Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/kint4/autoframe/api-coveragenpx skills add kint4/autoframe --skill api-coveragegit clone --depth 1 https://github.com/kint4/autoframeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00037 | $0.00347 |
| Opus 5 | $0.00018 | $0.00173 |
| Sonnet 5 | $0.00007 | $0.00069 |
| Haiku 4.5 | $0.00004 | $0.00035 |
Grade A, and why
api-coverage scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/api-coverage — Map API Test Coverage
Type: API Description: Maps API endpoints against existing API tests, showing which endpoints and methods are tested and which are missing.
Input Format
Optional:
- A list of endpoints (pasted, OpenAPI/Swagger spec, or via connector)
- A feature scope
With no input, map all existing API specs under tests/api/.
Output Format
A coverage table:
| Endpoint | Method | Tested | Cases covered (success / auth / invalid / error) |
|---|
Plus a prioritized list of gaps with the suggested skill to close each.
Step-by-Step Instructions
- Enumerate every
*.api.spec.tsundertests/api/. - Parse each test to extract the endpoint, method, and which case types it covers (success / 401 / 400 / error).
- If an endpoint list or OpenAPI spec was provided, align tests to it; otherwise infer the endpoint set from existing tests.
- Mark each endpoint+method as fully tested, partially tested (missing case types), or untested.
- Render the coverage table.
- List gaps in priority order and recommend
/new-api-specto close each.
Rules
- A method isn't "covered" unless success, auth failure, and invalid input are all tested.
- Read specs, don't execute them.
- Be explicit about assumptions when no endpoint list is provided.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 44 lines · 37 tokens per session scan A 21110da5155a
api-coverage is a skill published in the GitHub repository kint4/autoframe (6 stars, last pushed 2mo ago), licensed MIT. It adds 37 tokens to every session and 347 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
tokenless
Use when a task can be delegated through the globally installed Tokenless CLI without directly writing to the workspace; route it to a visible AI provider website to save agent tokens.
tokenless-install
Install, upgrade, repair, and verify Tokenless, its agent skills, and local Playwright runtime. Use only when the user explicitly asks for installation, upgrade, repair, browser sign-in handoff, a failed doctor check, or an installation integrity check.
agent-qa-authoring
Use when creating, editing, validating, or running agent-qa tests, suites, or hooks. Prefer agent-qa MCP tools, enforce canonical agent-qa IDs, and use the bundled schema reference to avoid hallucinated config keys or YAML fields.
agent-qa-debug-fix
Use after an agent-qa run has failed and you need to debug, patch, and verify the issue using MCP evidence, logs, artifacts, and local code changes instead of generated fix suggestions.
linggan-talking-cards
将中文或英文口播文案与可选截图拆成 3–10 张 PPT 式演示卡片,输出文字准确的 PNG 卡片、结构化 manifest 和带逐卡口播台词的响应式 HTML 预览页。支持 3:4、16:9、9:16、4:3 四种比例,以及苹果白色毛玻璃、糖果、Obsidian、新丑风等 10 种视觉系统;适用于“口播文案拆解PPT生多图”“把逐字稿做成卡片”“给口播配 slides”“截图放进讲解卡片”“生成多图和预览页”“换一种 PPT 风格”以及修改指定卡片的请求。.
k6-load-testing
Comprehensive k6 load testing skill for API, browser, and scalability testing. Write realistic load scenarios, analyze results, and integrate with CI/CD.