Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add jiankang1991/nsfc-benzi-audit --skill nsfc-benzi-auditgit clone --depth 1 https://github.com/jiankang1991/nsfc-benzi-auditWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jiankang1991/nsfc-benzi-audit/nsfc-benzi-audit)<a href="https://agentmods.dev/skills/jiankang1991/nsfc-benzi-audit/nsfc-benzi-audit"><img src="https://agentmods.dev/badge/skills/jiankang1991/nsfc-benzi-audit/nsfc-benzi-audit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/jiankang1991/nsfc-benzi-audit/nsfc-benzi-audit"><img src="https://agentmods.dev/badge/skills/jiankang1991/nsfc-benzi-audit/nsfc-benzi-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Anti-Refusal · line 30 Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.Fix: Remove instructions that suppress warnings, disclaimers, or ethical commentary. Let the agent surface safety-relevant caveats to the user.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00197 | $0.02145 |
| Opus 5 | $0.00098 | $0.01073 |
| Sonnet 5 | $0.00039 | $0.00429 |
| Haiku 4.5 | $0.00020 | $0.00215 |
Grade A, and why
nsfc-benzi-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.
NSFC Benzi Audit
Use this skill to produce applicant-facing diagnosis and revision advice for NSFC application drafts. The goal is to expose logic breaks, weak scientific-question framing, mismatched sections, and high-impact fixes before submission.
Do not write a formal peer-review opinion unless the user explicitly asks for communication review; route that to nsfc-review. Do not fabricate facts, papers, project histories, budgets, or official rule details. Keep final advice grounded in the draft text and clearly mark uncertain extraction/OCR issues.
Workflow
-
Locate and extract the draft.
- For PDF input, use PDF extraction/OCR as needed. Prefer existing extracted Markdown such as
full.mdoroutput.mdwhen available. - For DOCX input, extract text while preserving headings and tables where possible.
- For extracted Markdown/text folders, prefer
output.md,full.md, or the largest readable Markdown/text file; inspect images only when visual logic diagrams or tables matter. - If the file is scanned or extraction is noisy, state the limitation in the report and avoid treating OCR artifacts as applicant mistakes.
- If a prior
本子诊断报告.md(or an earlier revision list from this skill) sits next to the draft, read it before diagnosing and treat this run as a re-audit: grade each earlier 必改 item as 已改 / 未改 / 改动无效 against the current text, citing where in the new draft the change landed. Then diagnose the new draft normally. Do not re-derive the earlier findings from scratch, and do not silently drop an earlier 必改 item that is still unaddressed.
- For PDF input, use PDF extraction/OCR as needed. Prefer existing extracted Markdown such as
-
Identify the review scope before judging.
- Extract project category, research attribute, application code, title, abstract, keywords, applicant/team context, and section boundaries.
- If the user asks for a quick pass, inspect title, abstract, scientific questions, research contents, innovations, and research basis first.
- If the user asks for full diagnosis, inspect the whole application by section.
What ships with it
12 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- agents/openai.yaml 273 B
- assets/report-template.md 7.1 KB
- references/audit-surfaces.md 19 KB
- references/benzi-logic.md 38 KB
- references/current-rules.md 5.8 KB
- references/exemplar-learning.md 7.6 KB
- references/geospatial-remote-sensing.md 13 KB
- references/information-communication.md 9.1 KB
- references/kd-lookup.md 14 KB
- references/medical-biomedical.md 14 KB
- references/question-distillation.md 16 KB
- references/representative-works.md 6.3 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago Changed 60fdca811c36
- 13d ago First seen · 77 lines · 197 tokens per session scan A 7ac56e9662b8
nsfc-benzi-audit is a skill published in the GitHub repository jiankang1991/nsfc-benzi-audit (83 stars, last pushed 12d ago), licensed MIT. It adds 197 tokens to every session and 2,145 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
edgeone skill scanner
A local static scanner that checks agent-skill files for security risks before they are installed or used. Static analysis examines files without running them.
autoreview
Pre-commit/ship code review: Codex default; optional Claude or Pi.
convex-billing
Add Stripe billing/payments to the Convex app via @convex-dev/stripe (checkout + webhook + gating).
patent-map
A tool for making a visual map of stored patent case notes in an Obsidian vault. Obsidian is a note-taking application that stores linked text files.
sandbase
Access 2,000+ AI models and API tools through one MCP interface for inference, media generation, search, scraping, embeddings, social data, and structured retrieval. Use sandbasediscover before building custom integrations or declaring external data inaccessible; prefer an existing dedicated tool or API key when the…
dev-workflow
The complete development workflow for SkillHub contributors including local dev, staging validation, testing, and PR creation. Ensures agents follow the correct sequence of steps.