Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add khalilbenaz/claude-skills-collection --skill ocelot-gateway-guidegit clone --depth 1 https://github.com/khalilbenaz/claude-skills-collectionWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/khalilbenaz/claude-skills-collection/ocelot-gateway-guide)<a href="https://agentmods.dev/skills/khalilbenaz/claude-skills-collection/ocelot-gateway-guide"><img src="https://agentmods.dev/badge/skills/khalilbenaz/claude-skills-collection/ocelot-gateway-guide/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/khalilbenaz/claude-skills-collection/ocelot-gateway-guide"><img src="https://agentmods.dev/badge/skills/khalilbenaz/claude-skills-collection/ocelot-gateway-guide.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00110 | $0.02142 |
| Opus 5 | $0.00055 | $0.01071 |
| Sonnet 5 | $0.00022 | $0.00428 |
| Haiku 4.5 | $0.00011 | $0.00214 |
Grade A, and why
ocelot-gateway-guide scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 247 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Guide Ocelot API Gateway
Workflow — mise en place pas à pas
1. Installer les packages
dotnet add package Ocelot # Core — toujours requis
dotnet add package Ocelot.Provider.Consul # Service Discovery Consul
dotnet add package Ocelot.Provider.Eureka # Service Discovery Eureka
dotnet add package Ocelot.Cache.CacheManager # Cache distribué
dotnet add package Ocelot.Tracing.OpenTracing # Tracing distribué
2. Brancher Ocelot dans Program.cs
// Program.cs (.NET 8+)
var builder = WebApplication.CreateBuilder(args);
// Charge ocelot.json en priorité sur appsettings.json
builder.Configuration
.AddJsonFile("ocelot.json", optional: false, reloadOnChange: true)
.AddJsonFile($"ocelot.{builder.Environment.EnvironmentName}.json",
optional: true, reloadOnChange: true);
builder.Services
.AddOcelot(builder.Configuration)
.AddCacheManager(x => x.WithDictionaryHandle()) // cache en mémoire
.AddConsul() // si Consul utilisé
;
builder.Services.AddAuthentication()
.AddJwtBearer("Bearer", options =>
{
options.Authority = builder.Configuration["Jwt:Authority"];
options.Audience = builder.Configuration["Jwt:Audience"];
});
var app = builder.Build();
await app.UseOcelot();
app.Run();
3. Définir les routes dans ocelot.json
Chaque route = un objet dans "Routes". Minima obligatoires :
{
"Routes": [
{
"DownstreamPathTemplate": "/api/payments/{everything}",
"DownstreamScheme": "https",
"DownstreamHostAndPorts": [
{ "Host": "payment-service", "Port": 8080 }
],
"UpstreamPathTemplate": "/payments/{everything}",
"UpstreamHttpMethod": ["GET", "POST", "PUT", "DELETE"],
"AuthenticationOptions": {
"AuthenticationProviderKey": "Bearer"
},
"RateLimitOptions": {
"EnableRateLimiting": true,
"Period": "1m",
"PeriodTimespan": 60,
"Limit": 100
},
"QoSOptions": {
"ExceptionsAllowedBeforeBreaking": 3,
"DurationOfBreak": 10000,
"TimeoutValue": 5000
},
"FileCacheOptions": {
"TtlSeconds": 30,
"Region": "payments"
}
},
{
"DownstreamPathTemplate": "/api/orders/{everything}",
"DownstreamScheme": "https",
"DownstreamHostAndPorts": [
{ "Host": "order-svc-1", "Port": 8080 },
{ "Host": "order-svc-2", "Port": 8080 }
],
"UpstreamPathTemplate": "/orders/{everything}",
"UpstreamHttpMethod": ["GET", "POST"],
"LoadBalancerOptions": { "Type": "RoundRobin" }
}
],
"GlobalConfiguration": {
"BaseUrl": "https://api.company.com",
"RateLimitOptions": {
"DisableRateLimitHeaders": false,
"QuotaExceededMessage": "Trop de requêtes, réessayez plus tard",
"HttpStatusCode": 429
}
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 247 lines · 110 tokens per session scan A 4541743ac22b
ocelot-gateway-guide is a skill published in the GitHub repository khalilbenaz/claude-skills-collection (22 stars, last pushed 19d ago), licensed MIT. It adds 110 tokens to every session and 2,142 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
api-patterns
API design: naming, versioning, pagination, idempotency, OpenAPI, error contracts and safe retries. Triggers: API design, REST, GraphQL, OpenAPI, Swagger, error response, HTTP status, rate limit.
csharp-patterns
C#/.NET: LINQ, async/await, DI, records, nullable refs, ASP.NET Core, EF Core, MediatR. Triggers: C#, .NET, dotnet, ASP.NET, EF Core, LINQ, record type, IServiceCollection.
java-patterns
Java: Spring Boot, CompletableFuture, records, sealed types, JPA/Hibernate, virtual threads. Triggers: Java, Spring, JPA, Hibernate, Maven, Gradle, virtual thread, sealed class.
medplum-rules
Medplum (FHIR healthcare) coding rules: style, patterns, security, testing. Triggers: medplum.config.mts, medplum.config.ts, FHIR, Medplum, Bot, Subscription, Questionnaire.
api-design
REST API contract designer and reviewer. ALWAYS use when designing new endpoints, reviewing existing API contracts, planning API versioning, or standardizing error models. Covers resource modeling (URL/naming), HTTP method semantics, status code selection, error model consistency, pagination/filtering/sorting…
kafka-event-driven-design
Kafka event-driven architecture designer and reviewer, at the application/client layer. ALWAYS use when designing, reviewing, or troubleshooting how a service produces or consumes Kafka events — topic and partition-key design, producer and consumer client configuration, consumer group topology, event schema definition…