Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add abrahamADSK/maya-mcp --skill maya-anim-transfergit clone --depth 1 https://github.com/abrahamADSK/maya-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/abrahamadsk/maya-mcp/maya-anim-transfer)<a href="https://agentmods.dev/skills/abrahamadsk/maya-mcp/maya-anim-transfer"><img src="https://agentmods.dev/badge/skills/abrahamadsk/maya-mcp/maya-anim-transfer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/abrahamadsk/maya-mcp/maya-anim-transfer"><img src="https://agentmods.dev/badge/skills/abrahamadsk/maya-mcp/maya-anim-transfer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00102 | $0.01806 |
| Opus 5.5 | $0.00041 | $0.00722 |
| Sonnet 5.5 | $0.00020 | $0.00361 |
| Haiku 4.5 | $0.00010 | $0.00181 |
Grade A, and why
maya-anim-transfer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 176 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Animation transfer and authoring on a rigged character
Applies to any HumanIK-characterised rig, not one project's characters. Everything here was falsified in-vivo. Most of these failures report success — the viewport and the attribute read both agree with you while being wrong.
For which command or flag, ask search_maya_docs — it now carries a HumanIK
section (CMDS_API.md), so look there before assuming a command is missing. One
trap it records: HIK's cmds surface is split. hikGlobals plus twelve
UPPERCASE HIK* runtime commands handle pinning, body-part modes and keying;
characterisation and the control-rig bake are MEL via mel.eval(...). Checking
with a lowercase hik grep finds one command and hides twelve.
What follows is the procedure, which the corpus does not hold.
1. Author on the control rig. Never key the deform skeleton
The deform skeleton is driven output. Keys placed there fight the rig, survive bakes you did not intend, and produce a character that looks right in one frame and broken in motion.
Author on the rig's controls (*_Ctrl_* or whatever the rig's convention is) and
let the deformation follow. This cannot be enforced in code — nothing can
reliably tell a deform joint from a control — so the discipline is yours.
Verify in motion, with a playblast. A correct-looking single frame proves nothing about a deformation.
2. Rest pose is not zero
Read the rest pose from the rig publish before you zero, copy or mirror anything. It is not 0, and it differs per character and per node.
"Zeroing a control" is therefore not "returning it to neutral" — it is moving it to an arbitrary pose that happens to be numerically tidy. Every copy, mirror or reset that assumed zero has to be redone.
3. Existing keys silently override setAttr
You setAttr a pose. You read the attribute back. It reads 0.0, or the old
value, and you conclude the pose did not take.
It took — and then the existing animation curve overrode it on the next evaluation. The attribute read is honest about the result, not about your write.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 176 lines · 102 tokens per session scan A 6cf3cceb7e70
maya-anim-transfer is a skill published in the GitHub repository abrahamADSK/maya-mcp (2 stars, last pushed 5d ago), licensed MIT. It adds 102 tokens to every session and 1,806 once invoked, about $0.0004 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-29.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…
next-cache-components-optimizer
Optimize the meaningful UI available immediately from a Next.js route on an initial load (hard navigation) or named client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route and entry point at a time; the shipped test then guards…