Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/bish-x/bx-dev-skill/ai-securitynpx skills add bish-x/bx-dev-skill --skill ai-securitygit clone --depth 1 https://github.com/bish-x/bx-dev-skillWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/bish-x/bx-dev-skill/ai-security)<a href="https://agentmods.dev/skills/bish-x/bx-dev-skill/ai-security"><img src="https://agentmods.dev/badge/skills/bish-x/bx-dev-skill/ai-security.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00048 | $0.03484 |
| Opus 5 | $0.00024 | $0.01742 |
| Sonnet 5 | $0.00010 | $0.00697 |
| Haiku 4.5 | $0.00005 | $0.00348 |
Grade A, and why
ai-security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
The source is not reproduced here
No licence file
A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 305 lines · 48 tokens per session scan A d8c476626472
ai-security is a skill published in the GitHub repository bish-x/bx-dev-skill (23 stars, last pushed 3mo ago), with no licence file. It adds 48 tokens to every session and 3,484 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
ai-detector
Evidence-based AI-generated text risk analysis for essays, emails, reviews, articles, messages, and other prose samples.
llm-intern-skill
Use when polishing, diagnosing, tailoring, or exporting resumes for LLM, RAG, Agent, Agentic RL, post-training, pretraining, AIGC, search/ranking, multimodal, AI backend, or LLM algorithm internships from raw resume text, a materials folder, and/or a target job description. Audits evidence, maps JD fit, enforces truth…
math-research-activator
数学研究路由器:为 AI 架构/算子设计、理论性质分析、数学结构迁移,以及密码学定义、构造、归约与协议审查,选择必要的数学透镜、知识锚点和设计检查。也用于与 AI 研究有关的数学查询。纯实现型 debug、重构、调参和一般代码审查不触发。 English: Route AI architecture/operator design, theoretical analysis, math-to-AI transfer, and cryptographic definitions, constructions, reductions, or protocol reviews to the minimum necessary…
data-integrity-post-normalize
Apply a composable pipeline of normalization operations to a string. Trim whitespace, fix encoding, normalize unicode, strip HTML, and more — in a single call.
token-saver
Minimize token consumption & maximize prompt cache hit rate. Use when user asks to save tokens, reduce cost, improve cache hit rate, or be more concise.
seedance-2-5-prompt-director
为 Seedance 2.5 编写、诊断和重写可直接投喂的视频提示词,覆盖文生视频、图生视频、多图片视频音频参考、最长 30 秒叙事、多轮延长、指定时间段编辑、运镜与视角编辑、绿幕合成、白模渲染、声音与口型同步。用户提到 Seedance 2.5、即梦视频、@图片、@视频、@音频、长视频延长、局部编辑、白模参考、绿幕背景,或要求优化 Seedance 提示词时使用。普通跨模型写实短视频优先使用 realistic-video-prompting。.