Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/benchflow-ai/benchflow/suricata-rules-basicsnpx skills add benchflow-ai/benchflow --skill suricata-rules-basicsgit clone --depth 1 https://github.com/benchflow-ai/benchflowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/benchflow-ai/benchflow/suricata-rules-basics)<a href="https://agentmods.dev/skills/benchflow-ai/benchflow/suricata-rules-basics"><img src="https://agentmods.dev/badge/skills/benchflow-ai/benchflow/suricata-rules-basics.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00021 | $0.00879 |
| Opus 5 | $0.00010 | $0.00439 |
| Sonnet 5 | $0.00004 | $0.00176 |
| Haiku 4.5 | $0.00002 | $0.00088 |
Grade A, and why
suricata-rules-basics scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- suricata-rules-basics — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 131 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Suricata Rules Basics
This skill covers the core building blocks of Suricata signatures and how to express multi-condition DPI logic.
Rule anatomy
A typical alert rule looks like:
alert <proto> <src> <sport> -> <dst> <dport> (
msg:"...";
flow:...;
content:"..."; <buffer/modifier>;
pcre:"/.../"; <buffer/modifier>;
sid:1000001;
rev:1;
)
Key ideas:
sidis a unique rule id.revis the rule revision.- Use
flow:established,to_server(or similar) to constrain direction/state.
Content matching
content:"...";matches fixed bytes.- Add modifiers/buffers (depending on protocol) to scope where the match occurs.
Regex (PCRE)
Use PCRE when you need patterns like “N hex chars” or “base64-ish payload”:
pcre:"/[0-9a-fA-F]{64}/";
Sticky buffers (protocol aware)
For application protocols (e.g., HTTP), prefer protocol-specific buffers so you don’t accidentally match on unrelated bytes in the TCP stream.
Common HTTP sticky buffers include:
http.methodhttp.urihttp.headerhttp_client_body(request body)
Practical tips
- Start with strict conditions (method/path/header), then add body checks.
- Avoid overly generic rules that alert on unrelated traffic.
- Keep rules readable: group related matches and keep
msgspecific.
Task template: Custom telemetry exfil
For the suricata-custom-exfil task, the reliable approach is to compose a rule using HTTP sticky buffers.
Important: This skill intentionally does not provide a full working rule. You should build the final rule by combining the conditions from the task.
A minimal scaffold (fill in the key patterns yourself)
alert http any any -> any any (
msg:"TLM exfil";
flow:established,to_server;
# 1) Method constraint (use http.method)
# 2) Exact path constraint (use http.uri)
# 3) Header constraint (use http.header)
# 4) Body constraints (use http_client_body)
# - blob= parameter that is Base64-ish AND length >= 80
# - sig= parameter that is exactly 64 hex characters
sid:1000001;
rev:1;
)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 131 lines · 21 tokens per session scan A 12311a48a3bd
suricata-rules-basics is a skill published in the GitHub repository benchflow-ai/benchflow (340 stars, last pushed today), licensed Apache-2.0. It adds 21 tokens to every session and 879 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
lastlight-evals
Scaffold, configure and run a Last Light EVALS workspace — the harness that runs Last Light's real workflows against a mocked GitHub and grades them deterministically. Use when the user wants to "set up / scaffold Last Light Evals", "create an evals workspace or instance", "run evals", "compare models", or author new…
desktop-principles
Desktop-specific UX principles - hover states, pointer precision, keyboard shortcuts, multi-window, focus management. Covers macOS, Windows, Linux, web desktop.
canvas-generative
Algorithmic and generative art with Canvas 2D - particles, flow fields, noise, fractals, L-systems.
ceo-setup
One-time onboarding for the executive/manager commitment workflow — delegation-heavy, meeting prep, decision capture, morning and evening digests. Creates a commitments project and installs two dashboard widgets. After successful setup this skill is excluded from selection until the marker file is deleted.
portfolio
Cross-chain DeFi portfolio discovery, rebalancing suggestions, and NEAR Intent construction. Activates when the user pastes a wallet address or asks about yield/positions/rebalancing. Bootstraps a per-user "portfolio" project, aggregates positions across all the user's addresses inside one project, and offers a…
content-creator-setup
One-time onboarding for the content creator workflow — content pipeline stages, trend expiration, cross-platform cascades, heavy idea parking. After successful setup this skill is excluded from selection until the marker file is deleted.