Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add bks-lab/open-bridge --skill bridge-leak-checkgit clone --depth 1 https://github.com/bks-lab/open-bridgeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/bks-lab/open-bridge/bridge-leak-check)<a href="https://agentmods.dev/skills/bks-lab/open-bridge/bridge-leak-check"><img src="https://agentmods.dev/badge/skills/bks-lab/open-bridge/bridge-leak-check/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/bks-lab/open-bridge/bridge-leak-check"><img src="https://agentmods.dev/badge/skills/bks-lab/open-bridge/bridge-leak-check.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 2 findings, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Agent Snooping · line 88 Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.Fix: Remove all code or instructions that list or read other skills' files or directories. Skills should operate independently; cross-skill access is a privilege escalation.
- medium Agent Snooping · line 89 Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.Fix: Remove all code or instructions that list or read other skills' files or directories. Skills should operate independently; cross-skill access is a privilege escalation.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00153 | $0.01244 |
| Opus 5 | $0.00077 | $0.00622 |
| Sonnet 5 | $0.00031 | $0.00249 |
| Haiku 4.5 | $0.00015 | $0.00124 |
Grade A, and why
bridge-leak-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 100 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Bridge Leak Check — Categorized Content Scan
bridge-leak-check runs over a current repo state (not a diff), greps
the configured blocklists, and categorizes every hit into one of four
buckets so you don't drown in false positives. It complements
rules/promote-safety.md (which scans a diff per-destination at promote
time) by running on the post-merge state.
Read the referenced file ONLY when triggered.
Why both scans exist
| Scan | When | Scope | Strength |
|---|---|---|---|
rules/promote-safety.md |
At promote time | Diff only | Catches leaks introduced by the current commit |
bridge-leak-check |
Anytime | Whole repo state | Catches pre-existing leaks (from prior promotes, seedings, manual commits) |
The session that birthed this skill discovered that a clean source-side
scan does not guarantee a clean destination — open-bridge had three
pre-existing leaks (<your-username>-bks.yaml examples, com.bks.my-service,
bks wordmark) that no single promote scan caught because they predated
the per-repo blocklist.
Arguments
| Argument | Effect | Default |
|---|---|---|
(none) |
Scan current repo with the matching blocklist (auto-detected from .git/config origin) |
— |
--repo <name> |
Force which blocklist to apply (open-bridge / org-overlay / your-bridge / fallback) |
auto |
--strict-oss |
Also flag internal-vocabulary hardcoding (uses vocabulary_renames from bridge-audit/data/renames.yaml) |
false |
--report-only |
Only show categorized report; don't suggest fixes | false |
--target-dir <path> |
Scan a different working tree (e.g. /tmp/cloned-upstream) |
. |
Categories
Every hit lands in exactly one bucket:
| Category | Marker | Example | Action |
|---|---|---|---|
| Legitimate — self-reference | ✅ ✓ | bks-lab/open-bridge inside the open-bridge repo, schema $id URLs that point at this repo's published schemas |
Skip — this is correct |
| Legitimate — sister-repo | ✅ ✓ | {org}/bridge-deck cross-link in same OSS family |
Skip — this is correct |
| Leak — personal PII | 🔴 | <your-username>, /Users/<your-username>/, personal hostnames |
Always fix — replace with <your-username> placeholder |
| Leak — internal vocabulary (OSS-strict) | 🟡 | an org-shortname scope value (e.g. scope: acme) in shipped skill docs, a hardcoded org-bridge overlay slug as the only "internal overlay" example |
Generalize — see vocabulary_renames in bridge-audit/data/renames.yaml |
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 100 lines · 153 tokens per session scan A 1133abfc9385
bridge-leak-check is a skill published in the GitHub repository bks-lab/open-bridge (8 stars, last pushed today), licensed MIT. It adds 153 tokens to every session and 1,244 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
xlsx
Comprehensive spreadsheet creation, editing, and analysis with support for formulas, formatting, data analysis, and visualization. When Claude needs to work with spreadsheets (.xlsx, .xlsm, .csv, .tsv, etc) for: (1) Creating new spreadsheets with formulas and formatting, (2) Reading or analyzing data, (3) Modify…
Comprehensive PDF manipulation toolkit for extracting text and tables, creating new PDFs, merging/splitting documents, and handling forms. When Claude needs to fill in a PDF form or programmatically process, generate, or analyze PDF documents at scale.
pptx
Presentation creation, editing, and analysis. When Claude needs to work with presentations (.pptx files) for: (1) Creating new presentations, (2) Modifying or editing content, (3) Working with layouts, (4) Adding comments or speaker notes, or any other presentation tasks.
docx
Comprehensive document creation, editing, and analysis with support for tracked changes, comments, formatting preservation, and text extraction. When Claude needs to work with professional documents (.docx files) for: (1) Creating new documents, (2) Modifying or editing content, (3) Working with tracked changes, (4)…
mcp-host-styling-integration
Integrates MCP App UI with host theming system. Applies host CSS variables, handles onhostcontextchanged, safe area insets, display mode detection, and fullscreen configuration.
quality-hooks
Language-specific auto-lint/format/typecheck pipeline. Supports Python (ruff+pyright), TypeScript (prettier+eslint+tsc), Go (gofmt+golangci-lint). Auto-fix and convergence loops.