Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add arthurpanhku/dvalincode --skill dvalin-security-scangit clone --depth 1 https://github.com/arthurpanhku/dvalincodeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/arthurpanhku/dvalincode/dvalin-security-scan)<a href="https://agentmods.dev/skills/arthurpanhku/dvalincode/dvalin-security-scan"><img src="https://agentmods.dev/badge/skills/arthurpanhku/dvalincode/dvalin-security-scan/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/arthurpanhku/dvalincode/dvalin-security-scan"><img src="https://agentmods.dev/badge/skills/arthurpanhku/dvalincode/dvalin-security-scan.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium MCP Rug Pull · line 16 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00077 | $0.00696 |
| Opus 5 | $0.00039 | $0.00348 |
| Sonnet 5 | $0.00015 | $0.00139 |
| Haiku 4.5 | $0.00008 | $0.00070 |
Grade A, and why
dvalin-security-scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 66 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Dvalin security scan
A deterministic scanner. No model runs and it never edits the target workspace.
The default dvalin_scan MCP call is read-only and persists no state.
Running it
If a dvalin MCP server is configured, call dvalin_scan. Otherwise:
npx -y dvalincode security scan . --scanners builtin --json --no-workflow
Scan the whole workspace — the scanner takes a directory, not a file. builtin
needs nothing installed. Add semgrep, trivy, or osv-scanner only if they
are already on PATH; missing engines are reported, not fatal.
Reading the result
{ "score": 88, "grade": "B", "metrics": { "critical": 0, "high": 1 },
"findings": [ { "ruleId": "dvalin/eval", "path": "app.js", "startLine": 3,
"securitySeverity": "7.5", "helpUri": "https://cwe.mitre.org/..." } ] }
Report findings by file and line, with the rule and why it matters. Cite
helpUri when the user may not know the vulnerability class. securitySeverity
is CVSS-shaped: ≥9 critical, ≥7 high, ≥4 medium.
What to do next
Fix findings the way you would fix any other bug: read the surrounding code first, then make the smallest change that removes the vulnerability class rather than the symptom. Add a regression test that fails on the old code. Re-run the scan to confirm.
When a reported finding will be repaired and the MCP server is available, call
dvalin_begin_verification with the same scan arguments. This explicit step
persists the compact workflow used by dvalin_get_finding and
dvalin_verify_findings; do not create one merely to report scan results.
If the user wants Dvalin itself to do the repair under policy, with tests and a clean re-scan required before anything can become a PR:
dvalincode dvalin . --fix --verify --draft-pr
That command does use a model and edits files, so propose it rather than running it unprompted.
Honest limits
- A clean scan is not proof the code is safe. It finds known high-signal patterns; it does not find business-logic flaws, and it can produce false positives. Say so instead of declaring the code secure.
- Do not suppress a finding to make the scan pass. If something is genuinely a
test fixture, exclude that path in
.dvalincodeignoreand say why. - The score is a triage heuristic, not a certification. Lead with the findings, not the number.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago Changed · +4 lines cf1be058749f
- 9d ago First seen · 62 lines · 77 tokens per session scan A 4c6e3db7c973
dvalin-security-scan is a skill published in the GitHub repository arthurpanhku/dvalincode (114 stars, last pushed yesterday), licensed MIT. It adds 77 tokens to every session and 696 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
coding-agents-farm
To orchestrate parallel coding-agent farms (Claude, Codex, Copilot, Gemini, etc.) on isolated git worktrees.
odds-api
Build custom apps, bots, dashboards, scanners, and MCP workflows using Odds API data access.
sw-handoff
Use when the user runs /sw-handoff or wants to carry over context before /clear — prepares a structured handoff (keep/discard file decision + summary + next task) and returns a load token for the next segment.
sw-load
Restore a session handoff into context. Use when the user provides a handoff token, asks to resume or continue previous work, the session-start output announces a handoff, or you are about to call loadhandoff.
sw-explain
Use when the user asks what a Session Watcher metric means (br, mf, pp, u, wall, sweet, valley) or runs /sw-explain — explains the requested metric in plain language and contextualizes it for the current session.
review-plan-with-claude
Review a development plan produced in Codex with Claude through Inspectrum. Use when the user asks for a Claude second opinion, wants Claude to review a plan, or requests a cross-model plan check from Codex.