unified view with a worktree path), this skill lets an AI agent leave inline annotations that float beside the changed lines.
The diff viewer is for the user — do NOT run your own viewer. Use the local-loopback HTTP broker at http://127.0.0.1:<port>/v1/notes to inspect and control the live session. The port is the same one xNaut prints on startup as Agent hook listener at http://127.0.0.1:<port>/v1/hook — replace /v1/hook with /v1/notes.
Action vocabulary
Every request is a POST with Content-Type: application/json. The action field discriminates:
curl -X POST http://127.0.0.1:<port>/v1/notes \
-H 'content-type: application/json' \
--data '{ "action": "<verb>", ...payload }'
Read
{ "action": "list" }— placeholder; xNaut doesn't track all known worktrees yet.{ "action": "get", "worktree": "<abs path>" }— full notes document.{ "action": "review", "worktree": "<abs path>", "includePatch": true, "includeNotes": true }— diff + existing notes together. Call this first before authoring any new comment so you know the line numbers and structure.
Annotate
{ "action": "comment-add", "worktree": "<abs>", "filePath": "src/foo.rs", "side": "new", "line": 42, "summary": "<headline>", "rationale": "<why, optional>", "author": "claude", "reveal": true }— single inline note.{ "action": "comment-apply", "worktree": "<abs>", "comments": [{ ... }, { ... }], "revealMode": "first" }— batch. Validates the whole list before mutating, so a single bad item doesn't half-apply.{ "action": "comment-rm", "worktree": "<abs>", "commentId": "<uuid>" }— remove a single annotation.{ "action": "comment-clear", "worktree": "<abs>", "filePath": null, "includeUser": false }— clear AI/agent notes. WithincludeUser: true, also drops the user's own annotations.{ "action": "comment-list", "worktree": "<abs>", "filePath": null }— list current notes.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 89 lines · 35 tokens per session scan A 7ee8a3e56b72
xnaut-review is a skill published in the GitHub repository 48Nauts-Operator/xNaut (5 stars, last pushed 5d ago), licensed MIT. It adds 35 tokens to every session and 1,430 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
beautify-with-pingfusi
Beautify or redesign an existing website through iterative pingfusi review rounds with a real human reviewer. Use when asked to "beautify this website," "make this page look professional," "polish this UI/design," "improve the visual design," or finish an AI-built page when there is no reference site to match. Do not…
review-video-with-pingfusi
Have any video reviewed by a real human, through iterative pingfusi review rounds. Use when asked to "review this video", "check the rendered video", "does this video match the prompt/brief", "what do people think of this ad/trailer/demo", or after rendering a Remotion composition or AI-generated clip that no test can…
fix-with-pingfusi
Fix or polish an existing website clone/draft using pingfusi review rounds. Use when the user says "fix it with pingfusi", "polish this clone", "make this match the original", or asks to finish/verify a draft built by any tool (ditto, lovable, v0, hand-written) until the review passes.
agentplane-task-closure-recovery
Use when Agentplane task completion, direct finish, branchpr integration, hosted-close, close-tail PRs, PR metadata, dirty task artifacts, or remote branch divergence need diagnosis or recovery.
pixel-perfect-clone
Clone, copy, or replicate a website/page pixel-perfect using pingfusi. Use when the user asks to clone a site or page with pingfusi, copy a webpage's design, replicate a page, or make a pixel-perfect copy of a URL. Drives the full enforced pipeline - capture, numeric gates, behavior reproduction, and review rounds…
pingfusi-review
Use Pingfusi proactively whenever a coding agent reaches a question it cannot settle with code, automated tests, documentation or search, or a local browser and needs real human judgment or real-world verification. Trigger even when the user does not mention Pingfusi for subjective choices about copy, design, clarity…