Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add guanyang/open-agent-hub --skill baoyu-danger-gemini-webgit clone --depth 1 https://github.com/guanyang/open-agent-hubWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/guanyang/open-agent-hub/baoyu-danger-gemini-web)<a href="https://agentmods.dev/skills/guanyang/open-agent-hub/baoyu-danger-gemini-web"><img src="https://agentmods.dev/badge/skills/guanyang/open-agent-hub/baoyu-danger-gemini-web/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/guanyang/open-agent-hub/baoyu-danger-gemini-web"><img src="https://agentmods.dev/badge/skills/guanyang/open-agent-hub/baoyu-danger-gemini-web.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00074 | $0.01695 |
| Opus 5 | $0.00037 | $0.00847 |
| Sonnet 5 | $0.00015 | $0.00339 |
| Haiku 4.5 | $0.00007 | $0.00169 |
Grade A, and why
baoyu-danger-gemini-web scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to baoyu-danger-gemini-web — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 156 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Gemini Web Client
Text/image generation via Gemini Web API. Supports reference images and multi-turn conversations.
User Input Tools
When this skill prompts the user, follow this tool-selection rule (priority order):
- Prefer built-in user-input tools exposed by the current agent runtime — e.g.,
AskUserQuestion,request_user_input,clarify,ask_user, or any equivalent. - Fallback: if no such tool exists, emit a numbered plain-text message and ask the user to reply with the chosen number/answer for each question.
- Batching: if the tool supports multiple questions per call, combine all applicable questions into a single call; if only single-question, ask them one at a time in priority order.
Concrete AskUserQuestion references below are examples — substitute the local equivalent in other runtimes.
Script Directory
Important: All scripts are located in the scripts/ subdirectory of this skill.
Agent Execution Instructions:
- Determine this SKILL.md file's directory path as
{baseDir} - Script path =
{baseDir}/scripts/<script-name>.ts - Resolve
${BUN_X}runtime: ifbuninstalled →bun; ifnpxavailable →npx -y bun; else suggest installing bun - Replace all
{baseDir}and${BUN_X}in this document with actual values
Script Reference:
| Script | Purpose |
|---|---|
scripts/main.ts |
CLI entry point for text/image generation |
scripts/gemini-webapi/* |
TypeScript port of gemini_webapi (GeminiClient, types, utils) |
Consent Check (REQUIRED)
Before first use, verify user consent for reverse-engineered API usage.
Consent file locations:
- macOS:
~/Library/Application Support/baoyu-skills/gemini-web/consent.json - Linux:
~/.local/share/baoyu-skills/gemini-web/consent.json - Windows:
%APPDATA%\baoyu-skills\gemini-web\consent.json
Flow:
- Check if consent file exists with
accepted: trueanddisclaimerVersion: "1.0" - If valid consent exists → print warning with
acceptedAtdate, proceed - If no consent → show disclaimer, ask user via
AskUserQuestion:- "Yes, I accept" → create consent file with ISO timestamp, proceed
- "No, I decline" → output decline message, stop
- Consent file format:
{"version":1,"accepted":true,"acceptedAt":"<ISO>","disclaimerVersion":"1.0"}
What ships with it
27 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- scripts/bun.lock 389 B
- scripts/gemini-webapi/client.test.ts 1.0 KB runs code
- scripts/gemini-webapi/client.ts 23 KB runs code
- scripts/gemini-webapi/components/gem-mixin.ts 5.6 KB runs code
- scripts/gemini-webapi/components/index.ts 44 B runs code
- scripts/gemini-webapi/constants.ts 3.8 KB runs code
- scripts/gemini-webapi/exceptions.ts 1.2 KB runs code
- scripts/gemini-webapi/index.ts 273 B runs code
- scripts/gemini-webapi/types/candidate.ts 1.3 KB runs code
- scripts/gemini-webapi/types/gem.ts 1.8 KB runs code
- scripts/gemini-webapi/types/grpc.ts 369 B runs code
- scripts/gemini-webapi/types/image.ts 3.4 KB runs code
- scripts/gemini-webapi/types/index.ts 232 B runs code
- scripts/gemini-webapi/types/modeloutput.ts 816 B runs code
- scripts/gemini-webapi/utils/cookie-file.ts 2.3 KB runs code
- scripts/gemini-webapi/utils/decorators.ts 1.1 KB runs code
- scripts/gemini-webapi/utils/get-access-token.ts 7.4 KB runs code
- scripts/gemini-webapi/utils/http.ts 1.6 KB runs code
- scripts/gemini-webapi/utils/index.ts 1021 B runs code
- scripts/gemini-webapi/utils/load-browser-cookies.ts 9.6 KB runs code
- scripts/gemini-webapi/utils/logger.ts 1.2 KB runs code
- scripts/gemini-webapi/utils/parsing.ts 1.3 KB runs code
- scripts/gemini-webapi/utils/paths.ts 2.3 KB runs code
- scripts/gemini-webapi/utils/rotate-1psidts.ts 1.5 KB runs code
- scripts/gemini-webapi/utils/upload-file.ts 1.1 KB runs code
- scripts/main.ts 15 KB runs code
- scripts/package.json 145 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 156 lines · 74 tokens per session scan A 290c0f8b3957
baoyu-danger-gemini-web is a skill published in the GitHub repository guanyang/open-agent-hub (967 stars, last pushed yesterday), licensed MIT. It adds 74 tokens to every session and 1,695 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to baoyu-danger-gemini-web, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
llm-evaluation-design
Use this skill when you need to design LLM evaluation datasets, judges, metrics, and human-review boundaries; triggers include llm evaluation design.
llm-testing
Use this skill when you need to test LLM behavior, failure modes, and evidence-based quality boundaries; triggers include llm testing.
prompt-testing
Use this skill when you need to test prompt behavior, regression risk, and output boundaries across versions; triggers include prompt testing.
polymorph
This spell is about representation change, not: Naming changes (same structure, different identifiers) Execution changes (same code, different runtime) Architecture changes (new system design) Duplication (same thing, different place) The key test: Can you point to a source artifact and a target artifact where the…
locate-object
In D&D, Locate Object senses the direction to a specific object within range. The real-world version is artifact search: finding that config file you know exists somewhere, locating a document someone mentioned but did not link, tracking down the source of a data value through a pipeline, or finding where a specific…
magic-prompt-generator
Expert prompt engineering assistant that crafts world-class, production-ready prompts for any AI chatbot. Use when the user needs to create, improve, or refine a prompt for ChatGPT, Claude, Gemini, or any LLM. Triggers on: 'create a prompt', 'write a prompt', 'generate a prompt', 'help me prompt', 'prompt…