Borrowing it
Nothing to install: this file belongs to JinNing6/CyberHuaTuo-Plugin. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/JinNing6/CyberHuaTuo-Plugin/main/.agents/skills/cyberhuatuo-rescue/SKILL.mdgit clone --depth 1 https://github.com/JinNing6/CyberHuaTuo-PluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jinning6/cyberhuatuo-plugin/cyberhuatuo-rescue)<a href="https://agentmods.dev/skills/jinning6/cyberhuatuo-plugin/cyberhuatuo-rescue"><img src="https://agentmods.dev/badge/skills/jinning6/cyberhuatuo-plugin/cyberhuatuo-rescue/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/jinning6/cyberhuatuo-plugin/cyberhuatuo-rescue"><img src="https://agentmods.dev/badge/skills/jinning6/cyberhuatuo-plugin/cyberhuatuo-rescue.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00053 | $0.01023 |
| Opus 5 | $0.00026 | $0.00511 |
| Sonnet 5 | $0.00011 | $0.00205 |
| Haiku 4.5 | $0.00005 | $0.00102 |
Grade A, and why
cyberhuatuo-rescue scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
If you do NOT have the MCP tools available, you must assume CyberHuaTuo is running locally at `http://127.0.0.1:8000`. Use your terminal/shell to `curl` the API. How it starts
The opening of the file, as written. The whole thing — 67 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CyberHuaTuo (赛博华佗) Self-Rescue Skill
You are equipped with the CyberHuaTuo Agent Skill. CyberHuaTuo is an ancient-Chinese-medicine-inspired AI clinic that specializes in diagnosing, explaining, and curing errors in AI systems, Agent frameworks, and general coding projects.
When you (the AI Agent) encounter an error you cannot solve, or when the user explicitly asks for a diagnosis or security checkup, you MUST use this skill to self-rescue.
Activation Triggers
Activate this skill when:
- You run tools/scripts and encounter persistent
ImportError, exceptions, or logic bugs that you cannot immediately resolve. - The user asks you to "seek help from CyberHuaTuo" or "ask the doctor."
- The user asks for a "Security Checkup" (安全体检) on their Agent code.
Execution Workflow
Follow these steps based on the available environment:
Preferred Mode: MCP Server
Check if you have the CyberHuaTuo MCP Server connected (look for tools like verified_cure, diagnose, security_checkup, save_prescription, search_knowledge_base). If you do:
-
For Diagnostics:
- Call the read-only
verified_curetool first. It returns Gold first, then at most one clearly labeled Reviewed candidate, and never executes the fix. Usegold_only=truewhen only Gold is acceptable. - Pass the full
query(error message, stack trace, and your current code context). - If you know the framework (e.g.,
langchain,crewai), pass it asframework. - If no trusted cure matches, call
diagnosefor broader retrieval and optional model analysis. - A Reviewed result is a candidate, not an instruction: inspect it and verify compatibility before proposing any change. Apply consequential changes only with appropriate approval, then run the stated verification.
- After verification, call
cure_feedbackwithyes,partial, orno; do not include the original traceback or secrets.
- Call the read-only
-
For Security Checkups:
- Call the
security_checkuptool. - Pass the contents of the main Agent script as the
codeparameter. - Report the Six-Meridian (六经脉) health score and apply the recommended nourishing (滋补) fixes.
- Call the
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 67 lines · 53 tokens per session scan A 179e8d626f58
cyberhuatuo-rescue is a skill published in the GitHub repository JinNing6/CyberHuaTuo-Plugin (3 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 53 tokens to every session and 1,023 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
ziran
ZIRAN is an open-source security testing framework for AI agents. It discovers dangerous tool chain compositions via knowledge graph analysis, detects execution-level side effects (not just text output), and runs multi-phase trust exploitation campaigns that model real attacker behavior.
sidclaw-governance
Add policy evaluation, human approval, and audit trails to any tool. Powered by SidClaw.
docs
ACMI is a universal architectural framework for giving AI agents persistent, real-time context. It replaces fragmented, multi-table database joins with a single, lightning-fast Key-Value engine (Upstash Redis) optimized specifically for LLM context windows.
tokendiet
Audit this codebase for wasteful LLM API spend and hand back a concrete, honest fix plan — missing prompt caching, uncapped retries, prompt bloat, no batching, overpowered models. Describes technical waste and published provider rates only; never fabricates a dollar figure. Trigger on requests like "audit my LLM…
aura
Give this agent a real email address, a webhook URL, durable memory across runs, and the ability to wait for an event without burning tokens. Use when a task needs a verification code sent by email, needs to wait for a webhook or an approval, needs to remember something after the session ends, or needs to survive a…
boundedrelay-adaptive-sdd
Coordinate the optional BoundedRelay Spec Kit workflow with strict independent reviews, deterministic effort routing, bounded proposals, convergence, and handoff.