Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add hanmirage/deepdepcat --skill depwork-researchgit clone --depth 1 https://github.com/hanmirage/deepdepcatWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hanmirage/deepdepcat/depwork-research)<a href="https://agentmods.dev/skills/hanmirage/deepdepcat/depwork-research"><img src="https://agentmods.dev/badge/skills/hanmirage/deepdepcat/depwork-research/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hanmirage/deepdepcat/depwork-research"><img src="https://agentmods.dev/badge/skills/hanmirage/deepdepcat/depwork-research.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00059 | $0.00482 |
| Opus 5 | $0.00030 | $0.00241 |
| Sonnet 5 | $0.00012 | $0.00096 |
| Haiku 4.5 | $0.00006 | $0.00048 |
Grade A, and why
depwork-research scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Depwork 调研工作流
用于自媒体选题、行业调研、文献综述与事实核查。核心纪律:每条结论必须有来源,来源必须进资料夹,成稿必须带引用。
流程
- 明确需求:选题/问题、产出格式(短文/报告/文档)、引用风格(链接式即可,或 DOI)。
- 检索:
- 学术问题 →
research_search(Semantic Scholar + Crossref); - 行业/时效问题 →
web_search+web_fetch读原文。
- 学术问题 →
- 筛选与保存:只保留可核验的一手/权威来源;每确认一条就用
research_save存入资料夹(带 title/url/source/snippet/tags,快照可选)。 - 整理:
research_list回顾资料夹,按主题分组,找出支撑点与反例。 - 成稿:每个关键结论旁标注来源;不要写没有来源支撑的断言。
- 导出:
research_export生成带访问日期的引用列表,随稿交付。
规则
- 至少 2 个独立来源才能支撑一个事实性断言;
- 无法核验的信息明确标注「未证实」,不要编造来源;
- 保存时 snippet 写「这条资料支撑什么」,而不是复制标题;
- 成稿后做一次对抗检查:逐条结论问「来源是谁?权威吗?时间合适吗?」
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 30 lines · 59 tokens per session scan A 6b24799f0fcf
depwork-research is a skill published in the GitHub repository hanmirage/deepdepcat (10 stars, last pushed 21d ago), licensed Apache-2.0. It adds 59 tokens to every session and 482 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
eac-desktop-tips
A quick reference for using and troubleshooting features in the Deepseek Harness EAC desktop client. It covers window behavior, conversation rollback, plugins, desktop pets, Skills, MCP services, updates, and logs.
gog-workspace
Use the gog CLI for Google Workspace tasks across Gmail, Calendar, Drive, Docs, Sheets, Contacts, and related services. Use when the user asks to check email, search Gmail, inspect calendar events, find Drive files, read Docs or Sheets, or manage Google Workspace data through gog.
apple-calendar
Read macOS Calendar events via the icalBuddy CLI and create events via AppleScript (osascript). Use to check the user's calendar, agenda, upcoming events, or add an event on macOS.
apple-reminders
Manage Apple Reminders via the remindctl CLI on macOS — list, add, complete, delete, manage lists.
github
Drive GitHub via the official gh CLI — repos, issues, pull requests, releases, gists, Actions runs, and raw REST through gh api. Use when the user asks to inspect or manage GitHub.
docker
Manage Docker containers, images, volumes, and Compose stacks via the docker CLI — list, inspect, logs, run, build, stop, remove, compose up/down. Use for local container ops.