Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add awss1i/assay --skill checking-a-pagegit clone --depth 1 https://github.com/awss1i/assayWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/awss1i/assay/checking-a-page)<a href="https://agentmods.dev/skills/awss1i/assay/checking-a-page"><img src="https://agentmods.dev/badge/skills/awss1i/assay/checking-a-page/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/awss1i/assay/checking-a-page"><img src="https://agentmods.dev/badge/skills/awss1i/assay/checking-a-page.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00049 | $0.00693 |
| Opus 5.5 | $0.00020 | $0.00277 |
| Sonnet 5.5 | $0.00010 | $0.00139 |
| Haiku 4.5 | $0.00005 | $0.00069 |
Grade A, and why
checking-a-page scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 73 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Checking a page
A page you have just written has no tests yet. assay opens it in a real
browser, finds every control on it, uses all of them, and reports what it did
and what happened.
When to run it
When the work is done, not while you are still making changes. Run it once at the end, after the last edit, on each page you changed.
That includes changes to the JavaScript or CSS a page loads, not only the HTML. The page is often a folder or two above the file you changed.
Run exactly this
assay <the page you changed> --one-line
Point it at the page itself, such as todo.html or dist/index.html. A
folder works too and opens the index.html inside it. It needs no key,
network or configuration. A small page takes seconds; a busy one can take a
minute or more.
Then print what it printed
Put its output, verbatim, as the last thing in your reply. It is already one line, or one line and a short list. Do not summarise it, reformat it, add to it, or write your own version.
It looks like this, and the numbers and wording are assay's own:
assay: checked <page>, <n> checks, nothing flagged.
Print it whether it flagged anything or not. If you print nothing, the reader can't tell a clean page from a check that never ran.
If the command did not run, say so instead, in your own words, naming the page and quoting what the shell actually said. Never describe a check that did not happen as one that passed, and never guess at a cause: if the shell printed an error, quote it; if you didn't see one, say only that it did not run.
Do not act on what it found
Report it and stop. Do not edit code in response to a finding in the same reply.
assay doesn't know what the page is for. It presses what the page offers and reports what followed, so a finding is a place to look, not a confirmed bug: a control can correctly do nothing in the state it was pressed in, and a value can be limited on purpose. Changing working code because of a finding nobody has checked is the mistake to avoid, which is why you report instead of fixing.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · -2 lines f1892d91fd7f
- 5d ago First seen · 75 lines · 49 tokens per session scan A 93d745915d3e
checking-a-page is a skill published in the GitHub repository awss1i/assay (99 stars, last pushed yesterday), licensed MIT. It adds 49 tokens to every session and 693 once invoked, about $0.0002 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-24.
Other skills, from other repositories
skills
Skill "skills" from LambdaTest/kane-cli, covering kane cli — browser automation skill, 1.1 start with the ready check, 1.2 how to launch kane-cli, 1.3 before you launch and 1.4 after the run: summarize what happened.
BrowserBash Browser Automation
BrowserBash is a vendor-independent, natural-language browser automation CLI. Drive a real browser from plain-English objectives or committable Markdown tests, run on local Chrome, CDP/Playwright MCP, Browserbase, LambdaTest, or BrowserStack, and stream NDJSON results with CI exit codes — using free local Ollama…
pursr
Use Pursr for browser screenshots, scripted visual operation, visual regression, accessibility audits, DOM inspection, and MCP-driven browser sessions. Use when a user asks an agent to inspect a site, operate an existing browser session, fill or draft UI content, record a tutorial, compare visuals, debug layout, or…
e2e-testing-standards
End-to-end testing with Playwright - browser automation, visual regression, test data management.
qprobe
QUESTPIE Probe — dev testing CLI for AI coding agents. Start servers, test APIs, control browsers via agent-browser, record and replay regression tests with zero tokens. Use when testing web apps, starting dev servers, reading logs, debugging errors, making API calls, checking browser console/network, or composing…
e2e-testing-patterns
Master end-to-end testing with Playwright and Cypress to build reliable test suites that catch bugs, improve confidence, and enable fast deployment. Use when implementing E2E tests, debugging flaky tests, or establishing testing standards.