Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/huifer/skill-security-scan/log-analyzernpx skills add huifer/skill-security-scan --skill log-analyzergit clone --depth 1 https://github.com/huifer/skill-security-scanWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/huifer/skill-security-scan/log-analyzer)<a href="https://agentmods.dev/skills/huifer/skill-security-scan/log-analyzer"><img src="https://agentmods.dev/badge/skills/huifer/skill-security-scan/log-analyzer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00018 | $0.00585 |
| Opus 5 | $0.00009 | $0.00293 |
| Sonnet 5 | $0.00004 | $0.00117 |
| Haiku 4.5 | $0.00002 | $0.00059 |
Grade A, and why
Log Analyzer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Log Analyzer - 日志分析工具
功能描述
这是一个安全可靠的日志分析 Skill,用于帮助开发者快速分析和理解应用日志文件。
主要功能
- 错误识别 - 自动识别日志中的错误和异常
- 性能分析 - 检测慢查询和性能瓶颈
- 统计报告 - 生成错误统计和趋势分析
- 模式匹配 - 根据自定义规则搜索日志模式
使用场景
- 分析应用错误日志
- 监控系统性能指标
- 调试生产环境问题
- 审计安全事件
使用方法
当用户要求分析日志时:
1. 识别日志文件
查找并读取以下位置的日志文件:
./logs/*.log./var/log/*.log- 用户指定的日志文件路径
2. 分析日志内容
# 读取日志文件内容
# 使用正则表达式匹配错误模式:
# - ERROR, WARN, CRITICAL
# - Exception, Traceback
# - HTTP 错误码(4xx, 5xx)
3. 生成分析报告
- 错误总数统计
- 错误类型分布
- 时间范围分析
- Top 错误排行
4. 输出结果
以清晰的 Markdown 格式输出分析结果,包括:
- 执行摘要
- 详细错误列表
- 改进建议
安全说明
- ✅ 只读取日志文件,不修改任何文件
- ✅ 不执行任何系统命令
- ✅ 不访问网络资源
- ✅ 不读取敏感配置文件
依赖项
- Python 3.9+
- 标准库:re, datetime, collections
示例用法
用户:分析当前目录的 application.log
工具:[分析日志内容]
输出:✅ 发现 23 个错误,主要是数据库连接超时
限制
- 仅支持文本格式日志
- 最大支持 100MB 的日志文件
- 不处理二进制日志
最佳实践
- 定期清理旧日志文件
- 使用结构化日志格式(JSON)
- 在生产环境启用日志轮转
- 保护敏感日志文件权限
版本历史
- v1.0.0 (2024-12-29) - 初始版本
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 89 lines · 18 tokens per session scan A 5d7e66bcc472
Log Analyzer is a skill published in the GitHub repository huifer/skill-security-scan (169 stars, last pushed 8mo ago), licensed MIT. It adds 18 tokens to every session and 585 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
claude-md-improver
Audit and improve CLAUDE.md files in repositories. Use when user asks to check, audit, update, improve, or fix CLAUDE.md files. Scans for all CLAUDE.md files, evaluates quality against templates, outputs quality report, then makes targeted updates. Also use when the user mentions "CLAUDE.md maintenance" or "project…
agent-platform-rag-engine-management
Manage and query Agent Platform RAG Engine Corpora and retrieve grounded contexts using the Google GenAI SDK. Use when listing RAG corpora or files, inspecting a corpus, retrieving contexts, or generating content grounded in a RAG corpus. Do not use for standard database queries (use SQL/Spanner skills), Google…
agent-platform-model-registry
Agent Platform Model Registry Management. Use when you need to upload, list, describe, update, or delete machine learning models (and their versions) in the Agent Platform Model Registry. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform models.
twitter-reader
Read Twitter/X for financial research using opencli (read-only). Use this skill whenever the user wants to read their Twitter feed, search for financial tweets, view bookmarks, look up user profiles, or gather market sentiment from Twitter/X. Triggers include: "check my feed", "search Twitter for", "show my…
chenhao-limit-up
Use when evaluating A-share limit-up (涨停板) setups through Chen Hao's sentiment and momentum lens: market emotion cycles, board strength, follow-through, and short-term aggressive momentum trading.
comet-github
将 Comet GitHub 维护请求路由到基于证据的 PR 审阅、Issue 分诊、本地想法收集、CI 诊断或 Issue 实施流程。用户提到 Comet GitHub Issue/PR 但未指定流程,或询问下一步如何处理时使用。.