Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/alibaba/anolisa/ktunernpx skills add alibaba/anolisa --skill ktunergit clone --depth 1 https://github.com/alibaba/anolisaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/alibaba/anolisa/ktuner)<a href="https://agentmods.dev/skills/alibaba/anolisa/ktuner"><img src="https://agentmods.dev/badge/skills/alibaba/anolisa/ktuner.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00046 | $0.00768 |
| Opus 5 | $0.00023 | $0.00384 |
| Sonnet 5 | $0.00009 | $0.00154 |
| Haiku 4.5 | $0.00005 | $0.00077 |
Grade B, and why
ktuner scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Asks for rootmediumPrivilege escalation
A mod that escalates privileges can change anything on the machine, not only the project.
sudo ktuner tune --dry-run What it actually says
ktuner — 内核参数自动调优
核心能力
ktuner 是确定性规则引擎(非 LLM),评估 207 条内核调优规则,输出 JSON 格式的诊断结果和建议。
所有输出在 stdout,格式为 JSON。错误输出在 stderr,格式也是 JSON。
使用流程
第一步:诊断
ktuner check
输出示例:
{
"score": 30,
"predicted_score": 100,
"total_checked": 196,
"recommendations": [
{
"param": "net.ipv4.tcp_rfc1337",
"current": "0",
"recommended": "1",
"reason": "防止 TIME_WAIT 状态下的 RST 攻击",
"confidence": "high",
"category": "security",
"writable": true
}
],
"system": { "kernel": "6.6.102+", "cpu_cores": 2, "memory_gb": 8 },
"workload": "mixed",
"services": ["Nginx", "PostgreSQL"]
}
根据 score 判断是否需要调优:90+ 优秀,70-89 良好,低于 70 建议调优。
可选参数:
--category net|mem|io|cpu|security— 只看某一类--conservative— 只看高置信度建议
第二步:向用户解释建议
遍历 recommendations 数组,用中文向用户解释每条建议的 reason 和影响。
如果用户想了解某个具体参数:
ktuner why <参数名>
第三步:应用(需要 root,必须用户确认后才执行)
⚠️ 重要:tune 和 fix 会修改内核参数,必须先向用户展示建议内容,得到明确确认后再执行。
预览模式(不修改):
sudo ktuner tune --dry-run
应用全部建议:
sudo ktuner tune
只修一个参数:
sudo ktuner fix <参数名>
第四步:回滚(如果需要)
sudo ktuner rollback
输出:
{ "restored": 5, "failed": 0, "skipped": 0, "status": "Full" }
退出码
| 退出码 | 含义 |
|---|---|
| 0 | 成功(check 时表示系统已最优) |
| 1 | check 发现有建议(不是错误,表示可以优化) |
| 2 | 错误(详见 stderr 的 JSON) |
约束
- tune / fix / rollback 需要 root 权限(使用
sudo) - check / why 不需要 root
kernel.core_pattern、kernel.modprobe等代码执行参数被禁止写入- 调优后如发现性能劣化,使用
sudo ktuner rollback恢复
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 109 lines · 46 tokens per session scan B c0c1d58220a2
ktuner is a skill published in the GitHub repository alibaba/anolisa (618 stars, last pushed today), licensed Apache-2.0. It adds 46 tokens to every session and 768 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 1 finding (asks for root). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
beevibe-team-mesh-negotiation
Multi-round negotiation protocol — covers both initiator and peer roles. Use when about to call negotiate(), when receiving a intent block as a peer, or when receiving an 'escalated' sentinel from a blocked respondnegotiate. Covers proposal crafting, counter-strategy, deadlock detection, when to accept early…
beevibe-verify-pr
CI verification before marking a PR-bearing task done. Use BEFORE calling mcpbeevibeupdateprogress(done) on any session whose deliverable is a pull request — including the first dispatch (you opened the PR with gh pr create) and any revision dispatch (you pushed new commits to an existing PR). Watches the PR's…
beevibe-pre-task-setup
Cold-start git workspace setup for a fresh beevibe task. Use at the start of a session whose intent has a block but NO or block — i.e. the first dispatch of this task. Checks for an existing repo clone, pulls the base branch if present (clone if missing), prunes any per-task worktrees from earlier tasks whose work has…
beevibe-use-repo
You are the child agent inside a fresh Docker sandbox. Borrow the given GitHub repo, produce a real artifact for the goal, and export it. Do not review the repo. The proof is that it works.
spec-converge
Iteratively review an instar-development spec with multi-angle internal reviewers (security, scalability, adversarial, integration, decision-completeness, lessons-aware) and real cross-model external reviewers routed through the agent's own installed CLIs (codex → GPT-tier, gemini → Gemini-tier; one pass per available…
beevibe-discover-repo
Find the best GitHub repo for a goal, then call userepo to run it in a sandbox. Use whenever the user's goal requires a capability you don't have natively and you haven't been given a specific repo.