Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/besty0728/unity-skills/packagenpx skills add Besty0728/Unity-Skills --skill packagegit clone --depth 1 https://github.com/Besty0728/Unity-SkillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/besty0728/unity-skills/package)<a href="https://agentmods.dev/skills/besty0728/unity-skills/package"><img src="https://agentmods.dev/badge/skills/besty0728/unity-skills/package.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00012 | $0.01422 |
| Opus 5 | $0.00006 | $0.00711 |
| Sonnet 5 | $0.00002 | $0.00284 |
| Haiku 4.5 | $0.00001 | $0.00142 |
Grade A, and why
unity-package scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 137 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Before calling any skill in this module: if you are about to call a skill with parameters guessed from its name or description, STOP — read this file (or fetch its schema via
GET /skills/recommend?includeSchema=true) first. If you already have the parameter definitions from recommend/schema, you may proceed straight to dryRun.
Triggers
- Adding or removing UPM packages
- Checking installed versions
- Searching the registry
- Scripting package operations
- 添加或移除 UPM 包、检查已装版本、搜索 registry、脚本化包操作
Package Skills
Manage installed Unity packages and package-related helper flows such as Cinemachine and Splines setup.
Guardrails
Operating Mode (v1.9 three-tier):
- Approval (default): query skills (
package_list,package_check,package_search,package_get_dependencies,package_get_versions,package_get_cinemachine_status) run directly.package_refreshis the only FullAuto mutator — onMODE_RESTRICTED, run the grant protocol for it. Every other mutator is auto-forbidden (next bullet) and grant does not unlock it. - Auto / Bypass: SemiAuto and FullAuto run directly.
- Auto-forbidden in this module:
package_install,package_remove,package_install_cinemachine,package_install_splines(allMayTriggerReload = true,RiskLevel = "high";package_removealso carriesSkillOperation.Delete). They returnMODE_FORBIDDENunder both Approval and Auto, and are reachable only under Bypass mode or via a user-managed Allowlist entry; the grant flow returnsMODE_FORBIDDENtoo, so do not attempt it. - Install/remove/refresh jobs return immediately with a
jobId; the actual package import + Domain Reload happens asynchronously and may make the REST server transiently unavailable. Poll withjob_status/job_wait.
DO NOT (common hallucinations):
package_add/package_updatedo not exist -> usepackage_installpackage_get_infodoes not exist -> usepackage_list,package_check,package_get_dependencies, orpackage_get_versionspackage_searchsearches the installed package cache only; it does not query the Unity Registry- Package query skills initialize their cache automatically after Domain Reload. During the short cold-start window they return
{ success: false, status: "refreshing", cacheReady: false, retryStrategy: "wait_and_retry", retryAfterSeconds: 2 }; retry instead of treating this asinstalled=false. - Package install/remove/refresh jobs can trigger package import and Domain Reload; expect transient server unavailability and use returned job IDs
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 137 lines · 12 tokens per session scan A ee890f248145
unity-package is a skill published in the GitHub repository Besty0728/Unity-Skills (1,698 stars, last pushed today), licensed MIT. It adds 12 tokens to every session and 1,422 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
hatch-pet-v1
Create, repair, validate, preview, and package legacy Codex v1 animated pet spritesheets from character art, screenshots, generated images, or visual references. Use when a project requires the 8x9, 1536x1872 pet contract with transparent unused cells, row-by-row animation prompts, QA contact sheets, preview videos…
16-marketing-psychology-global
Use when persuasion principles have to be applied to a specific asset — reciprocity, scarcity, authority, social proof, liking, commitment, and unity mapped onto copy, a landing page, an email, or an ad, each with a hypothesis and a test plan. Trigger on 'marketing psychology', 'Cialdini', 'persuasion principles'…
new-littlejs-game
Scaffold a brand-new, complete playable game project — LittleJS engine included, opens straight from disk in a browser with no server, smallest playable loop written for you. TRIGGER on ANY request to make/create/start/build a game when no other engine or framework is named — "make me a pong game", "make a breakout…
littlejs-conventions
LittleJS game engine (littlejsengine) conventions — REQUIRED before answering, writing, editing, reviewing, or debugging ANY LittleJS code, including one-line questions about a snippet. TRIGGER whenever "LittleJS" appears, or the code uses…
atlas-shape-art
Use when a LittleJS game's visuals are geometric/abstract/neon shapes or it has many round entities (orbs, gems, bubbles, asteroids, particles, stars), OR when speeding up a game that calls many drawCircle/drawEllipse/drawPoly/drawRegularPoly per frame. Renders shapes as tinted atlas tiles instead.
dotcraft-unity
Use when dotcraft-unity MCP or unityexecutecsharp is available, or when the user asks to inspect, automate, capture, or debug Unity Editor state, scenes, assets, Console logs, or GameView output. Provides background-first Unity Editor automation rules.