Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/aeonfun/aeon/deploy-uni-hooknpx skills add aeonfun/aeon --skill deploy-uni-hookgit clone --depth 1 https://github.com/aeonfun/aeonWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00107 | $0.04572 |
| Opus 5 | $0.00053 | $0.02286 |
| Sonnet 5 | $0.00021 | $0.00914 |
| Haiku 4.5 | $0.00011 | $0.00457 |
Grade A, and why
deploy-uni-hook scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- deploy-uni-hook — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 127 lines — stays where its author put it; the contents beside it link to each section on GitHub.
${var} — the hook brief. Grammar:
[arm:][template:<name>] [chain:<name>] <brief>
- `` (empty) → print help and exit
DEPLOY_HOOK_EMPTY.<brief>→ dry-run: generate, compile, mine, and simulate. Never broadcasts. [default — no prefix]arm:<brief>→ broadcast: do the full dry-run first, then deploy for real if the simulation passes.template:<name>→ force a mode:dynamic|noop|skim(pre-audited templates) orfreeform(build a whole hook from the prompt). Omit to auto-pick: a brief that matches a template uses it; anything else →freeform.chain:<name>→ any Uniswap v4 chain inchains.tsv(run./hook-deploy.sh chainsto list). Defaultbase-sepolia. Testnets:base-sepolia,unichain-sepolia,arbitrum-sepolia. Mainnets (testnet: false, e.g.base,ethereum,unichain,arbitrum,optimism,polygon,bnb,avalanche, ...) require BOTHarm:and an explicitchain:— the skill never targets mainnet by default.base-mainnetis accepted as an alias forbase.
Today is ${today}. This skill turns a one-line brief into a live Uniswap v4 hook. It is built to be safe: it simulates every deploy before it broadcasts, it defaults to a dry-run on testnet, and it needs an explicit arm: to move on-chain.
Why this design
A hook binding is immutable and a bad hook can brick a pool or steal funds. So the gates sit BEFORE the deploy: two of them (dry-run then arm:), a mandatory simulation, and idempotent state. Everything after the broadcast is just recording what already happened — appended to memory/state/hook-deploys.json on main, no PR (there is nothing left to review). The Foundry flow is the proven one — mine a CREATE2 salt so the address carries the right hook-flag bits, deploy, initialize the pool, add liquidity, run one swap.
Safety contract (do not skip)
- Mainnet needs a triple lock. Never target a
testnet: falsechain unless${var}has BOTHarm:AND an explicitchain:<mainnet-name>— AND the instance hasHOOK_MAINNET_OK=1set as a repo variable (a third, operator-level lock enforced insidehook-deploy.sh, exit 7; store it as a variable, not a secret - a secret value of1masks every1in the run log, so tx hashes and links print as***). An instance that never authorized mainnet cannot broadcast there even if an armed message asks it to. This skill must only run on an instance whose inbound path is owner-gated (TELEGRAM_ALLOWED_USER_ID/ the multi-channel allowlist) — a mainnet deploy spends real gas, so an untrusted sender must never be able to dispatch it. On a mainnet chain, first read the deployer balance withcast balanceand abort (DEPLOY_HOOK_UNDERFUNDED) if it cannot cover the simulation'sEstimated amount required;hook-deploy.shindependently enforces a funding floor (exit 8), an optionalMAX_GAS_GWEIgas-price ceiling (exit 9), and warns if the deployer holds more thanHOOK_MAX_FLOAT_ETH(default 0.25) — a deploy key must hold gas float only, never LP or treasury capital. Log a clearMAINNETwarning in the output. - Simulate before every broadcast. If the simulation reverts, do not broadcast. Report the revert and exit
DEPLOY_HOOK_SIM_FAILED. - Dry-run is the default. Broadcast only when
${var}starts witharm:. - Key hygiene. The deployer key is a burner. Never print it. Never put it on a shell command line — always go through
./hook-deploy.sh, which reads it from the env inside the script. - Idempotency. Before broadcasting, read
memory/state/hook-deploys.json. If an identical brief already deployed within the last hour, do not re-deploy. The deploy script is also idempotent at the address level: it deploys to the canonical address (the first flag-matching CREATE2 salt for this exact(creationCode, flags, PoolManager)). If that address already holds code, an identical hook is already live, so the script logsALREADY_DEPLOYED <addr>and does nothing — the runner reports the existing address instead of deploying a duplicate. (HookMiner itself skips occupied addresses, so without this check a re-run would silently deploy another copy at a new address.)
What ships with it
11 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- hook-deploy.sh 16 KB runs code
- templates/chains.tsv 4.1 KB
- templates/DeployHook.s.sol 7.9 KB
- templates/DynamicFeeHook.sol 3.5 KB
- templates/foundry.toml 351 B
- templates/hook.env.example 755 B
- templates/Hook.sol 2.9 KB
- templates/Hook.t.sol 7.1 KB
- templates/HookFeeHook.sol 2.9 KB
- templates/MockERC20.sol 1.7 KB
- templates/NoOpHook.sol 1.4 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 127 lines · 107 tokens per session scan A e232a3a30edf
deploy-uni-hook is a skill published in the GitHub repository aeonfun/aeon (706 stars, last pushed 3d ago), licensed MIT. It adds 107 tokens to every session and 4,572 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
solana
Query Solana blockchain data with USD pricing — wallet balances, token portfolios with values, transaction details, NFTs, whale detection, and live network stats. Uses Solana RPC + CoinGecko. No API key required.
base
Query Base (Ethereum L2) blockchain data with USD pricing — wallet balances, token info, transaction details, gas analysis, contract inspection, whale detection, and live network stats. Uses Base RPC + CoinGecko. No API key required.
agent-framework-py-release
Use when cutting a Python release for the microsoft/agent-framework monorepo. Triggers on "bump py versions", "cut a python release", "prepare release PR for python", "release py packages", "bump python to X.Y.Z", or similar requests to bump Python package versions and prepare a release PR. Handles all four lifecycle…
foundry-hosted-agent-validation
Step-by-step process for validating a Python Foundry hosted agent sample (under python/samples/04-hosting/foundry-hosted-agents/) end to end — running it locally (native runtime and azd ai agent run) and after deploying it to an Azure AI Foundry project with azd. Use this when asked to validate a hosted agent sample.
python-feature-lifecycle
Guidance for package and feature lifecycle in the Agent Framework Python codebase, including stage meanings, feature-stage decorators, feature enums, and how to move APIs from one stage to the next.
build-and-test
How to build and test .NET projects in the Agent Framework repository. Use this when verifying or testing changes.