Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/huskar20/huskar20-plugins/applynpx skills add huskar20/huskar20-plugins --skill applygit clone --depth 1 https://github.com/huskar20/huskar20-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/huskar20/huskar20-plugins/apply)<a href="https://agentmods.dev/skills/huskar20/huskar20-plugins/apply"><img src="https://agentmods.dev/badge/skills/huskar20/huskar20-plugins/apply.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00131 | $0.03274 |
| Opus 5 | $0.00066 | $0.01637 |
| Sonnet 5 | $0.00026 | $0.00655 |
| Haiku 4.5 | $0.00013 | $0.00327 |
Grade A, and why
apply scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 262 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Career Hunter — Apply
Hunt for matching roles and submit applications in the user's name, end to end, within the guardrails below. When a form demands something outside the profile, the answer is always skip-and-flag — a skipped application costs a day; a wrong or invented answer costs the job.
Load configuration first
Read from the working folder; if any is missing, stop and route the user to
career-hunter: setup:
career-profile.md— single source of truth for every answer. Re-read every run; the owner edits it by hand.career-hunter-state/config.json— spreadsheet ID, resume path,resume_uploadable(whetherfile_uploadcan actually reach the resume — set by setup), daily cap, per-company cap, allowed days, SSO permission, and submission_mode, one of:auto— fill and submit without per-form confirmationreview— fill everything, then stop and let the user review and submitprepare— never open a form at all; find, score, and write ready-to-paste answers to a queue file for the user to work through by hand. By far the cheapest mode; see step 5b.
career-hunter-state/seen_jobs.json— dedupe memory. Schema:
{
"last_run_utc": "...",
"jobs": {
"<normalized company|title>": {
"disposition": "applied | skipped | flagged | failed | queued-blocked-domain",
"date": "YYYY-MM-DD",
"reason": "short note"
}
}
}
If today is not one of apply_days and this is a scheduled run, note that and
stop (a manual "run the job hunt" always proceeds).
Guardrails (non-negotiable)
- Answers come only from
career-profile.mdand the resume. Never invent, round up, or embellish experience, certifications, degrees, or eligibility. Free-text answers ("why this company") are built strictly from resume facts + the JD. - Honor the profile's "Never answer / always skip-and-flag" list (SSN/DOB/IDs, references, assessments, unusual legal attestations). Abandon the form without submitting and list the role in the summary with the reason.
- Work-auth/citizenship/clearance questions: answer exactly as the profile states. If a role hard-requires something the profile says the user lacks (citizenship, active clearance), skip it entirely.
- Logins: prefer no-account flows. If a login wall appears and config says
google_sso_allowed, use Continue with Google — never type or store a password. Password-only signup, captcha, or 2FA → skip and flag. Never attempt to solve or bypass a captcha. - Stop-and-verify before submit: on each review page, check
name/email/phone/resume-attached/screening answers. In
reviewmode, stop here and hand off to the user. Verify by text (see Cost discipline); take one screenshot before submitting inautomode — that is the audit record for an action taken in the user's name. - No assessments, no interviews: never start a coding test, recorded video, or scheduling flow. Flag them.
- Hidden-requirement check: application forms sometimes reveal requirements the listing hid (mandatory onsite days in another city, citizenship, unusual consents). If a form contradicts the profile's location/level/auth filters, do NOT submit — flag with what you found.
- Anything ambiguous about whether the user would want the job at all (weird comp structure, heavy on-call, relocation-coded "hybrid") → don't apply; flag.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 262 lines · 131 tokens per session scan A 348e72f3168f
apply is a skill published in the GitHub repository huskar20/huskar20-plugins (3 stars, last pushed 21d ago), licensed MIT. It adds 131 tokens to every session and 3,274 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
orbit-notion
Open Orbit briefing skill — selected by the Orbit pipeline when Notion is the user's only connected connector, or when the user explicitly scopes their daily digest to Notion. Pulls the past 24 hours of document edits, comments, mentions, and database row changes from the user's authenticated Notion connection and…
pinchtab-mcp
Use this skill when a task requires browser automation through PinchTab's MCP server connected to a remote browser instance. Covers navigation, element interaction, data extraction, form filling, multi-step flows, and session management via MCP tools.
feishu
Work with Feishu or Lark bots, docs, sheets, bitables, approval flows, and OpenAPI/MCP setup without hardcoding credentials.
Cortex
Operate Cortex, the LifeOS memory system — the typed Knowledge Archive (People, Companies, Ideas, Research with typed related: links) plus recall of prior work sessions, ISAs, and conversations. Search, add, harvest, develop, ingest, distill, graph-navigate, recall. USE WHEN cortex, knowledge, knowledge base, search…
peekaboo
Capture and automate macOS UI with the Peekaboo CLI.
mochi-remind
Handle due reminders — notify the user with natural language and mark them done.