Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ai-driven-dev/framework --skill 02-checkgit clone --depth 1 https://github.com/ai-driven-dev/frameworkWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ai-driven-dev/framework/02-check)<a href="https://agentmods.dev/skills/ai-driven-dev/framework/02-check"><img src="https://agentmods.dev/badge/skills/ai-driven-dev/framework/02-check/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ai-driven-dev/framework/02-check"><img src="https://agentmods.dev/badge/skills/ai-driven-dev/framework/02-check.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00091 | $0.00423 |
| Opus 5 | $0.00046 | $0.00211 |
| Sonnet 5 | $0.00018 | $0.00085 |
| Haiku 4.5 | $0.00009 | $0.00042 |
Grade A, and why
02-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Check
flowchart LR
ask([project]) --> locate --> diagnose
diagnose --> inplace([what is in place])
inplace -.->|"measurement off"| stopped([stopped])
inplace -.->|"not a git repository"| stopped
inplace --> answer([four claims])
Actions
Run the flow above. Read only the next action file.
| Action | Does |
|---|---|
| locate | confirm the CLI |
| diagnose | run it, and present every line it printed |
Transversal rules
- Checking that a hook fired is not the same as checking that a file exists. A run file with only
session_startis not evidence of anything closed. - Run only
aidd telemetry check. Never a script, and never a command belonging to another skill. - Present every printed line. A line this skill leaves out is a claim the user cannot check.
- What is in place is printed first and is never a claim — it appears whether or not measurement is on, and names the file behind every fact so the user can go and change it.
ok,FAILand--are three different answers.--means there was nothing to evaluate, not that the chain is healthy.- A declaration that the recorder is set up is not proof it fired. Relay it as what it is — a fact about configuration, never a promise about behaviour.
- The
aiddcommand cannot be found: say so and check nothing.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 36 lines · 91 tokens per session scan A fbd2bf01b028
02-check is a skill published in the GitHub repository ai-driven-dev/framework (460 stars, last pushed yesterday), licensed MIT. It adds 91 tokens to every session and 423 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-09.
Other skills, from other repositories
image-generation
Use this skill when the user requests to generate, create, imagine, or visualize images including characters, scenes, products, or any visual content. Supports structured prompts and reference images for guided generation.
podcast-generation
Use this skill when the user requests to generate, create, or produce podcasts from text content. Converts written content into a two-host conversational podcast audio format with natural dialogue.
vercel-deploy
Deploy applications and websites to Vercel. Use this skill when the user requests deployment actions such as "Deploy my app", "Deploy this to production", "Create a preview deployment", "Deploy and give me the link", or "Push this live". No authentication required - returns preview URL and claimable deployment link.
skill-reviewer
Reviews DeerFlow skill packages for readiness, triggers, safety boundaries, resources, and evidence. Invoke when users ask to audit, grade, or production-check an existing skill.
build-monetized-app
Use when the task is building a new app on Eliza Cloud that earns money — chat apps, agent apps, MCP-backed tools, anything that calls the cloud's chat/messages/inference endpoints on behalf of users. Covers app registration, container deploy, markup configuration, affiliate header, app charge requests, x402 payment…
tmux
Remote-control tmux sessions for interactive CLIs by sending keystrokes, capturing pane output, and managing terminal multiplexer windows. Enables parallel coding-agent orchestration, background process management, and REPL interaction via sockets. Use when the agent needs to launch, monitor, or coordinate…