Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add aimerdoux/wavex-os --skill feishu-integration-developergit clone --depth 1 https://github.com/aimerdoux/wavex-osWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/aimerdoux/wavex-os/feishu-integration-developer)<a href="https://agentmods.dev/skills/aimerdoux/wavex-os/feishu-integration-developer"><img src="https://agentmods.dev/badge/skills/aimerdoux/wavex-os/feishu-integration-developer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.04799 |
| Opus 5 | $0.00000 | $0.02400 |
| Sonnet 5 | $0.00000 | $0.00960 |
| Haiku 4.5 | $0.00000 | $0.00480 |
Grade B, and why
feishu-integration-developer scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Sends data to an external URLmediumData exfiltration
A POST to an outside endpoint may be telemetry or may be exfiltration; either way the mod talks to somewhere, and you should know where.
const resp = await fetch( 'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal', { method: 'POST', The source is not reproduced here
A licence we could not identify
The repository carries a LICENSE file, but it is custom or dual enough that GitHub cannot name it and neither can this catalogue. Unknown terms are not permission, so the body is not copied here. Read the licence at the source and decide for yourself.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 601 lines · 0 tokens per session scan B 93655489cf67
feishu-integration-developer is a skill published in the GitHub repository aimerdoux/wavex-os (10 stars, last pushed 2mo ago), with no licence file. It costs nothing until one of its globs matches a file; then it loads 4,799 tokens. A static security scan graded it B with 1 finding (sends data to an external url). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
google-ai
Generate optional still images and off-camera narration through Google's Gemini API for Video Studio. Do not use Google video models: all Video Studio footage uses MiniMax H3 through fal.ai.
video-provider-capabilities
Resolve an AI-video model's live official API schema and turn it into a durable request, continuity, cost, and review plan before any paid video call. Use for Kling, Seedance, Veo, or any other video model when selecting a model, preparing or retrying a request, assigning image/video/audio references, using first or…
seedance-video
Plan and generate Seedance video effectively through current Seedance 2.0 and 2.5 endpoints on fal.ai, or supported direct Seeddance models through its separately authenticated API. Use when a production selects or considers Seedance for text-to-video, image-to-video, first/last-frame control, multimodal…
seeddance-api
Generate supported Seedance video through the independent Seeddance API at seeddance.io using the deployment's SEEDANCEAPIKEY, separately from fal.ai. Use when choosing between direct Seeddance and fal, checking direct account credits or model access, or submitting, polling, downloading, retrying, and reviewing direct…
veo-video
Plan and generate Google Veo video effectively through current fal.ai, Gemini API, or Vertex AI contracts. Use when a production selects or considers Veo for text-to-video, image-to-video, first/last-frame interpolation, reference-image identity or product guidance, Veo video extension, portrait video, high…
hive.browser-automation
Required before any hive-browser CLI command. The browser is driven from the terminal by running hive-browser ... --json via terminalexec — not via MCP tools. Teaches the browser lifecycle rules (the bridge attaches to the USER'S running Chrome — never kill or launch browser processes; timeouts are transport issues…