Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add guanyang/open-agent-hub --skill baoyu-imaginegit clone --depth 1 https://github.com/guanyang/open-agent-hubWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/guanyang/open-agent-hub/baoyu-imagine)<a href="https://agentmods.dev/skills/guanyang/open-agent-hub/baoyu-imagine"><img src="https://agentmods.dev/badge/skills/guanyang/open-agent-hub/baoyu-imagine/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/guanyang/open-agent-hub/baoyu-imagine"><img src="https://agentmods.dev/badge/skills/guanyang/open-agent-hub/baoyu-imagine.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 2 findings, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Excessive Agency · line 82 Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.Fix: Remove the model/provider override or disclose it prominently and require explicit operator approval before invoking an external coding CLI or billed model.
- medium MCP Rug Pull · line 30 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00103 | $0.04700 |
| Opus 5 | $0.00051 | $0.02350 |
| Sonnet 5 | $0.00021 | $0.00940 |
| Haiku 4.5 | $0.00010 | $0.00470 |
Grade A, and why
baoyu-imagine scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 276 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Image Generation (AI SDK)
Official API-based image generation. Supports OpenAI GPT Image 2, Azure OpenAI, Google, OpenRouter, DashScope (阿里通义万象), Z.AI GLM-Image, MiniMax, Jimeng (即梦), Seedream (豆包) and Replicate.
User Input Tools
When this skill prompts the user, follow this tool-selection rule (priority order):
- Prefer built-in user-input tools exposed by the current agent runtime — e.g.,
AskUserQuestion,request_user_input,clarify,ask_user, or any equivalent. - Fallback: if no such tool exists, emit a numbered plain-text message and ask the user to reply with the chosen number/answer for each question.
- Batching: if the tool supports multiple questions per call, combine all applicable questions into a single call; if only single-question, ask them one at a time in priority order.
Concrete AskUserQuestion references below are examples — substitute the local equivalent in other runtimes.
Script Directory
{baseDir} = this SKILL.md's directory. Main script: {baseDir}/scripts/main.ts. Resolve ${BUN_X}: prefer bun; else npx -y bun; else suggest brew install oven-sh/bun/bun.
Step 0: Load Preferences ⛔ BLOCKING
This step MUST complete before any image generation — generation is blocked until EXTEND.md exists.
Check these paths in order; first hit wins:
| Path | Scope |
|---|---|
.baoyu-skills/baoyu-imagine/EXTEND.md |
Project |
${XDG_CONFIG_HOME:-$HOME/.config}/baoyu-skills/baoyu-imagine/EXTEND.md |
XDG |
$HOME/.baoyu-skills/baoyu-imagine/EXTEND.md |
User home |
- Found → load, parse, apply. If
default_model.[provider]is null → ask model only. - Not found → run first-time setup (
references/config/first-time-setup.md) using AskUserQuestion to collect provider + model + quality + save location. Save EXTEND.md, then continue. Do not generate images before this completes.
Legacy compatibility: if .baoyu-skills/baoyu-image-gen/EXTEND.md exists and the new path doesn't, the runtime renames it to baoyu-imagine. If both exist, the runtime leaves them alone and uses the new path.
What ships with it
35 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/codex-image2-fallback.md 1.8 KB
- references/codex-oauth-vs-openai-api-key.md 1.9 KB
- references/config/first-time-setup.md 13 KB
- references/config/preferences-schema.md 4.1 KB
- references/providers/dashscope.md 4.5 KB
- references/providers/minimax.md 1.2 KB
- references/providers/openrouter.md 776 B
- references/providers/replicate.md 1.8 KB
- references/providers/zai.md 1.1 KB
- references/usage-examples.md 4.6 KB
- scripts/build-batch.test.ts 4.5 KB runs code
- scripts/build-batch.ts 7.3 KB runs code
- scripts/main.test.ts 17 KB runs code
- scripts/main.ts 42 KB runs code
- scripts/providers/azure.test.ts 5.3 KB runs code
- scripts/providers/azure.ts 5.7 KB runs code
- scripts/providers/dashscope.test.ts 11 KB runs code
- scripts/providers/dashscope.ts 18 KB runs code
- scripts/providers/google.test.ts 3.3 KB runs code
- scripts/providers/google.ts 9.6 KB runs code
- scripts/providers/jimeng.test.ts 2.7 KB runs code
- scripts/providers/jimeng.ts 13 KB runs code
- scripts/providers/minimax.test.ts 5.1 KB runs code
- scripts/providers/minimax.ts 6.2 KB runs code
- scripts/providers/openai.test.ts 5.4 KB runs code
- scripts/providers/openai.ts 12 KB runs code
- scripts/providers/openrouter.test.ts 5.3 KB runs code
- scripts/providers/openrouter.ts 9.7 KB runs code
- scripts/providers/replicate.test.ts 7.0 KB runs code
- scripts/providers/replicate.ts 17 KB runs code
- scripts/providers/seedream.test.ts 6.4 KB runs code
- scripts/providers/seedream.ts 9.6 KB runs code
- scripts/providers/zai.test.ts 5.2 KB runs code
- scripts/providers/zai.ts 8.7 KB runs code
- scripts/types.ts 2.1 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 276 lines · 103 tokens per session scan A 335cef672ab1
baoyu-imagine is a skill published in the GitHub repository guanyang/open-agent-hub (967 stars, last pushed yesterday), licensed MIT. It adds 103 tokens to every session and 4,700 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
llm-evaluation-design
Use this skill when you need to design LLM evaluation datasets, judges, metrics, and human-review boundaries; triggers include llm evaluation design.
llm-testing
Use this skill when you need to test LLM behavior, failure modes, and evidence-based quality boundaries; triggers include llm testing.
prompt-testing
Use this skill when you need to test prompt behavior, regression risk, and output boundaries across versions; triggers include prompt testing.
polymorph
This spell is about representation change, not: Naming changes (same structure, different identifiers) Execution changes (same code, different runtime) Architecture changes (new system design) Duplication (same thing, different place) The key test: Can you point to a source artifact and a target artifact where the…
locate-object
In D&D, Locate Object senses the direction to a specific object within range. The real-world version is artifact search: finding that config file you know exists somewhere, locating a document someone mentioned but did not link, tracking down the source of a data value through a pipeline, or finding where a specific…
magic-prompt-generator
Expert prompt engineering assistant that crafts world-class, production-ready prompts for any AI chatbot. Use when the user needs to create, improve, or refine a prompt for ChatGPT, Claude, Gemini, or any LLM. Triggers on: 'create a prompt', 'write a prompt', 'generate a prompt', 'help me prompt', 'prompt…