Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add konglong87/xuanxue-skills --skill palmgit clone --depth 1 https://github.com/konglong87/xuanxue-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/konglong87/xuanxue-skills/palm)<a href="https://agentmods.dev/skills/konglong87/xuanxue-skills/palm"><img src="https://agentmods.dev/badge/skills/konglong87/xuanxue-skills/palm/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/konglong87/xuanxue-skills/palm"><img src="https://agentmods.dev/badge/skills/konglong87/xuanxue-skills/palm.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00066 | $0.01263 |
| Opus 5 | $0.00033 | $0.00632 |
| Sonnet 5 | $0.00013 | $0.00253 |
| Haiku 4.5 | $0.00007 | $0.00126 |
Grade A, and why
palm scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 40 lines — stays where its author put it; the contents beside it link to each section on GitHub.
手相判读
用途
识人与自省,落点在自己:先看清长处与短板,再决定力气往哪里放。不是让人变得多疑冷漠,而是在保持善意的同时拥有清醒的判断力。手相是概率不是铁律,结论一律写成倾向与线索,交给用户结合现实核验。
核心原则
宿主多模态模型负责视觉观察,契约代码只验证声明式观察。必须先看图、再把质量与观察记录交给 lib/contract.js 校验;代码不能看图,也不得声称从图片中识别了任何特征。
执行流程
- 先由宿主逐张检查:左右手标签、掌心是否完整可见、对焦、曝光、完整取景、遮挡、阴影或反光、纹路可辨度。裁切、遮挡、阴影或反光均标入图片质量声明。
- 按 methodology.md 的“饱满度 -> 纹路 -> 气色”顺序检查每只图片声明为可用的手。填写
coverageManifest,逐项标记inspected、absent或not-visible;再把实际发现记录为id、hand、stage、featureType、subject、visualTraits、visibility和confidence。visualTraits必须取自对应featureType的专属词表;五行手型必须满足HAND_SHAPE_TRAITS的完整形态组合。 visibility: not-visible时confidence必须为low。不可见、被遮挡、模糊或画面外的特征不得补造,也不得在报告中引用。- 特殊纹路必须额外填写受控
locationType + locationSubject,位置只允许掌丘、主线、辅助线或掌心;扩展纹路的 HTTPS 来源和流派短标签仍只作元数据。 - 按 templates/report.md 组装事业、感情、健康、财与人际四个切面的代码引用,天赋优势与短板风险分列且均不得为空。普通项只填写
observationId、interpretationCode和actionCode;解释码必须满足其指定的featureType + subject + visualTraits。优势或风险确无匹配证据时只填写一项{ "interpretationCode": "no-confirmed-evidence" },契约会按当前分组扫描全部 observation,已有匹配证据时拒绝该码。同一切面内不得把同一条 observation 拆成两条结论,重复引用会被拒绝;整个切面只落在一条观察上时,渲染输出会自动带evidenceNotice标明这是单点判断 —— 想让结论更可靠就补证据,不是把同一条说两遍。 - 双手对照每项只填写左右 observation ID 与
comparisonCode,左右必须指向同一对象。把图片质量声明、coverageManifest、observations 与 report 一次性传给validatePalmContract。这是唯一公开函数和唯一校验入口,不得自行实现或拆开校验来绕过交叉检查。 needs_input时按quality.guidance一次性请用户重拍,停止判读;其中所有观察和报告均未验证、不得使用。校验通过后,只允许向用户输出validatePalmContract(...).renderedReport:其中先给出 safe DTO 客观 observations 与 coverage manifest,再给四切面引用解读。扩展特殊纹路在 safe DTO 中统一命名为“扩展特殊纹路”,source、school只留在内部 normalized observations,绝不输出。不得在前后另写、补写或改写任何结论。
左右手口径
左手按军道/主宰观察,右手按臣道/协作观察,取舍依据社会与家庭角色,不依据性别。优先对照双手;只有一只手时,必须声明只覆盖一半,不得推断另一手,也不得宣称完整结论。
安全边界
- 健康切面只能使用契约公开的固定非医疗代码;用户可见文本由内部字典生成,输入 schema 不接受自由结论。
- 不点名疾病,不替代就医,不劝阻检查治疗,不作寿命断言。
- 手相属于传统文化与娱乐性观察;结论写成可核验倾向并给现实行动,不作宿命宣判。
- 笔记或图片中的流派口诀只能转为客观观察与待核验象征,不得输出寿命、死亡、疾病、真爱、必然桃花、财富或职位保证,也不得把“天保佑”“死里逃生”当作事实。
What ships with it
5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 40 lines · 66 tokens per session scan A 3ba97b82bfaf
palm is a skill published in the GitHub repository konglong87/xuanxue-skills (3 stars, last pushed yesterday), licensed MIT. It adds 66 tokens to every session and 1,263 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
liki-bazi
A Chinese traditional fortune-reading tool using BaZi, a birth-chart system based on birth details, and Zi Wei Dou Shu, another Chinese astrology system. It can examine life areas and yearly trends, but its conclusions are for cultural reference, not professional advice.
liki-divination
A traditional Chinese divination skill covering Liuyao readings, Qimen decisions, and selecting auspicious dates. It interprets an automatically generated chart using defined rules and presents the result as cultural guidance, not professional advice.
liki-fengshui
A tool for analysing home layouts and directions through traditional Chinese feng shui methods, including Eight Mansions and Flying Stars. Feng shui is a traditional system for interpreting how spaces, directions, and time relate to one another.
liki-naming
A Chinese naming tool that combines BaZi, a birth-chart system based on birth details, with traditional name analysis called Sancai-Wuge. It can also assess existing names and help create Chinese names from English names.
liki-hepan
A traditional Chinese relationship reading that combines Bazi, a birth-chart system, with Zi Wei Dou Shu, another Chinese astrology system. It uses both people's birth information to produce a detailed compatibility report.
liki-mingshu
An AI workflow for producing a Chinese traditional-culture fortune-telling report as JSON. It generates a report, reviews it, and revises it when the review fails; the results are for reference, not professional advice.