Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/apiliumcode/mayros/prompt-guardnpx skills add ApiliumCode/mayros --skill prompt-guardgit clone --depth 1 https://github.com/ApiliumCode/mayrosWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00015 | $0.00408 |
| Opus 5 | $0.00008 | $0.00204 |
| Sonnet 5 | $0.00003 | $0.00082 |
| Haiku 4.5 | $0.00002 | $0.00041 |
Grade A, and why
prompt-guard scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
prompt-guard
Detects prompt injection patterns in graph content and classifies findings by risk level.
When to Use
Use this skill when:
- Inspecting user-submitted text stored in the knowledge graph for injection attempts
- Auditing graph content before it reaches downstream agents or tools
- Monitoring for adversarial inputs such as role overrides, encoding evasion, or jailbreak prompts
Risk Classification
Each finding is classified into one of three levels:
- dangerous -- Active injection attempts (role overrides, system overrides, jailbreak, shell commands)
- suspicious -- Evasion techniques or anomalies (zero-width characters, homoglyphs, encoding tricks, template injection)
- safe -- No injection patterns detected
The overall classification for a scanned item is dangerous if any dangerous finding exists, suspicious if only suspicious findings exist, and safe otherwise.
Instructions
- Store text content in the graph using
skill_assertorskill_graph_query - Query with predicate
guard:scan-resultto trigger the prompt-guard runtime - The skill enriches each result with a
classificationfield and afindingsarray - Use
guard:injection-detected(with proof) to record confirmed injection attempts - Query
guard:historyto review past scan results for the current agent
What ships with it
9 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 51 lines · 15 tokens per session scan A fd2b4dffbb35
prompt-guard is a skill published in the GitHub repository ApiliumCode/mayros (12 stars, last pushed 1mo ago), licensed MIT. It adds 15 tokens to every session and 408 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
campaign
Start, drive, monitor, and stop an Autonomous Improvement Campaign — a durable, repeatable wrapper around the dev-improve loop.
dev-loop
Pull the next task from a platform Ralph Loop queue (via the devloop MCP bridge) and drive it to a verified, committed, reported outcome. One task per invocation — this is a Ralph-pattern loop body designed to be driven repeatedly by /loop /dev-loop.
gen-tests
Generate RSpec request specs for untested controllers and service specs for untested services.
improve
Discover, offer, and triage code-quality improvements for the dev-improve loop.
verify
Run targeted verification based on what changed since last commit.
audit
Run comprehensive codebase quality and pattern compliance audit.