Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add kensaurus/cursor-kenji --skill audit-uxgit clone --depth 1 https://github.com/kensaurus/cursor-kenjiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/kensaurus/cursor-kenji/audit-ux)<a href="https://agentmods.dev/skills/kensaurus/cursor-kenji/audit-ux"><img src="https://agentmods.dev/badge/skills/kensaurus/cursor-kenji/audit-ux.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Anti-Refusal · line 239 Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.Fix: Remove instructions that suppress warnings, disclaimers, or ethical commentary. Let the agent surface safety-relevant caveats to the user.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00072 | $0.04391 |
| Opus 5 | $0.00036 | $0.02195 |
| Sonnet 5 | $0.00014 | $0.00878 |
| Haiku 4.5 | $0.00007 | $0.00439 |
Grade A, and why
audit-ux scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 429 lines — stays where its author put it; the contents beside it link to each section on GitHub.
UX Audit Skill
Degree of freedom: MIXED — Steps 0, 2–5 [HIGH freedom]; Step 1
research JSON and every playwright step [LOW freedom — run exactly].
Read protocol-browser-anti-stall before any browser interaction.
How to reason
- Observe — quote the screenshot, copy, or code line
- Interpret — what does this do to the human in this moment of the pipeline?
- Classify — heuristic fail / law violation / microcopy / correct-as-is
- Severity — blocks the success moment = P0; recoverable friction = P1; nit = P2
Worked example
Observe: invoice Submit stays enabled; no toast;
POST /invoicesin-flight 4s. Interpret: a second click creates a duplicate invoice (H1 + H5, money path). Classify: heuristic fail on a trust-sensitive write. Severity: P0 — double-submit on money. Finding:/invoices/new| H1/H5 | P0 | no pending state | disable + toast.
Self-critique before reporting [LOW freedom — do not skip]
- Evidenced — screenshot or quoted copy, not "feels confusing"
- Per-page — cross-page IA/stories →
audit-ux-journeys - Severity justified — P0 blocks the recorded success moment
- Right owner — breakpoints →
audit-responsive; empty/error →audit-ui-states - Context first — no finding without Step 0 human + pipeline
Context-First
Before scoring a heuristic: who is the human (state, not "users"), where this page sits in the journey, how data moves input → API → DB → screen, and the emotional arc. Step 0 is mandatory.
Step 0: Deep Product and Pipeline Understanding
0a. Understand the Business and Human Context
Read README, landing page, marketing copy, and any onboarding flows to answer:
- What problem does this solve? (Not features — the human pain it alleviates)
- Who is the primary human? (Demographics, technical skill, emotional state when using)
- What's the alternative? (What do people do without this product? Spreadsheets? Phone calls? Nothing?)
- What's the success moment? (The "aha" — when the human gets what they came for)
- What's the trust model? (Does the user trust this product with money? Health data? Business data?)
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 429 lines · 72 tokens per session scan A bed3de0b5da0
audit-ux is a skill published in the GitHub repository kensaurus/cursor-kenji (9 stars, last pushed 10d ago), licensed MIT. It adds 72 tokens to every session and 4,391 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
frontend-slides
Create stunning, animation-rich HTML presentations from scratch or by converting PowerPoint files. Use when the user wants to build a presentation, convert a PPT/PPTX to web, or create slides for a talk/pitch. Helps non-designers discover their aesthetic through visual exploration rather than abstract choices.
brand-intel-branddev
Brand intelligence - logos, colors, fonts, styleguides, and company data from any domain.
create-workflow-diagram
Create FigJam/Miro-style workflow diagrams as high-quality PNG images from plain-text workflow descriptions. Renders beautiful HTML diagrams with connected nodes, arrows, and labels, then screenshots them for sharing.
goose-graphics-create-style
End-to-end skill that turns a single reference image into a published Gooseworks style — analyzes the image, drafts the slim style spec, renders a hero example plus 2-3 additional formats via Playwright, writes the gooseworks-style.json manifest, and publishes via npx gooseworks styles publish so other agents can…
goose-graphics
Portable visual skill pack for the Agent Skills ecosystem (Claude Code, Claude Desktop, Claude Cowork, Claude Design, Goose, Cursor, Codex). Discovers community-published styles + formats via the gooseworks CLI, runs an extract-style workflow on reference images, and exports rendered PNGs via Playwright.
create-chatgpt-mockup
Render pixel-accurate ChatGPT mobile (iOS) screen mockups in light mode from a thread JSON. Supports user text bubbles, user image attachments, assistant markdown prose, citation chips, the OpenAI spiral logo, the Apps-SDK GPT chip in the composer, and three header styles (model-tag, plain title, "Get Plus"). Fixed…