Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fuyuxiang/echo-agent/web-searchnpx skills add fuyuxiang/echo-agent --skill web-searchgit clone --depth 1 https://github.com/fuyuxiang/echo-agentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fuyuxiang/echo-agent/web-search)<a href="https://agentmods.dev/skills/fuyuxiang/echo-agent/web-search"><img src="https://agentmods.dev/badge/skills/fuyuxiang/echo-agent/web-search.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00032 | $0.00575 |
| Opus 5 | $0.00016 | $0.00287 |
| Sonnet 5 | $0.00006 | $0.00115 |
| Haiku 4.5 | $0.00003 | $0.00057 |
Grade C, and why
web-search scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
curl -s "http://localhost:8080/search?q=QUERY&format=json&engines=google,bing,duckduckgo" | python3 -m json.tool Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -s "http://localhost:8080/search?q=QUERY&format=json&engines=google,bing,duckduckgo" | python3 -m json.tool What it actually says
Web Search
Free web search without API keys. Two options: DuckDuckGo (zero config) or SearXNG (self-hosted).
DuckDuckGo (Primary)
Python library (recommended)
pip install duckduckgo_search
from duckduckgo_search import DDGS
# Text search
results = DDGS().text("query here", max_results=5)
for r in results:
print(f"{r['title']}\n{r['href']}\n{r['body']}\n")
# News search
news = DDGS().news("AI agents", max_results=5)
# Image search
images = DDGS().images("cat meme", max_results=3)
CLI one-liner
python3 -c "
from duckduckgo_search import DDGS
for r in DDGS().text('$QUERY', max_results=5):
print(f\"{r['title']}\n {r['href']}\n {r['body'][:100]}\n\")
"
Helper script
python3 scripts/web_search.py "your query" --max 5
python3 scripts/web_search.py "AI news" --type news
python3 scripts/web_search.py "cat" --type images
SearXNG (Self-hosted alternative)
For privacy or heavy usage, deploy your own SearXNG instance:
# JSON API (no key needed for self-hosted)
curl -s "http://localhost:8080/search?q=QUERY&format=json&engines=google,bing,duckduckgo" | python3 -m json.tool
Docker deployment:
docker run -d -p 8080:8080 searxng/searxng
Rate Limits
| Service | Limit | Notes |
|---|---|---|
| DuckDuckGo | ~20-30 req/min | No official limit, be respectful |
| SearXNG | Unlimited (self-hosted) | Depends on upstream engines |
Tips
- Use specific queries with operators:
site:github.com Python agent - For recent results, add year:
"2026" AI agent framework - DuckDuckGo respects
regionparam:DDGS().text(query, region="cn-zh")
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 81 lines · 32 tokens per session scan C 7ee00a125ba3
web-search is a skill published in the GitHub repository fuyuxiang/echo-agent (988 stars, last pushed 4d ago), licensed MIT. It adds 32 tokens to every session and 575 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
pptx
从论文、大纲或结构化文本生成 PowerPoint (.pptx) 演示文稿。Use when 用户需要把一篇论文/文章/大纲做成幻灯片、slides、演示文稿、PPT、deck。Don't use when 只需纯文本总结、生成 Word/PDF、或修改已有 pptx 的单个像素级样式。.
ai-style
当任务是用中文撰写或改写面向读者的文案(产品发布稿、公众号文章、邮件、README 等), 或用户反馈文字「AI 味太重」「不像人写的」时,加载本 Skill。.
triage
你是当前任务的分诊协调者。先识别用户的全部目标、顺序依赖和验收条件,再按 “事实检索 → 计算/执行 → 写作”顺序逐步请求切换到需要的专业能力。不要替专业 能力完成它的工作,也不要在信息缺失时臆造结果。.
writing
将共享历史中的已验证事实和计算结果整理成符合受众、格式与长度约束的成稿。.
kungfu-agent-onboarding
Discover the exact Kungfu Project, WorkConsole, WorkRef, Skill catalog, and Core Work state admitted to this Amp process.
data_analysis
基于已确认数据执行可审计的数学计算和描述统计。.