Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add aeonfun/aeon --skill mention-radargit clone --depth 1 https://github.com/aeonfun/aeonWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/aeonfun/aeon/mention-radar)<a href="https://agentmods.dev/skills/aeonfun/aeon/mention-radar"><img src="https://agentmods.dev/badge/skills/aeonfun/aeon/mention-radar.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00031 | $0.02763 |
| Opus 5 | $0.00015 | $0.01381 |
| Sonnet 5 | $0.00006 | $0.00553 |
| Haiku 4.5 | $0.00003 | $0.00276 |
Grade A, and why
mention-radar scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
`XAI_API_KEY` is **injected into your environment** for this skill (declared in `requires:`). It is present and valid. **The primary fetch path for X/Twitter mentions is a direct `curl` to `https://api.x.ai/v1/responses` Copies of this mod
1 near-identical copy found in the catalogue:
- mention-radar — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 141 lines — stays where its author put it; the contents beside it link to each section on GitHub.
${var} — Comma-separated project names to track (e.g. "MyApp, my-lib"). If empty, derives targets from MEMORY.md and memory/topics/projects.md.
Read memory/MEMORY.md for current project status. Read the last 3 days of memory/logs/ to avoid re-surfacing already-noted mentions.
Steps
-
Define the targets.
- If
${var}is set: parse it as a comma-separated list of project names. - Otherwise: scan
memory/MEMORY.md(goals, active topics) andmemory/topics/projects.md(if it exists) for the operator's active projects. A target needs at least a name; collect a site/domain and a GitHubowner/repotoo when known. - Cap at 6 targets — prefer the most active ones.
- If zero targets can be derived: log
MENTION_RADAR_SKIP: no projects configured — set var or add projects to memory/topics/projects.mdand stop. No notification.
For each target, build search terms:
- The exact project name in quotes (e.g.
"MyApp" site:x.com OR site:reddit.com OR site:news.ycombinator.com) - The domain if known (e.g.
"myapp.xyz") - The repo if known (e.g.
site:github.com owner/myapp)
- If
-
Search for external mentions. X/Twitter is fetched via the X.AI Responses API (primary); the rest of the public web (Reddit, Farcaster, blogs, newsletters, GitHub Discussions, HN, Product Hunt) goes through WebSearch, which is also the last-resort fallback for X itself. Derive the operator's handle from
soul/SOUL.mdif present (call it$OPERATOR) so you can exclude their own posts.Path A — X.AI API (primary, X/Twitter mentions). For each target, ask Grok's
x_searchwho is talking about the project on X. See the Fetching contract below — attempt this whenever the key is present, set the Bash tooltimeoutto ≥180000, and capture the HTTP status. Use a unique tmp filename per target if you loop (e.g./tmp/xai-mr-$SLUG.json).$NAME/$DOMAIN/$REPOcome from the target built in step 1 ($DOMAIN/$REPOmay be empty — leave them out if so):FROM_DATE=$(date -u -d "7 days ago" +%Y-%m-%d 2>/dev/null || date -u -v-7d +%Y-%m-%d) TO_DATE=$(date -u +%Y-%m-%d) PROMPT="Search X for posts by OTHER people mentioning the project \"${NAME}\" (also its site ${DOMAIN} and repo ${REPO} when given), posted between ${FROM_DATE} and ${TO_DATE}. Exclude posts by the operator @${OPERATOR} and by the project's own accounts. For each mention return: @handle, the full post text, date, exact engagement counts (likes, retweets, replies; 0 if unknown), the poster's approximate follower count if visible, and the direct link https://x.com/handle/status/ID. Prioritize people discovering it for the first time, asking confused questions, hitting friction (setup/docs/missing feature), comparing it to a competitor, or requesting a feature. Return a numbered list; if nobody is talking about it, say so explicitly." jq -n --arg p "$PROMPT" --arg fd "$FROM_DATE" --arg td "$TO_DATE" \ '{model:"grok-4.6", input:[{role:"user",content:$p}], tools:[{type:"x_search",from_date:$fd,to_date:$td}]}' \ > /tmp/xai-mr-payload.json HTTP=$(./secretcurl -s -o /tmp/xai-mr.json -w '%{http_code}' --max-time 150 -X POST "https://api.x.ai/v1/responses" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer {XAI_API_KEY}" \ -d @/tmp/xai-mr-payload.json) echo "xai http=$HTTP bytes=$(wc -c </tmp/xai-mr.json)"On
HTTP=200with a non-empty body, parse/tmp/xai-mr.jsonwithjq -r '.output[] | select(.type == "message") | .content[] | select(.type == "output_text") | .text'and feed the X mentions into categorization (step 4). RecordX_SOURCE=api.Path B — WebSearch (broader web + X fallback). Always use WebSearch for the non-X surfaces — Reddit, Farcaster, personal blogs, newsletters, GitHub Discussions, HN, Product Hunt:
- Try both brand name and URL variants
- Time-box to last 7 days where the search engine supports it
- Skip results from the operator's own accounts and the project's own repos
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 141 lines · 31 tokens per session scan A 41875dfe0e27
mention-radar is a skill published in the GitHub repository aeonfun/aeon (716 stars, last pushed yesterday), licensed MIT. It adds 31 tokens to every session and 2,763 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
flowcraft-config
Author, validate, and troubleshoot complete FlowCraft deployment configuration (deploy.yaml with the runtime section, inference/workspace/sandbox/tool sub-documents, core/memory contracts, and graph JSON node wiring). Use when writing or reviewing FlowCraft configs, assembling an agent deployment, adding…
api-interface-design
Use when designing public APIs, module boundaries, provider adapters, tool schemas, or data contracts.
explore
Explore the codebase and summarize how the project is wired.
unit-converter
Converts values between metric and imperial units, using the project's agreed factors.
flow-define
Multi-AI requirements scoping using Codex and Gemini CLIs (Double Diamond Define phase). Use when: AUTOMATICALLY ACTIVATE when user requests clarification or scoping:. "define the requirements for X". "clarify the scope of Y".
flow-develop
Multi-AI implementation using Codex and Gemini CLIs (Double Diamond Develop phase). Use when: AUTOMATICALLY ACTIVATE when user requests building or implementation:. "build X" or "implement Y" or "create Z". "develop a feature for X".