Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add KunanonJ/ai-skills-hub --skill aside-password-managergit clone --depth 1 https://github.com/KunanonJ/ai-skills-hubWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/kunanonj/ai-skills-hub/aside-password-manager)<a href="https://agentmods.dev/skills/kunanonj/ai-skills-hub/aside-password-manager"><img src="https://agentmods.dev/badge/skills/kunanonj/ai-skills-hub/aside-password-manager/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/kunanonj/ai-skills-hub/aside-password-manager"><img src="https://agentmods.dev/badge/skills/kunanonj/ai-skills-hub/aside-password-manager.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00039 | $0.02254 |
| Opus 5 | $0.00019 | $0.01127 |
| Sonnet 5 | $0.00008 | $0.00451 |
| Haiku 4.5 | $0.00004 | $0.00225 |
Grade A, and why
aside-password-manager scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 215 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Password Manager
Aside Password Manager is a native credential manager the agent can use without seeing generated passwords.
Use passwordManager in the REPL to autofill logins, payment cards, and identities, create signup password refs, search saved credential sites, and store credentials.
Before using Aside Password Manager as the website login source, check memory/USER.md for connected external password manager preferences.
If the user configured one or more external providers, try a connected provider first and use Aside Password Manager to unlock that provider or as the fallback.
If no connected external provider preference is present, use Aside Password Manager as the default login/autofill source.
Use Cases
1. Check websites the user is using
When searching for task-relevant information, saved credential sites are useful hints about services the user already uses. It never exposes the secret values so it's safe to use for searching.
const keywords = ['search 1', 'search 2', 'search 3'];
const vaults = await passwordManager.listVaults();
// vaults: [{ vaultId, name }, ...]
const results = await Promise.all(keywords.map(k => passwordManager.listItems({ text: k })));
// results: [[{ title, urls, category, username, oauth, primaryHost, vaultId, itemId }, ...], ...]
Use these results to find relevant sites the user already uses.
2. Autofill a selected item
When you are on a login page, search login candidates with listItems(...), then use autofillItem(page, itemId) only after selecting a clearly matching item.
listItems(...) may return multiple candidates. Choose by site, title, username/OAuth account, URLs, and task context. Ask only when the right account is genuinely ambiguous - last resort!
If Aside has no usable login, continue normal page inspection. Users may have other password managers (e.g. 1Password), and focusing a field may reveal their autofill UI.
const candidates = await passwordManager.listItems({ text: 'example.com', category: 'login' });
console.log(candidates);
// If one candidate clearly matches the user's task, use it and continue browsing.
await passwordManager.autofillItem(page, '<selected-item-id>');
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 215 lines · 39 tokens per session scan A 1f84067c124a
aside-password-manager is a skill published in the GitHub repository KunanonJ/ai-skills-hub (5 stars, last pushed 2d ago), licensed MIT. It adds 39 tokens to every session and 2,254 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
issue-creation
Trigger: issue creation, bug reports, feature requests, or issue approval. Create and triage GitHub issues from repository evidence.
sdd-tasks
Break an SDD change into implementation tasks. Trigger: orchestrator launches task planning for a change.
work-unit-commits
Plan commits as reviewable work units. Trigger: implementation, commit splitting, chained PRs, or keeping tests and docs with code.
systemic-issue-triage
Trigger: new issue, bug report, triage, backlog, issue flood, community report, root cause, dead-end, blocked user. Attack issues by root class, never one-by-one; fixes must shrink the system, not grow it.
sdd-research
Trigger: SDD research, external evidence, source-backed research. Produce auditable evidence for a selected research lane.
skill-improver
Trigger: improve skills, audit skills, refactor skills, skill quality. Audit and upgrade existing LLM-first skills.