Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add daxaur/openpaw --skill c-contactsgit clone --depth 1 https://github.com/daxaur/openpawWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/daxaur/openpaw/c-contacts)<a href="https://agentmods.dev/skills/daxaur/openpaw/c-contacts"><img src="https://agentmods.dev/badge/skills/daxaur/openpaw/c-contacts.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00021 | $0.00462 |
| Opus 5 | $0.00010 | $0.00231 |
| Sonnet 5 | $0.00004 | $0.00092 |
| Haiku 4.5 | $0.00002 | $0.00046 |
Grade A, and why
c-contacts scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Contacts — Address Book
Access macOS Contacts app via AppleScript. No CLI tool needed.
Commands
# Search for a contact by name
osascript -e 'tell application "Contacts"
set results to (every person whose name contains "John")
set output to ""
repeat with p in results
set output to output & name of p & linefeed
repeat with e in emails of p
set output to output & " Email: " & value of e & linefeed
end repeat
repeat with ph in phones of p
set output to output & " Phone: " & value of ph & linefeed
end repeat
set output to output & linefeed
end repeat
return output
end tell'
# Get all contact names
osascript -e 'tell application "Contacts" to get name of every person'
# Get a specific contact's email
osascript -e 'tell application "Contacts"
set p to first person whose name is "John Smith"
get value of every email of p
end tell'
# Get a specific contact's phone
osascript -e 'tell application "Contacts"
set p to first person whose name is "John Smith"
get value of every phone of p
end tell'
# Count contacts
osascript -e 'tell application "Contacts" to count every person'
# Search by email
osascript -e 'tell application "Contacts"
set results to (every person whose value of emails contains "john@")
get name of results
end tell'
Guidelines
- Always search by partial name (uses
contains) to be flexible - Return name, email, and phone by default
- If multiple matches, list all and let the user pick
- Contacts app does not need to be running — AppleScript handles it
- Never store contact details in memory files for privacy
- If asked "what's [name]'s number?", search contacts first, then memory
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 64 lines · 21 tokens per session scan A d273d979b9e2
c-contacts is a skill published in the GitHub repository daxaur/openpaw (167 stars, last pushed 3mo ago), licensed MIT. It adds 21 tokens to every session and 462 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
work-log-codex
A workflow for turning Codex and Claude Code session records into readable Markdown work logs. It can organize activity by project and date range, such as today, this week, or a custom period.
shell-scripting
A guide to writing Bash shell scripts, which automate command-line tasks on Linux and similar systems. It covers variables, arrays, conditions, loops, functions, and safer script structure.
ansible
A guide for using Ansible, a tool that automates commands and configuration across multiple computers. It covers hosts, reusable playbooks, modules, permissions, and check mode.
apple-reminders
Create and manage Apple Reminders on macOS using AppleScript - set due dates, priorities, and lists.
bear-notes
Create and manage notes in Bear on macOS using the Bear x-callback-url scheme.
cron-manager
Create, inspect, pause, and remove scheduled jobs using natural language descriptions.