Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/hashgraph-online/awesome-codex-plugins/gitnexusnpx skills add hashgraph-online/awesome-codex-plugins --skill gitnexusgit clone --depth 1 https://github.com/hashgraph-online/awesome-codex-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hashgraph-online/awesome-codex-plugins/gitnexus)<a href="https://agentmods.dev/skills/hashgraph-online/awesome-codex-plugins/gitnexus"><img src="https://agentmods.dev/badge/skills/hashgraph-online/awesome-codex-plugins/gitnexus.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00058 | $0.00781 |
| Opus 5 | $0.00029 | $0.00391 |
| Sonnet 5 | $0.00012 | $0.00156 |
| Haiku 4.5 | $0.00006 | $0.00078 |
Grade A, and why
gitnexus scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
GitNexus
用途
- 对存量仓库做更深代码图谱分析:符号上下游、调用链、执行流、跨仓影响面。
- 在改动前用
impact/detect_changes类证据确认 blast radius。 - 为
/team-plan、/team-execute、/team-review提供可追溯的 MCP/图谱证据。
触发信号
- brownfield 项目改动跨多个模块、服务或仓库。
- 需要回答“改这个 symbol/API 会影响谁”“这段流程从哪里进入、流向哪里”。
- 评审或发布前需要对 git diff 做影响面确认。
- Graphify 的轻量结构扫描不够,需要 MCP tool、资源或多仓上下文。
默认工作流
- 先跑
npm run gitnexus:doctor,确认 Node、npm/npx 与上游包元数据。 - 用户自行确认 GitNexus 上游许可证和项目使用场景是否匹配。
- 在目标项目根目录显式执行索引命令,并保留 TSP 的 AGENTS/CLAUDE 契约:
npx --yes gitnexus@latest analyze --skip-agents-md - 通过 MCP 或 CLI 查询
query/context/impact/detect_changes等结果。 - 把关键发现回落到主链:
- 规划阶段 ->
/team-plan的 Brownfield Context Snapshot 和 readiness 证据 - 执行阶段 ->
/team-execute的 story slice 影响面说明 - 评审阶段 ->
/team-review的风险、回归边界和放行建议
- 规划阶段 ->
输出约定
- GitNexus 索引由上游工具管理,通常写入目标仓库
.gitnexus/与用户级 registry。 - TSP 侧只沉淀结论,不沉淀上游数据库:
- 分析目标
- 查询入口(MCP tool/resource 或 CLI 命令)
- 核心发现
- 对
/team-*决策的影响 - 后续验证或回退建议
边界与禁用项
- 不把 GitNexus 当作 TSP 依赖或默认安装项。
- 不自动运行
gitnexus setup,避免改写用户全局 MCP/editor 配置。 - 不在 TSP 管理仓库里运行不带
--skip-agents-md的gitnexus analyze。 - 不复制 GitNexus 源码、hooks、skills 或生成产物到 TSP canonical source。
- 当前按上游 npm 元数据视为非商业许可证约束;商业使用前需要用户自行确认授权。
推荐组合
- 轻量 brownfield 结构扫描:
/team-help -> /update-codemaps -> graphify -> /team-plan - 深影响面分析:
/team-help -> /update-codemaps -> GitNexus impact/detect_changes -> /team-plan - 高风险评审:
/team-execute -> GitNexus detect_changes -> /handoff -> /team-review
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 61 lines · 58 tokens per session scan A 7597557d303d
gitnexus is a skill published in the GitHub repository hashgraph-online/awesome-codex-plugins (924 stars, last pushed today), licensed Apache-2.0. It adds 58 tokens to every session and 781 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
search
Search 2500+ curated ChatGPT and LLM open-source repositories. Use when the user asks to find tools, libraries, or repos related to ChatGPT, LLMs, RAG, agents, langchain, NLP, AI development, or any open-source AI tooling.
similar-resources
Given a Japanese NLP GitHub repo or Hugging Face model/dataset (URL / owner/repo / tool name), find repositories or models/datasets that do the same or related processing. Mines the bundled dataset for content-similar items, then expands via web research across both GitHub and Hugging Face, then merges and re-ranks.
sprr
Single PR reviewer for awesome-quant. Use when the user asks to review, validate, comment on, label, close, or merge one specific pull request that adds README.md entries. Triggers include "sprr", "review PR", "check PR", and "validate contribution".
bprr
Bulk PR reviewer for awesome-quant. Use when the user asks to review all open PRs, review unreviewed PRs, bulk review, or mentions "bprr". Reviews open PRs lacking the reviewed label and presents a summary before any merge/comment/label action.
reverse-engineering-android-malware-with-jadx
Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests…
implementing-code-signing-for-artifacts
This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools, establishing trust chains, and verifying signatures in deployment…