Borrowing it
Nothing to install: this file belongs to gaotiexinqu/OneResearchClaw. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/gaotiexinqu/OneResearchClaw/main/.cursor/skills/one-report/SKILL.mdgit clone --depth 1 https://github.com/gaotiexinqu/OneResearchClawWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/gaotiexinqu/oneresearchclaw/one-report)<a href="https://agentmods.dev/skills/gaotiexinqu/oneresearchclaw/one-report"><img src="https://agentmods.dev/badge/skills/gaotiexinqu/oneresearchclaw/one-report/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/gaotiexinqu/oneresearchclaw/one-report"><img src="https://agentmods.dev/badge/skills/gaotiexinqu/oneresearchclaw/one-report.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 3 findings, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Data Exfiltration · line 1422 Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.Fix: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted.
- medium Data Exfiltration · line 1462 Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.Fix: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted.
- medium Data Exfiltration · line 1609 Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.Fix: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00054 | $0.15039 |
| Opus 5 | $0.00027 | $0.07519 |
| Sonnet 5 | $0.00011 | $0.03008 |
| Haiku 4.5 | $0.00005 | $0.01504 |
Grade A, and why
one-report scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 1,626 lines — stays where its author put it; the contents beside it link to each section on GitHub.
One-Report
Use this skill as the single top-level entry skill for the full One-Report pipeline.
This skill is a thin orchestration layer. It does not replace existing input, grounding, research, summary, review, or export skills. It must reuse them.
The purpose of this skill is to let a user provide:
- one input file path
- a small set of research requirements
- requested export format(s)
and then complete the full pipeline:
input -> grounding -> research -> report drafting -> review quality gate -> output export
without requiring the user to manually run each stage.
What This Skill Does
This skill must:
- read the user-provided pipeline inputs
- route the input into the correct existing grounding workflow
- continue until grounding is actually completed
- identify the grounded unit(s) that should continue downstream
- for multi-topic grounding: use
Tasktool to create independent subagent branches for each topic child (see Subagent Rule below) - run research for each grounded unit
- run the main report-drafting stage for each grounded unit
- run the final review/refinement stage for each grounded unit
- run output export for each final reviewed report
- enforce strict downstream skill fidelity for every grounded unit, whether single-topic or multi-topic
- report the final output paths clearly
What This Skill Does Not Do
This skill must not:
- implement its own grounding logic
- implement its own literature search logic
- implement its own report-writing logic
- implement its own review logic
- implement its own export logic
- rewrite existing lower-level skill contracts
- skip
grounded-reviewand treat the draft report as the final deliverable - ask downstream stages to compress rich literature analysis into a shallow memo
- satisfy a downstream stage with a visibly abbreviated or weakened version of that stage's own skill contract
- let single-topic execution become lax just because no fan-out occurred
- attempt downstream work in the parent context when multi-topic grounding exists (must use subagent branches)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 1,626 lines · 54 tokens per session scan A f54cd6c2378c
one-report is a skill published in the GitHub repository gaotiexinqu/OneResearchClaw (446 stars, last pushed 4mo ago), licensed MIT. It adds 54 tokens to every session and 15,039 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
quantum-qiskit
Reference qiskit 2.x patterns for variational quantum machine learning. Covers data-encoding feature maps, variational quantum classifier (VQC) training, variational quantum eigensolver (VQE) for chemistry, matrix-product-state circuits, and noise model integration. Use when writing Python code that imports qiskit…
flux-analyzer
Analyse FBA flux distributions to extract biological insights. Covers gene essentiality, phenotypic phase planes, flux sampling, pathway-level aggregation, secretion product prediction, and production of publication- quality figures.
fba-simulator
Run Flux Balance Analysis (FBA) and related constraint-based simulations using COBRApy. Covers standard FBA, parsimonious FBA (pFBA), Flux Variability Analysis (FVA), loopless FBA, gene/reaction knockouts, and carbon source swapping. Outputs flux distributions and CSV files.
gsmm-validator
Validate a COBRApy genome-scale metabolic model for mass/charge balance, stoichiometric consistency, biomass producibility, dead-end metabolites, thermodynamic loops, and GPR rule formatting. Outputs a structured validation report with errors and warnings.
metabolic-study-planner
Plan publishable constraint-based metabolic modelling studies when the user has a broad biological or metabolic-engineering topic but no concrete dataset, organism, model, or hypothesis. Selects feasible BiGG/COBRA models, objectives, perturbations, analyses, metrics, figures, and risk controls before FBA code is…
gsmm-builder
Build or load a genome-scale metabolic model (GSMM) using COBRApy. Covers loading from BIGG, constructing minimal models from scratch, setting medium constraints, and exporting validated .json model files.