Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/joinwell52-ai/codeflowmu-open/windows-usenpx skills add joinwell52-AI/CodeFlowMu-open --skill windows-usegit clone --depth 1 https://github.com/joinwell52-AI/CodeFlowMu-openWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/joinwell52-ai/codeflowmu-open/windows-use)<a href="https://agentmods.dev/skills/joinwell52-ai/codeflowmu-open/windows-use"><img src="https://agentmods.dev/badge/skills/joinwell52-ai/codeflowmu-open/windows-use.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00060 | $0.00896 |
| Opus 5 | $0.00030 | $0.00448 |
| Sonnet 5 | $0.00012 | $0.00179 |
| Haiku 4.5 | $0.00006 | $0.00090 |
Grade A, and why
windows-use scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 49 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Windows Use
Control only applications the user approved in CodeFlowMu Panel. Treat application approval as permission to access that app, not blanket permission for risky side effects.
Workflow
- Call
windows.capabilitieswhen host readiness is unknown. - Call
windows.list_targetsbefore handling login. FollowloginMethod,verificationChannel,loginInstruction, andrequiresUser; never infer an authentication flow. A saved password is reported only as a boolean and is never returned. - For
qr_codeor verification-code methods, stop at the login step and wait for the user. If the method isunspecified, ask the user instead of guessing. - To open an approved target, first reuse any window returned by discovery. Call
windows.launch_targetonly when the target is not already running. Native launch is idempotent and may returnalready_running=true; never relaunch a minimized, hidden, or initializing application. Web launch only opens the URL—route all page DOM work to a browser-specific capability. - For a native target, call
windows.wait_for_appinstead of using Shell sleep, then select the returnedapp_idandwindow_id. Never invent or reuse a stale window identifier. - Call
windows.inspect_uiwhen labels or standard controls can identify the target. Preferwindows.invoke_ui: UI Automation InvokePattern works without taking foreground focus. - Only when an operation truly needs foreground input, call
windows.activate. Never use PowerShell, Alt+Tab, or a terminal to force focus. If activation is blocked,windows.clickcan deliver a bounded window-message fallback, while text/keyboard input must pause for one user click. - Use
windows.screenshotand window-relative coordinates only when UI Automation is insufficient. - Batch a small set of related actions, then inspect again to verify the result. Stop after an error or if the user takes over the foreground window.
- Call
windows.cancelwhen the user asks to stop. Claim “paused” only after it returnspaused=true. This is an MCP-session pause, not project-level disablement. Callwindows.statusto verify; callwindows.resumeonly after explicit user instruction.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 49 lines · 60 tokens per session scan A b6dc16ad587e
windows-use is a skill published in the GitHub repository joinwell52-AI/CodeFlowMu-open (2 stars, last pushed 10d ago), licensed MIT. It adds 60 tokens to every session and 896 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
agentbro-release
Use when releasing AgentBro from this repository: merging dev/main, bumping versions, updating release notes, tagging, pushing, monitoring GitHub Actions, Homebrew cask publication, or fixing a bad release.
agentbro-pr-merge
Use when reviewing, fixing CI for, approving workflows for, or merging AgentBro pull requests into dev/main, especially external contributor PRs where contributor attribution matters.
source-command-check
跑全套本地校验(前端 lint/test/build + Rust check)。.
oculpm-journal
MCP 도구가 보이면 이 스킬 대신 도구를 쓴다 — journalwrite / planstatus / planupdate 가 경로·파일명·frontmatter 규격을 서버에서 보장한다. 아래는 도구가 없을 때 파일을 직접 쓰는 규격이다.
self-audit
작업을 "완료"라고 보고하기 직전, 스스로 결과를 감사할 때. 커밋/PR 직전 최종 점검에도 사용.
project-inception
Use when kicking off a new project or feature area in an ocul-pm tracked project (.oculpm/ present) — research the stack landscape via web search, then converse with the user (research-backed choices) to settle the optimal spec, and seed a discussion doc, a detailed 3-depth plan (plancreate), EVALS.md done-criteria…