Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/florianbruniaux/cc-skill-usage/skill-usage-reportnpx skills add FlorianBruniaux/cc-skill-usage --skill skill-usage-reportgit clone --depth 1 https://github.com/FlorianBruniaux/cc-skill-usageWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/florianbruniaux/cc-skill-usage/skill-usage-report)<a href="https://agentmods.dev/skills/florianbruniaux/cc-skill-usage/skill-usage-report"><img src="https://agentmods.dev/badge/skills/florianbruniaux/cc-skill-usage/skill-usage-report.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00049 | $0.00871 |
| Opus 5 | $0.00024 | $0.00436 |
| Sonnet 5 | $0.00010 | $0.00174 |
| Haiku 4.5 | $0.00005 | $0.00087 |
Grade B, and why
skill-usage-report scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
grep -rl 'skill-name' ~/.claude/projects --include="*.jsonl" | wc -l How it starts
The opening of the file, as written. The whole thing — 80 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill Usage Report
Runs and interprets cc-skill-usage (this repo's own CLI) to answer
questions about Skill usage. Read README.md and EXAMPLES.md in this repo
first if either is unfamiliar, they hold the full flag reference and the
scenario-to-command mapping this skill draws from.
Picking the right command
Match the question to the scenario in EXAMPLES.md rather than improvising
flags: a monthly recap is --since 30d --show-context, a single skill's
health check is <skill-name> --show-context, a repo-versus-everything-else
comparison needs two --json runs diffed by skill name, and so on. Default
to --show-context whenever the user's question includes "why", "when", or
"in what context": counts alone rarely answer that.
The one non-negotiable step: verify before reporting a surprising number
If a count is unexpectedly low, unexpectedly high, or contradicts the user's own memory of how much they used something, do not report it as-is. Cross- check it independently before presenting a verdict:
# raw mentions (expect this far higher, it includes prose, files, summaries)
grep -rl 'skill-name' ~/.claude/projects --include="*.jsonl" | wc -l
# real invocations, independent of cc-skill-usage's own parsing code
grep -rh '"name":"Skill"' ~/.claude/projects --include="*.jsonl" \
| jq -r '.message.content[]? | select(.type=="tool_use" and .name=="Skill") | .input.skill' \
| grep -c '^skill-name$'
If the independent pipeline matches cc-skill-usage's own count, the tool is
right and the surprise is the invocation-vs-mention gap (measured at 212x on
real data during this tool's own development, see README.md), not a bug.
State that plainly, with both numbers, rather than either blindly trusting
or blindly doubting the first result.
Known blind spots to disclose, not paper over
State these when relevant instead of letting a report imply more precision than the data supports:
- Typed slash-command invocations may be under-represented versus
natural-language-triggered ones; the invocation signature this tool
matches is a
Skilltool call, and that path is well verified, but a purely-typed/skill-namepath has fewer confirmed clean examples. --show-contextoccasionally reports "(no preceding user message found)" when the real preceding message was a large tool result, skipped by design to avoid an OOM failure mode. That gap affects the context line only, never the invocation count itself.- Scanning a live session's own transcript while investigating a skill can make raw text-mention counts (never real invocation counts) pick up an echo of your own prior grep output.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 80 lines · 49 tokens per session scan B 02e2814aacc4
skill-usage-report is a skill published in the GitHub repository FlorianBruniaux/cc-skill-usage (5 stars, last pushed 3d ago), licensed MIT. It adds 49 tokens to every session and 871 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…