Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add chrischall/honeybook-mcp --skill honeybookgit clone --depth 1 https://github.com/chrischall/honeybook-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/chrischall/honeybook-mcp/honeybook)<a href="https://agentmods.dev/skills/chrischall/honeybook-mcp/honeybook"><img src="https://agentmods.dev/badge/skills/chrischall/honeybook-mcp/honeybook/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/chrischall/honeybook-mcp/honeybook"><img src="https://agentmods.dev/badge/skills/chrischall/honeybook-mcp/honeybook.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00096 | $0.02223 |
| Opus 5 | $0.00048 | $0.01111 |
| Sonnet 5 | $0.00019 | $0.00445 |
| Haiku 4.5 | $0.00010 | $0.00222 |
Grade A, and why
honeybook scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 117 lines — stays where its author put it; the contents beside it link to each section on GitHub.
honeybook-mcp
MCP server for HoneyBook's client portal — contracts, invoices, questionnaires, messages, meetings, tasks and payments across multiple wedding vendors, with magic-link session capture, in-portal messaging, and deep-link fallback for signing and paying.
Tools
use_magic_link— Capture a portal session from a vendor magic-link URL (/app/link/resolve/…)use_flow_link— Capture a questionnaire credential from a flow link (/flow/<flowId>?hash=…)list_active_sessions— Show active credentials, split intoportalSessionsandflowCredentialsget_flow(flow_id?, view?)— Read one questionnaire (flow) and its answers (two calls: public/minimalfor the vendor company id, then/client/flow/<id>/active?ctxc=…)list_workspace_files— All files one vendor has shared (filter by type)get_workspace_file(file_id, section?)— Full detail for one file. Takessection, notview— see belowget_workspace— Workspace detail + status flagslist_payment_methods— Saved payment methodssign_contract— Deep link to sign in portal (requiresconfirm:true)pay_invoice— Deep link to pay in portal (requiresconfirm:true)list_projects— Your projects (HoneyBook "events") with a vendor, each with theworkspace_idthe tools below takeget_project(project_id, view?)— Project details: date, time, location, guests, custom fields, people (name/email/phone/role)list_messages— Messages in a workspace (kind=activityfor the activity log,kind=allfor both): compact cards, newest first; never marks anything seenget_message— One message in full (format=textdefault, orhtml) with attachments and delivery statussend_message— Send a new message (subject+body) or reply (reply_to_message_id, subject inherited) through the portal; requiresconfirm:truemark_messages_seen— Mark feed items seen, the way opening the Activity tab doeslist_meetings— Meetings the vendor scheduled (consultations, Zoom calls): time, join link, password; rescheduled meetings show their latest timelist_tasks— Tasks assigned to you with today/this-week/overdue counts and task groupslist_notes— Notes the vendor shared (meeting notes, AI recaps)list_attachments— Loose images, files and bookmarks (not contracts/invoices — those are workspace files)list_payments— Every payment on every file in a workspace, with paid/unpaid totals
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago Changed · +59 lines be22e6dfbe6d
- 8d ago Changed · +23 lines · +23 tokens per session 27f6df451e83
- 11d ago First seen · 35 lines · 73 tokens per session scan A b59b44ff1474
honeybook is a skill published in the GitHub repository chrischall/honeybook-mcp (1 stars, last pushed today), licensed MIT. It adds 96 tokens to every session and 2,223 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
expense-review-policy
Review invoices and contracts against accounts-payable policy before human approval.
audit-support
Support SOX 404 compliance with control testing methodology, sample selection, and documentation standards. Use when generating testing workpapers, selecting audit samples, classifying control deficiencies, or preparing for internal or external audits.
kyc-doc-parse
Parse an investor or client onboarding packet into structured KYC fields — identity, ownership, control, source of funds, and document inventory. Use as the first step of KYC screening; output feeds the rules engine.
fiscaliste
Fiscaliste IA pour la fiscalité personnelle des particuliers français : optimisation et déclaration de l'impôt sur le revenu, IFI, revenus du capital, revenus fonciers, equity salarial, crypto-actifs et PER. Couvre le calcul de l'IR (barème, quotient familial, décote, PAS, CEHR, revenus exceptionnels), la déclaration…
regulatory-analysis
Analyzes documents and processes against FINRA, SEC, Federal Reserve, and CFPB regulatory frameworks. Identifies compliance gaps, classifies findings by severity, and recommends remediation. Use when performing compliance audits, regulatory reviews, gap analyses, or verifying policy adherence to financial regulations.
subcontractor-payment-tracker
Track subcontractor payments, lien waivers, and compliance. Manage payment schedules and documentation.