Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Dannykkh/skill-olympus --skill biz-strategygit clone --depth 1 https://github.com/Dannykkh/skill-olympusWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/dannykkh/skill-olympus/biz-strategy)<a href="https://agentmods.dev/skills/dannykkh/skill-olympus/biz-strategy"><img src="https://agentmods.dev/badge/skills/dannykkh/skill-olympus/biz-strategy/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/dannykkh/skill-olympus/biz-strategy"><img src="https://agentmods.dev/badge/skills/dannykkh/skill-olympus/biz-strategy.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 4 findings, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Agent Snooping · line 245 Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.Fix: Remove all code or instructions that list or read other skills' files or directories. Skills should operate independently; cross-skill access is a privilege escalation.
- medium Agent Snooping · line 246 Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.Fix: Remove all code or instructions that list or read other skills' files or directories. Skills should operate independently; cross-skill access is a privilege escalation.
- medium Agent Snooping · line 247 Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.Fix: Remove all code or instructions that list or read other skills' files or directories. Skills should operate independently; cross-skill access is a privilege escalation.
- medium Agent Snooping · line 248 Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.Fix: Remove all code or instructions that list or read other skills' files or directories. Skills should operate independently; cross-skill access is a privilege escalation.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00096 | $0.02853 |
| Opus 5 | $0.00048 | $0.01426 |
| Sonnet 5 | $0.00019 | $0.00571 |
| Haiku 4.5 | $0.00010 | $0.00285 |
Grade A, and why
biz-strategy scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 249 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Hermes (헤르메스) — 사업성 검토
헤르메스(Hermes): 상업과 무역의 신, 메신저. "이거 돈 되나?" — 프로젝트 시작 전, 사업성을 6개 영역으로 분석합니다.
Quick Start
/hermes # 전체 6개 영역 분석
/hermes "온라인 교육 플랫폼" # 주제 지정
/hermes --canvas-only # 비즈니스 모델 캔버스만
/hermes --market-only # 시장 분석만
공식 호출명: /hermes (별칭: 헤르메스, 사업성, 사업화)
파이프라인 위치
/hermes → /athena → /zephermine → /agent-team → ... → /estimate
사업분석 CEO 코칭 기술 설계 구현 견적서
독립 실행 가능 — 파이프라인 밖에서 단독 사용.
CRITICAL: First Actions
1. Print Intro
Hermes(헤르메스) — 상업의 신이 사업성을 검토합니다
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
7개 영역: 수요 검증 → 모델 → 수익 → 시장 → GTM → 지표 → 코호트
2. 주제 확인
$ARGUMENTS가 없으면 현재 CLI의 질문 방식으로 확인:
question: "어떤 사업/제품/서비스를 분석할까요?"
header: "분석 대상"
기존 젭마인 산출물(spec.md)이 있으면 거기서 자동 추출 가능.
3. Archive 기존 산출물
docs/hermes/{project-name}.md가 이미 존재하면 archive로 이동:
1. docs/hermes/archive/ 디렉토리 생성 (없으면)
2. 기존 파일 → docs/hermes/archive/{project-name}-{YYYY-MM-DD-HHMM}.md 로 이동 (Bash mv)
3. 새 산출물을 docs/hermes/{project-name}.md 에 생성
이렇게 하면 최신 결과는 항상 같은 경로에 있고, 이전 결과는 archive에 보존됩니다.
4. 웹 리서치 (3-Layer 합성)
분석 대상에 대해 WebSearch로 3계층 합성 리서치:
| Layer | 내용 | 검색 키워드 |
|---|---|---|
| Layer 1: 정석 | 이 분야에서 검증된 통설, 업계 표준 | "{주제} 시장 현황", "{산업} best practices" |
| Layer 2: 트렌드 | 최근 1~2년 새로운 흐름, 신규 플레이어 | "{주제} {올해} trends", "{산업} 신규 서비스" |
| Layer 3: 1원칙 | Layer 1~2를 의심 — 통설이 틀린 부분은? | 독자적 추론 (검색 아님) |
유레카 체크: Layer 3에서 통설과 모순되는 진짜 인사이트를 발견하면:
"EUREKA: 업계는 {A}가 정석이라 하지만, {대화에서 나온 증거}를 보면 {B}가 맞을 수 있다."
결과를 이후 7개 영역에 활용.
영역 0: 수요 검증 (Demand Reality)
시장 크기보다 먼저: "진짜 원하는 사람이 있는가?" (YC office-hours 방법론 참고)
4개 강제 질문 — 현재 CLI의 질문 방식으로 하나씩, 구체적이고 불편할 때까지 밀어붙이기:
Q1. 수요 현실: "이 제품이 내일 사라지면 진짜 패닉할 사람이 있나요? '관심 있다'가 아니라 '없으면 못 살겠다'인 사람요."
- 레드 플래그: "사람들이 관심 있어 해요", "대기자 500명", "VC가 좋아해요"
- 그린 플래그: 구체적 이름, 돈을 내는 행동, 매일 쓰는 사용자
Q2. 현상유지: "지금 이 문제를 어떻게 해결하고 있나요? — 엑셀, 카톡, 수작업이라도요."
- 현상유지가 "아무것도 안 함" → 수요가 약할 수 있음
- 현상유지가 "엑셀+카톡으로 4시간" → 강한 수요 신호
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 249 lines · 96 tokens per session scan A 3f0e4f24c000
biz-strategy is a skill published in the GitHub repository Dannykkh/skill-olympus (5 stars, last pushed today), licensed MIT. It adds 96 tokens to every session and 2,853 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
audit-orchestrator
Universal Pre-Scan → Analysis → Optimization → Report orchestrator for ANY project type — web apps (Astro/SvelteKit/Next), infrastructure/homelab repos, CLI tools, libraries, backend services, monorepos, data/ML projects, docs. Self-detects project type and runs the matching analysis track. Session state lives in…
capture-pdf
Website-to-PDF capture (all pages + interactive states). Use when: "capture", "pdf", "print", "screenshot", "capture pages".
audit
Systematic website audit (stack detection, 9 phases). Use when: "audit", "website audit", "site audit", "check website".
consult
Interactive project consultant. Scans your project, asks targeted questions, and creates a structured improvement plan.
freshness-check
Pipeline source freshness check (frameworks, tools, standards). Use when: "freshness", "update check", "is everything current", "check versions".
project-audit
Repository audit for non-website projects (CLI, libs, backend, monorepo). Use when: "project-audit", "project audit", "repo audit", "code audit".