Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add JustVugg/tools-factory --skill npm-registrygit clone --depth 1 https://github.com/JustVugg/tools-factoryWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/justvugg/tools-factory/npm-registry)<a href="https://agentmods.dev/skills/justvugg/tools-factory/npm-registry"><img src="https://agentmods.dev/badge/skills/justvugg/tools-factory/npm-registry/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/justvugg/tools-factory/npm-registry"><img src="https://agentmods.dev/badge/skills/justvugg/tools-factory/npm-registry.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00038 | $0.00374 |
| Opus 5 | $0.00019 | $0.00187 |
| Sonnet 5 | $0.00008 | $0.00075 |
| Haiku 4.5 | $0.00004 | $0.00037 |
Grade A, and why
npm-registry scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
npm-registry
Generated by Gutenberg. Use this skill to call the npm-registry API through the local npm-registry CLI.
When to use
- The user asks for data exposed by npm-registry (-, express).
- An agent task needs structured JSON from https://registry.npmjs.org.
- You need to perform a write/destructive operation on npm-registry — always preview first, run with
--yesonly on explicit user confirmation.
How to invoke
The skill assumes the generated CLI is on PATH (or invoke via scripts/use-go.sh run ./cmd/npm-registry from the project directory).
npm-registry operations
npm-registry call getExpress --json
npm-registry sync --json
npm-registry search "<keyword>" --json
Authentication
No authentication required.
Operations index
getExpress(GET /express) — read — GET /expressgetSearch(GET /-/v1/search) — read — GET /-/v1/search
Output contract
- All commands accept
--jsonand emit machine-readable output. callreturns{ dryRun, operation, request, response }.dryRun: truemeans the call was not executed (write op without--yes).searchreturns cached records.syncpopulates the local SQLite cache.
Provenance
- Schema: gutenberg.blueprint.v1
- Generated by: gutenberg 0.3.0
- Source spec: /tmp/npm-registry.openapi.json
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 49 lines · 38 tokens per session scan A eec05826c86b
npm-registry is a skill published in the GitHub repository JustVugg/tools-factory (53 stars, last pushed 2mo ago), licensed MIT. It adds 38 tokens to every session and 374 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
vs-search-tuning-specify-policy-direction
Viking Search tuning for specified policy directions. Use this when the user provides specific queries, a type of query, or a business policy direction, and asks to boost, suppress, or fix a class of search results through request-parameter passthrough. You must only perform read-only baseline evaluation and…
vs-product-qa
Answer Viking AI Search product questions, CLI usage questions, API/auth questions, configuration questions, and troubleshooting questions by grounding every claim in either the installed vs CLI's own output or official Volcengine documentation. Never fabricate.
vs-search-tuning-partial-case
Use when the user provides 1-50 concrete bad-case search queries for one Viking Search app and wants local deterministic fixes. This skill only verifies request-level fine-operation interventions against a read-only baseline scene and delivers a console-ready configuration sheet, validated payloads, and a replay…
vs-user-onboarding
Guide a brand-new SearchCLI/vs user from first-time usage questions to sign-up, purchase of Viking AI Search, AK/SK setup, and a working authenticated CLI. Use when the user says they downloaded or installed SearchCLI/vs and asks how to use it, how to start, sign up, buy, or onboard.
vs-crawler
Crawl websites (news, blogs, papers, GitHub, product docs, RSS feeds) into a fixed-schema JSONL file, then create a dataset and a searchable application in Viking AI Search. Supports one-time crawl and scheduled recurring crawl with automatic incremental sync.
volcengine-documentation
Volcengine official documentation lookup helper. Supports both document search and full-content fetch across Volcengine products, developer tools, support content, best practices, pricing, deployment, troubleshooting, API, SDK, and policy pages.