Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add jinyimeng01/net-code-audit-skill-master --skill dotnet-offsec-auditgit clone --depth 1 https://github.com/jinyimeng01/net-code-audit-skill-masterWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jinyimeng01/net-code-audit-skill-master/dotnet-offsec-audit)<a href="https://agentmods.dev/skills/jinyimeng01/net-code-audit-skill-master/dotnet-offsec-audit"><img src="https://agentmods.dev/badge/skills/jinyimeng01/net-code-audit-skill-master/dotnet-offsec-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00170 | $0.01654 |
| Opus 5 | $0.00085 | $0.00827 |
| Sonnet 5 | $0.00034 | $0.00331 |
| Haiku 4.5 | $0.00017 | $0.00165 |
Grade A, and why
dotnet-offsec-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
The source is not reproduced here
Licensed MulanPSL-2.0
The repository is licensed MulanPSL-2.0, which this catalogue does not treat as permission to reproduce the file. Read it at the source.
What ships with it
34 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- agents/openai.yaml 839 B
- references/RAW_REFERENCE_INDEX.md 1.8 KB
- references/raw/hack-skills/api-auth-and-jwt-abuse/SKILL.md 2.5 KB
- references/raw/hack-skills/cmdi-command-injection/SKILL.md 20 KB
- references/raw/hack-skills/cors-cross-origin-misconfiguration/SCENARIOS.md 5.2 KB
- references/raw/hack-skills/cors-cross-origin-misconfiguration/SKILL.md 9.7 KB
- references/raw/hack-skills/csrf-cross-site-request-forgery/SKILL.md 17 KB
- references/raw/hack-skills/deserialization-insecure/JAVA_GADGET_CHAINS.md 18 KB
- references/raw/hack-skills/deserialization-insecure/SKILL.md 24 KB
- references/raw/hack-skills/http-host-header-attacks/SKILL.md 12 KB
- references/raw/hack-skills/idor-broken-object-authorization/SKILL.md 11 KB
- references/raw/hack-skills/oauth-oidc-misconfiguration/SKILL.md 2.5 KB
- references/raw/hack-skills/open-redirect/SKILL.md 12 KB
- references/raw/hack-skills/path-traversal-lfi/SKILL.md 24 KB
- references/raw/hack-skills/request-smuggling/H2_SMUGGLING_VARIANTS.md 15 KB
- references/raw/hack-skills/request-smuggling/SKILL.md 15 KB
- references/raw/hack-skills/saml-sso-assertion-attacks/SKILL.md 2.2 KB
- references/raw/hack-skills/ssrf-server-side-request-forgery/SCENARIOS.md 7.6 KB
- references/raw/hack-skills/ssrf-server-side-request-forgery/SKILL.md 11 KB
- references/raw/hack-skills/ssrf-server-side-request-forgery/URL_PARSER_TRICKS.md 21 KB
- references/raw/hack-skills/upload-insecure-files/SCENARIOS.md 4.2 KB
- references/raw/hack-skills/upload-insecure-files/SKILL.md 18 KB
- references/raw/hack-skills/waf-bypass-techniques/SKILL.md 11 KB
- references/raw/hack-skills/waf-bypass-techniques/WAF_PRODUCT_MATRIX.md 10.0 KB
- references/raw/hack-skills/web-cache-deception/CACHE_POISONING_TECHNIQUES.md 18 KB
- references/raw/hack-skills/web-cache-deception/SKILL.md 6.8 KB
- references/raw/hack-skills/xss-cross-site-scripting/ADVANCED_XSS_TRICKS.md 9.0 KB
- references/raw/hack-skills/xss-cross-site-scripting/SCENARIOS.md 8.8 KB
- references/raw/hack-skills/xss-cross-site-scripting/SKILL.md 13 KB
- references/raw/hack-skills/xxe-xml-external-entity/SCENARIOS.md 3.2 KB
- references/raw/hack-skills/xxe-xml-external-entity/SKILL.md 16 KB
- references/REPORT_TEMPLATE.md 6.2 KB
- references/ROUTING_MATRIX.md 911 B
- scripts/collect_dotnet_surface.py 21 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 87 lines · 170 tokens per session scan A cb75cbd3cf86
dotnet-offsec-audit is a skill published in the GitHub repository jinyimeng01/net-code-audit-skill-master (5 stars, last pushed 4mo ago), licensed MulanPSL-2.0. It adds 170 tokens to every session and 1,654 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
smart-panel-dev
Master / orchestrator skill for Tuya Ray panel miniapp development. Use this as the SINGLE ENTRY POINT for any panel miniapp task — it covers the full lifecycle (architecture → requirement → coding conventions → upload audit) and dispatches to category- or topic-specific sub-skills (ray-common, smart-ui…
powerbi-orchestrator
MASTER SKILL — Single entry point for creating Power BI dashboards from CSV/Excel. Mandatory for any Power BI task, dashboard creation, PBIP generation, DAX modeling, or visual report editing. Automatically loads sub-skills and enforces 6 guardrails, 5 core styling principles, and script verification.
pinchtab-mcp
Use this skill when a task requires browser automation through PinchTab's MCP server connected to a remote browser instance. Covers navigation, element interaction, data extraction, form filling, multi-step flows, and session management via MCP tools.
pinchtab-stealth-score
Run the PinchTab stealth-score sweep against 15 bot-detection / fingerprint sites (sannysoft, rebrowser, deviceandbrowserinfo, iphey, whoer, browserscan, pixelscan, fingerprint-scan, incolumitas, fvision, amiunique, browserleaks, creepjs, coveryourtracks, fingerprint-demo). Starts a Docker PinchTab container per…
oma-scholar
Scholarly research companion using Knows sidecar spec (.knows.yaml). Generates, validates, reviews, queries, and compares structured research-paper sidecars, and fetches them from knows.academy. Use for academic literature search, survey synthesis, paper authoring assistance, and peer review with token-efficient…
oma-hwp
Convert HWP / HWPX / HWPML files to Markdown using kordoc. Extracts text, headings, tables, lists, images, footnotes, and hyperlinks. Use for Korean word processor files (Hangul), government documents, and AI-ready data preparation.