Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/codeshux/tokenwise/undonpx skills add CodeShuX/tokenwise --skill undogit clone --depth 1 https://github.com/CodeShuX/tokenwiseWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00056 | $0.00689 |
| Opus 5 | $0.00028 | $0.00345 |
| Sonnet 5 | $0.00011 | $0.00138 |
| Haiku 4.5 | $0.00006 | $0.00069 |
Grade B, and why
undo scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
2. ~/.claude/settings.json.tokenwise-backup-20260511-143219 How it starts
The opening of the file, as written. The whole thing — 78 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/tokenwise:undo — Restore from backup
Find TokenWise backups and restore one.
Steps
-
Find backups with Bash:
find ~/.claude -maxdepth 3 -name "*.tokenwise-backup-*" 2>/dev/null find . -maxdepth 3 -name "*.tokenwise-backup-*" 2>/dev/null -
If none found:
No TokenWise backups found. Backups are created automatically by /tokenwise:install before any file modification. If you've never run /tokenwise:install, there's nothing to undo. If you removed the backups manually, you'll need to restore from version control or recreate config by hand. -
If found, print a numbered list:
TokenWise backups found: 1. ~/.claude/CLAUDE.md.tokenwise-backup-20260511-143218 (target: ~/.claude/CLAUDE.md, created <relative time>) 2. ~/.claude/settings.json.tokenwise-backup-20260511-143219 (target: ~/.claude/settings.json, created <relative time>) Restore which? (1-N, or 'all', or 'cancel'): -
Parse user response:
- Single number → restore that one
all→ restore all backupscancel(or empty) → exit withNo changes made.
-
For each backup to restore:
- Derive target path: strip the
.tokenwise-backup-<ts>suffix - Confirm:
Restore <target> from <backup>? This will overwrite <target>. [Y/n] - If Y:
- Read current target file (if exists), back it up to
<target>.tokenwise-pre-undo-<ts>(so undo is reversible) - Copy backup over target:
cp <backup> <target> - Verify by reading target — confirm content matches backup
- Read current target file (if exists), back it up to
- If n: skip
- Derive target path: strip the
-
Optionally delete the consumed backup:
Delete the backup file <backup> now that it has been restored? [Y/n] -
Print summary:
Undo complete. Restored: <list> Pre-undo backups (in case you want to redo): <list> -
Remind user: "Restart Claude Code so the original CLAUDE.md / settings.json take effect."
Edge cases
- Multiple backups for the same target file: the user should pick which one. Print them sorted by timestamp descending (newest first).
- Backup file is empty: warn before restoring (
Backup is empty. Restoring will leave <target> empty. Continue?). - Target file no longer exists: that's fine — restore creates it.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 78 lines · 56 tokens per session scan B 1c1c57f69d26
undo is a skill published in the GitHub repository CodeShuX/tokenwise (3 stars, last pushed 6d ago), licensed MIT. It adds 56 tokens to every session and 689 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
archify
Create polished, validated architecture, workflow, sequence, data-flow, and lifecycle/state diagrams as explorable standalone HTML with inline SVG, dark/light themes, optional trace motion, and PNG/JPEG/WebP/SVG/WebM export. Accept plain-language requirements or pasted Mermaid flowchart, sequenceDiagram, and…
vox-director
Turn ONE topic into a finished Vox-style paper-collage explainer / ad video, end to end on the Atlas Cloud API + local ffmpeg — script, collage keyframes, motion, voice-over, music, captions, all automated. Use this whenever the user wants a "Vox style" video, a paper/torn-paper collage animation, a "motion collage"…
social-post
學習使用者的 Facebook/Instagram/YouTube/Threads/X 語氣與受眾,規劃、撰寫、確認後發佈內容;以已登入 Chrome 受控掃描、草擬及回覆 FB/IG/Threads 留言;並作為流量、留存與轉化的結構化帳本。使用者說「發文」「用我的口氣」「回覆留言」「自動回留言」「掃留言」「查流量」「演算法」「把數據訓練進去」「比較貼文」「優化 pattern」時使用。.
privacy-jp
日本サービス向け(일본 서비스용) プライバシーポリシー・利用規約・同意モーダル・Cookieバナー 자동 생성. 個人情報保護法(APPI)·消費者契約法·特定商取引法 반영. Next.js 1316 프로젝트 대상.
higgsfield
Use this skill whenever the user asks anything about Higgsfield AI — writing or refining video/image prompts, choosing a model (Kling, Sora 2, Veo, Wan, Seedance, Minimax Hailuo, DoP, Soul, Nano Banana, Seedream, Flux, GPT Image, etc.), camera controls, named motion presets, Soul ID character consistency, Cinema…
higgsfield-camera
Use when the user asks about camera movements, shot types, or how to describe camera behavior in a Higgsfield prompt. Contains all named camera controls with descriptions, best use cases, and example prompt phrases.