Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/day1labs/openava/xnpx skills add Day1Labs/OpenAva --skill xgit clone --depth 1 https://github.com/Day1Labs/OpenAvaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/day1labs/openava/x)<a href="https://agentmods.dev/skills/day1labs/openava/x"><img src="https://agentmods.dev/badge/skills/day1labs/openava/x.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00027 | $0.00880 |
| Opus 5 | $0.00014 | $0.00440 |
| Sonnet 5 | $0.00005 | $0.00176 |
| Haiku 4.5 | $0.00003 | $0.00088 |
Grade A, and why
x scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 96 lines — stays where its author put it; the contents beside it link to each section on GitHub.
X
Use this skill when the task is specifically about X content or account graphs and you want structured results from the authenticated web GraphQL endpoints instead of only scraping public web pages.
What this skill is good for
- search recent or top tweets for a topic
- fetch a user's profile data
- fetch a user's own tweet timeline
- inspect followers or following with cursor pagination
- switch between stored credentials and inline credentials when needed
Recommended workflow
- If the task needs authenticated X data and credentials may not be configured yet, call
x_authwithaction: "status"first. - If credentials are missing and the user has provided
auth_tokenand optionallyct0/ bearer, save them withx_authusingaction: "set". - Use
x_querywith exactly one operation at a time:user_profilesfor one or more usernamesprofile_tweetsfor a single target user timelinefollowers/followingfor graph traversalsearch_tweetsfor topic or keyword discovery
- For
profile_tweets,followers, andfollowing, preferusernameunless you already have auserId. - For
search_tweets, start withmaxResults: 10to20, then follownextCursoronly if the user wants deeper coverage. - When the returned data is insufficient or the user needs page-level context, follow up with
web_fetchon a tweet URL or profile URL.
Search guidance
Prefer search_tweets in these cases:
- the user asks what people are saying about a topic
- the user wants recent posts from multiple accounts
- the user wants structured filters like:
fromUsersexactPhraseshashtagsAnytweetTypeminLikessince/until
Useful tweetType values:
alloriginals_onlyreplies_onlyretweets_onlyexclude_repliesexclude_retweets
Use displayType: "latest" for recent coverage and displayType: "top" for more ranked results.
Pagination guidance
followers,following,profile_tweets, andsearch_tweetsmay returnnextCursor- only continue pagination when the user actually needs more than the first page
- mention when the result is only the first page of a larger set
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 96 lines · 27 tokens per session scan A 2fbb5671b861
x is a skill published in the GitHub repository Day1Labs/OpenAva (10 stars, last pushed 1mo ago), licensed MIT. It adds 27 tokens to every session and 880 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
agent-harness-fault-injection
Use when an agent workflow needs deterministic recovery evidence for sandbox, MCP/tool, worker, checkpoint, memory, or orchestration failures.
foundry-config-setup
Resolve missing setup caused by a hardcoded Foundry project endpoint or model in a sample. Use when a sample fails because it uses a placeholder/hardcoded projectendpoint (for example "https://your-project.services.ai.azure.com") or a hardcoded model instead of reading them from the environment.
error-recovery
Standard recovery patterns for all squad agents. When something fails, adapt — don't just report the failure.
agentic-workflow-designer
Conversational skill that interviews users to design new agentic workflows.
security-review
How to review PRs for security — credentials, injection, workflow permissions, supply chain, git operation safety.
shogun-screenshot
スクリーンショットの取得・加工を行う。ローカルスクショから最新画像を取得、 PlaywrightでWebページをキャプチャ、画像のトリミング・リサイズ、機微情報を黒塗りマスキング。 記事執筆、レポート作成、UI確認、画像加工時に起動。 「スクショ」「スクリーンショット」「画面キャプチャ」「最新のスクショ」「画像加工」「トリミング」「マスク」「写メ」「写メ撮った」「スクショ撮った」で起動。 Do NOT use for: 画像生成(shogun-imagegenを使え)。.