Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ksachdeva/zephyr-rtos-ai --skill zephyr-cborgit clone --depth 1 https://github.com/ksachdeva/zephyr-rtos-aiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ksachdeva/zephyr-rtos-ai/zephyr-cbor)<a href="https://agentmods.dev/skills/ksachdeva/zephyr-rtos-ai/zephyr-cbor"><img src="https://agentmods.dev/badge/skills/ksachdeva/zephyr-rtos-ai/zephyr-cbor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ksachdeva/zephyr-rtos-ai/zephyr-cbor"><img src="https://agentmods.dev/badge/skills/ksachdeva/zephyr-rtos-ai/zephyr-cbor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00085 | $0.02107 |
| Opus 5 | $0.00043 | $0.01053 |
| Sonnet 5 | $0.00017 | $0.00421 |
| Haiku 4.5 | $0.00009 | $0.00211 |
Grade A, and why
zephyr-cbor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 235 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Zephyr CBOR (zcbor)
Zephyr integrates the zcbor library for CBOR encoding/decoding.
⭐ Recommended: Code Generation from CDDL Schema
For any non-trivial message format, use zcbor's code generator instead of hand-writing zcbor calls. It generates type-safe C structs and encode/decode functions from a CDDL schema — less error-prone, easier to maintain, and handles unions/optionals automatically.
1. Write a CDDL schema
CDDL supports two container styles — choose based on whether field order matters:
- Group/tuple
(...)— ordered sequence, no keys on wire (more compact) - Map
{...}— key-value pairs, order-independent (more flexible)
; my-api.cddl
; Integer constants for a discriminated union
cmd_get_status = 1
cmd_set_config = 2
command_id /= cmd_get_status
command_id /= cmd_set_config
; Enum values
status_idle = 0
status_active = 1
status_error = 2
device_status /= status_idle
device_status /= status_active
device_status /= status_error
; Tuple (ordered, compact — no keys on wire)
set_config_params = (
threshold: uint .size 2,
enabled: bool,
)
; Map (key-value, order-independent)
status_response = {
status_code: device_status,
uptime_ms: uint,
? error_msg: tstr,
}
; Top-level message with optional params
My_Command = (
command_id: command_id,
? params: set_config_params,
)
2. Generate C code
pip install zcbor
zcbor code --decode --encode \
--short-names \
-c my-api.cddl \
-t My_Command \
status_response \
--output-c src/cbor/my-api.c \
--output-h include/cbor/my-api.h \
--output-h-types include/cbor/my-api_types.h \
--include-prefix "cbor/" \
--default-max-qty 3
Key flags:
| Flag | Purpose |
|---|---|
--decode / --encode |
Generate decode and/or encode functions |
-t <types> |
Root types to generate entry-point functions for |
--short-names |
Shorten generated symbol names (avoids very long identifiers) |
--output-c/h/h-types |
Output paths for .c, .h, and _types.h |
--include-prefix |
Prefix added to #include paths inside generated .c files |
--default-max-qty N |
Max array/list entries (affects struct array sizes) |
--file-header <file> |
Prepend a custom copyright/license header to generated files |
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 235 lines · 85 tokens per session scan A 83e7a51c6141
zephyr-cbor is a skill published in the GitHub repository ksachdeva/zephyr-rtos-ai (23 stars, last pushed 3mo ago), licensed Apache-2.0. It adds 85 tokens to every session and 2,107 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
home-assistant
This skill should be used when helping with Home Assistant setup, including creating automations, modifying dashboards, checking entity states, debugging automations, and managing the smart home configuration. Use this for queries about HA entities, YAML automation/dashboard generation, or troubleshooting HA issues.
raspberry-pi-pico2
Use when developing with Raspberry Pi Pico 2 or the Pi Debug Probe.
piper-tts-training
Train custom TTS voices for Piper (ONNX format) using fine-tuning or from-scratch approaches. Use when creating new synthetic voices, fine-tuning existing Piper checkpoints, preparing audio datasets for TTS training, or deploying voice models to devices like Raspberry Pi or Home Assistant. Covers dataset preparation…
gap
Program robots with GaP (graph-as-policy) — compile natural-language tasks into typed, verified robot skill graphs and run them on simulators or real robots. Use when the user mentions GaP or graph-as-policy, robot manipulation, robot skills, robot tools or capabilities, skill registries, open-robot-skills, LIBERO or…
web-components
Architecture and coding rules for single-page applications using web components, BCE layering, lit-html templating, unidirectional Redux-style state management (reduction.js, standards-based), and standards-based client-side routing (Navigation API + URLPattern). Web standards and web platform first, minimal external…
sbce
Spec-driven BCE workflow where one capability spec equals one business component (same name) and the spec is the boundary contract. Invoked as /sbce new|apply (or by intent), it drives declare → converge; the stack's own test loop is the oracle for "done". new accepts a BC name or a natural-language feature…