Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/igapyon/igapyon-agent-skills/code-examplenpx skills add igapyon/igapyon-agent-skills --skill code-examplegit clone --depth 1 https://github.com/igapyon/igapyon-agent-skillsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00027 | $0.00148 |
| Opus 5 | $0.00014 | $0.00074 |
| Sonnet 5 | $0.00005 | $0.00030 |
| Haiku 4.5 | $0.00003 | $0.00015 |
Grade A, and why
widget-api-helper scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -X POST https://api.example.invalid/v2/widgets \ What it actually says
widget-api-helper
Send a Widget API request with the required version and JSON shape.
curl -X POST https://api.example.invalid/v2/widgets \
-H 'Content-Type: application/json' \
-H 'X-Widget-Version: 2026-07-01' \
-d '{"widgetId":"wdg-2048","enabled":true}'
Never remove X-Widget-Version. Treat HTTP 409 as an existing-widget result,
not as a retryable failure. Return the HTTP status and response body.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 19 lines · 27 tokens per session scan A 0e3b4374d996
widget-api-helper is a skill published in the GitHub repository igapyon/igapyon-agent-skills (2 stars, last pushed 17d ago), licensed Apache-2.0. It adds 27 tokens to every session and 148 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
openwrite-novel
Use when user wants to write novels, manage outlines, characters, world-building, style, workflows, or chapter review. Triggers: 写章节, 生成大纲, 创建角色, 世界观, 风格, 伏笔, 小说.
novel-creator
Use when user wants to write chapters, generate drafts, or continue the story. Triggers include "写第", "生成章节", "续写", "草稿", "创作".
novel-manager
Use when user wants to manage project settings, create characters, update world-building, view outline, or check foreshadowing status. Triggers include "新建", "角色", "世界观", "大纲", "伏笔", "项目".
novel-reviewer
Use when user wants to check logic consistency, polish style, find plot holes, or review existing chapters. Triggers include "检查", "润色", "逻辑", "伏笔漏洞", "审查".
goethe-agent
Use when user wants to start or continue a long-session planning flow for a novel, gather and refine ideation, characters, setting, outline, or source packs, and hand off to Dante when the writing window is ready.
post-validation
Use when user wants to validate chapter quality, check for AI patterns, forbidden phrases, or writing issues. Triggers include "验证", "AI味", "禁止词", "质量检查", "没人味".