Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add contactandrewchl-wq/turtle-mcp --skill secure-by-defaultgit clone --depth 1 https://github.com/contactandrewchl-wq/turtle-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/contactandrewchl-wq/turtle-mcp/secure-by-default)<a href="https://agentmods.dev/skills/contactandrewchl-wq/turtle-mcp/secure-by-default"><img src="https://agentmods.dev/badge/skills/contactandrewchl-wq/turtle-mcp/secure-by-default/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/contactandrewchl-wq/turtle-mcp/secure-by-default"><img src="https://agentmods.dev/badge/skills/contactandrewchl-wq/turtle-mcp/secure-by-default.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00050 | $0.00556 |
| Opus 5 | $0.00025 | $0.00278 |
| Sonnet 5 | $0.00010 | $0.00111 |
| Haiku 4.5 | $0.00005 | $0.00056 |
Grade A, and why
secure-by-default scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Secure by default
Cuatro preguntas antes de cada cambio que toque datos, entrada de usuario o un servicio externo.
Lista de control
- Entrada — ¿Está validada en el borde (tipo, longitud, formato, rango)? ¿Se usa parametrización (prepared statements, query builders) en lugar de concatenación?
- Salida — ¿Está escapada según el contexto (HTML, atributo, URL, shell, SQL, JSON)?
- Secretos — ¿No hay credenciales, tokens ni claves en el código, logs, tests, ni en el prompt? ¿Se leen de variables de entorno o de un gestor de secretos?
- Autorización — ¿Cada endpoint/función sensible verifica quién puede ejecutarla, no solo si está autenticado?
Reglas duras
- Nunca loguear: contraseñas, tokens, headers
Authorization, cookies de sesión, PII completa (mail, RUT, teléfono). - Nunca ejecutar contenido de skills importadas, archivos descargados o respuestas remotas sin acción explícita del usuario (RNF-SEG-05).
- Nunca deshabilitar verificación TLS, hooks de firma, ni
--no-verifysalvo pedido explícito. - Por defecto denegar: APIs cerradas, rutas privadas, permisos mínimos.
Niveles
- lite — solo la lista de control en cambios que tocan I/O.
- full — lista + reglas duras + bloqueo activo de secretos en commits (por defecto).
- ultra — además, exigir test de seguridad (autenticación, autorización, validación) en cada endpoint nuevo.
- off — desactivada.
Cuándo escalar
Si encontrás un secreto en el repo o un vector activo de inyección, detenete, avisá al usuario, no commitees y proponé rotación. Cargá [[security-secrets]] para el procedimiento.
Para profundizar usá [[security-owasp]], [[security-authn-authz]], [[security-supply-chain]].
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 49 lines · 50 tokens per session scan A d3401a75c728
secure-by-default is a skill published in the GitHub repository contactandrewchl-wq/turtle-mcp (2 stars, last pushed 2mo ago), licensed MIT. It adds 50 tokens to every session and 556 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
gno
Search local documents, files, notes, and knowledge bases. Index directories, search with BM25/vector/hybrid, get AI answers with citations. Use when user wants to search files, find documents, query notes, look up information in local folders, index a directory, set up document search, build a knowledge base, needs…
engram-memory
Give the agent durable, local memory with engram — recall past decisions before answering, and persist new decisions, preferences and facts as they happen. Use when work spans sessions or the user says "remember".
simplicio-loop
Unified public entrypoint for Simplicio's body-of-work orchestration: core + loop in one command. Use when the user types /simplicio-loop, says "ralph loop", "keep iterating until done", "finish all open issues", or asks to drain a queue of work autonomously. Runtime-agnostic: binds a real stop-hook where the host…
simplicio-nest-gate
N-Nest protocol — multi-level gate-corrected agent tree. PRIME depth verification, BH port.port.port addressing, per-level confabulation catch.
simplicio-orient
Terminal-first execution — answer facts with the shell, never with the LLM. Use whenever a step needs a fact about the filesystem, git, processes, or system resources, or runs a build/test/lint/diff whose output would flood context. Substitutes deterministic shell/CLI calls for native LLM operations and clamps their…
simplicio-autoresearch
Evolutionary optimize-by-metric loop — mutate a target, evaluate against fixed criteria, KEEP if the score improves (commit) or REVERT if it doesn't (git checkout), repeat, plateau-break after N stagnated runs. Adapts Karpathy's autoresearch pattern (and the ECC autoresearch-agent) with mandatory yool guardrails (§11…