Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/coderadius-ai/coderadius/validate-payloadnpx skills add coderadius-ai/coderadius --skill validate-payloadgit clone --depth 1 https://github.com/coderadius-ai/coderadiusWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00016 | $0.00068 |
| Opus 5 | $0.00008 | $0.00034 |
| Sonnet 5 | $0.00003 | $0.00014 |
| Haiku 4.5 | $0.00002 | $0.00007 |
Grade A, and why
validate-payload scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Validate Payload
- Load the schema for the endpoint from the schema registry
- Validate the request body against the schema
- Return structured validation errors with field paths
- Log validation failures with correlation ID
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 12 lines · 16 tokens per session scan A 9f69ca7522ad
validate-payload is a skill published in the GitHub repository coderadius-ai/coderadius (24 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 16 tokens to every session and 68 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
mandu-mcp-index
MCP 도구 오케스트레이션 라우터 (always-on). 108개 MCP 도구 중 상황에 맞는 워크플로우 skill 선택, 집계>세분 우선순위, anti-pattern 카탈로그. MCP 도구 호출 직전 자동 참조.
mandu-mcp-verify
편집 후 검증 루프. 파일 편집 직후, "check 해줘", stop-hook 자동 호출. ateautopipeline + guardcheck + doctor 를 병렬로. 개별 ate 도구로 수동 분해 금지 — 실패했을 때만 drill-down.
mandu-lint
Lint 가이드 — 가드레일의 한 축. oxlint 셋업 / 실행 / type-aware / lefthook 통합. "lint 켜줘", "코드 스타일 검사", lint 에러 발생 시 자동 호출.
mandu-mcp-create-flow
스펙 우선 생성 워크플로우. "만들어줘", 피처/리소스/라우트 추가 시 자동 호출. contract → generate 순서를 강제하고 생성 직후 verify loop 로 전이. granular 도구 (addroute + createcontract + generate) 를 손으로 엮지 않는다.
mandu-mcp-deploy
빌드/배포 파이프라인 워크플로우. "배포", "deploy", release 전 자동 호출. deploy.check 는 fail-fast 게이트. deploy.preview 로 프로덕션 리허설. manual build + guard + seo 나열 대신 aggregate 도구 사용.
mandu-mcp-safe-change
위험 변경 트랜잭션 래퍼. 마이그레이션 / 대규모 리팩터 / refactor 도구 / "돌이킬 수 없는 변경" 시 자동 호출. historysnapshot + txbegin 필수, verify green 이면 txcommit, 아니면 txrollback.