Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add huaweicloud/huaweicloud-devkit --skill huawei-modelartsgit clone --depth 1 https://github.com/huaweicloud/huaweicloud-devkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/huaweicloud/huaweicloud-devkit/huawei-modelarts)<a href="https://agentmods.dev/skills/huaweicloud/huaweicloud-devkit/huawei-modelarts"><img src="https://agentmods.dev/badge/skills/huaweicloud/huaweicloud-devkit/huawei-modelarts/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/huaweicloud/huaweicloud-devkit/huawei-modelarts"><img src="https://agentmods.dev/badge/skills/huaweicloud/huaweicloud-devkit/huawei-modelarts.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 2 findings, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Prompt Injection · line 19 Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.Fix: Remove the large whitespace padding (blank-line blocks or long space runs) and review any content hidden below or to the right of it. Keep skill files compact and reviewable so no instructions can be
- medium MCP Rug Pull · line 72 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00073 | $0.00742 |
| Opus 5 | $0.00036 | $0.00371 |
| Sonnet 5 | $0.00015 | $0.00148 |
| Haiku 4.5 | $0.00007 | $0.00074 |
Grade A, and why
huawei-modelarts scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Huawei Cloud ModelArts
STOP - Do not answer from general knowledge. Follow the procedure below.
Always run hcloud ModelArts <Operation> --help before constructing commands to discover exact parameter names and requirements.
Overview
Domain expertise for ModelArts. Covers training jobs, model deployment, notebook instances, and OBS integration.
Critical Warnings
| Trap | Why |
|---|---|
| OBS bucket required | All training data, model outputs, and notebook storage use OBS. Create bucket first |
| Training charges by duration | Pay-per-minute GPU/CPU billing. Stop unused notebooks and services |
| Notebook auto-stop needed | Default no auto-stop — can run indefinitely and incur charges |
| Model deployment needs quota | Online services may require service quota approval in new accounts |
| Training job output must be OBS | Local output not supported. Ensure --output_path is a valid OBS path |
Prerequisites
- Training data must be stored in an OBS bucket (see
huawei-obs) - Output path for trained models must be an OBS path
- Notebook instances need a VPC/subnet (see
huawei-vpc)
Common Workflows
| Task | Operation |
|---|---|
| List models | ListModels --cli-region=<r> --project_id=<p> |
| List training jobs | ListTrainJobs --cli-region=<r> --project_id=<p> |
| List services | ListServices --cli-region=<r> --project_id=<p> |
| List notebooks | ListNotebooks --cli-region=<r> --project_id=<p> |
| Create model | CreateModel --cli-region=<r> --project_id=<p> |
| Create notebook | CreateNotebook --cli-region=<r> --project_id=<p> |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago Changed · +8 lines 4cb405a4ba94
- 12d ago First seen · 66 lines · 73 tokens per session scan A 5bdc6f4d8458
huawei-modelarts is a skill published in the GitHub repository huaweicloud/huaweicloud-devkit (47 stars, last pushed today), licensed Apache-2.0. It adds 73 tokens to every session and 742 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
azure-storage-file-datalake-py
Azure Data Lake Storage Gen2 SDK for Python. Use for hierarchical file systems, big data analytics, and file/directory operations. Triggers: "data lake", "DataLakeServiceClient", "FileSystemClient", "ADLS Gen2", "hierarchical namespace".
prompt
Prompt engineering conventions for x-cmd — reuse via template variables, structure rules, safety enforcement patterns.
x-cpu
Display CPU information and detect system endianness. Shows model, cores, frequency, vendor, cache size. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
airunway-aks-setup
Set up AI Runway on AKS — from bare cluster to running model. Covers cluster verification, controller install, GPU assessment, provider setup, and first deployment. WHEN: "setup AI Runway", "onboard AKS cluster", "install AI Runway", "airunway setup", "deploy model to AKS", "GPU inference on AKS", "KAITO setup on…
x-ohmyposh
Oh-My-Posh prompt theme engine with theme management. Cross-platform tool to render your prompt with consistent experience. Auto-downloads oh-my-posh binary if not available. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
thegraph-mcp-skill
Use The Graph Subgraph MCP through UXC via native SSE with a fixed linked command for subgraph discovery, schema retrieval, deployment selection, and GraphQL query execution with help-first inspection and explicit auth handling.