Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/kychee-com/run402/buzznpx skills add kychee-com/run402 --skill buzzgit clone --depth 1 https://github.com/kychee-com/run402What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00119 | $0.03896 |
| Opus 5 | $0.00060 | $0.01948 |
| Sonnet 5 | $0.00024 | $0.00779 |
| Haiku 4.5 | $0.00012 | $0.00390 |
Grade A, and why
run402-buzz scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 157 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Run402 for Buzz
Keep the Buzz/Nostr key and Run402 wallet key separate. Link their public identities with the existing dual-proof ceremony; never derive, import, export, or expose either private key.
Buzz and Run402 treat people and agents as first-class participants. Each person or agent acts through its own identity and keeps an attributable history. Equal standing never means shared credentials or equal permissions: Run402 memberships, grants, delegates, freshness, and spend policy still determine authority.
Keep the authority domains explicit. Buzz is authoritative for signed collaboration evidence. Run402 is authoritative for organizations, project authority, deploys, leases, billing, delivery attempts, and runtime receipts. Identity links and receipts connect the records; Buzz proof is evidence, never Run402 authentication or authorization.
Copying, updating, or discovering the skill files performs no setup and grants no authority. In a managed Buzz conversation, the canonical request Please install the run402.com skill is nevertheless a goal-shaped request to install and connect Run402: after the inert files are verified, continue in the same turn through preflight, setup, and public identity-link verification. Stop after file installation only when the human explicitly says to copy/install the files only or says not to set up or connect Run402.
Install or update this skill
Read references/installation.md when installing, updating, repairing, or reporting this skill. Use first-party discovery at https://run402.com, the exact managed-runtime target, and the bounded transport-only GitHub fallback defined there. An integrity failure or ambiguous failure stops before setup with mutation_state: "not_started"; never hide it by changing source. Installation itself remains inert. After verifying the installed package and target path, immediately read the installed SKILL.md from that verified path and continue with the setup workflow below in the current turn. Do not say that the skill will be available on the next turn, ask whether to set up Run402, or stop at the installation receipt unless the human explicitly requested files only or prohibited setup/connection.
What ships with it
26 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- fixtures/buzz-relay-v0.2.1-notification-capability.json 927 B
- fixtures/buzz-relay-v0.2.1-notification-kind9.json 3.7 KB
- fixtures/buzz-relay-v0.2.1-notification-membership.json 2.0 KB
- fixtures/buzz-relay-v0.2.1-notification-tombstone.json 1.1 KB
- fixtures/buzz-v0.4.26-desktop-owner-negative.json 1.8 KB
- fixtures/buzz-v0.4.26-managed-agent-kind1.json 2.0 KB
- fixtures/buzz-v0.5.2-browser-fragment-v1.json 4.4 KB
- fixtures/buzz-v0.5.2-cli-capabilities.json 2.6 KB
- fixtures/buzz-v0.5.2-community-authority.json 4.8 KB
- fixtures/identity-link-v1-golden.json 8.7 KB
- fixtures/run402-buzz-doctor-v1-contract.json 3.1 KB
- helper.test.mjs 3.9 KB runs code
- install-smoke.mjs 8.1 KB runs code
- package.test.mjs 14 KB runs code
- README.md 10 KB
- references/community-control-plane.md 10 KB
- references/conversations.md 2.0 KB
- references/identity-and-security.md 4.4 KB
- references/installation.md 6.0 KB
- references/preflight.md 7.2 KB
- references/receipts.md 3.6 KB
- scripts/buzz-publish-proof.mjs 5.3 KB runs code
- scripts/doctor-report.mjs 4.0 KB runs code
- scripts/setup.mjs 35 KB runs code
- scripts/strict-json.mjs 4.1 KB runs code
- setup.test.mjs 35 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 157 lines · 119 tokens per session scan A aa74be99ce0e
run402-buzz is a skill published in the GitHub repository kychee-com/run402 (24 stars, last pushed 2d ago), licensed MIT. It adds 119 tokens to every session and 3,896 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
agentpay
Use this skill when the user wants to monetize an MCP server, accept payments from AI agents, set up x402 micropayments on Solana, work with the agentpay TypeScript stack, or build "agent pays for tools" flows. Triggers include phrases like "monetize my tool", "paid MCP server", "agent payments", "x402", "agentpay"…
utcp-cli
Call external APIs, MCP servers, and CLI tools by writing TypeScript code that runs in a sandbox — without MCP. Use when the user wants the agent to use a tool/API/integration (e.g. "search Open Library", "read my Notion", "call this REST API") in an environment that has a shell but no MCP config and no settable…
design-mcp-server
Design the tool surface, resources, and service layer for a new MCP server. Use when starting a new server, planning a major feature expansion, or when the user describes a domain/API they want to expose via MCP. Produces a design doc at docs/design.md that drives implementation.
earn-hunter
Automatically monitors OKX Flash Earn, Fixed Earn and Flexible Earn opportunities, sends push notifications, and guides subscription. 自动监控 OKX 闪赚、定期和活期赚币机会,推送通知并引导申购。Use when user says: 有闪赚通知我, 监控赚币, monitor earn, notify me about earn, 定时检查理财, 执行 earn-hunter 扫描, earn-hunter scan, 活期年化高了通知我, 监控活期.
okx-cex-market
Use this skill when the user asks for: price of any asset, ticker, order book, candles, OHLCV, funding rate, open interest, OI change scanner, market screener (top movers, high-volume, newly listed), mark price, index price, recent trades, instrument list, stock tokens, metals prices (gold, XAU, XAG), commodities…
cortex-automate
Set up automation — prospective memory triggers, neuro-symbolic rules, and CLAUDE.md sync. Use when the user says 'remind me when', 'trigger when', 'create a rule', 'auto-remember', 'sync to CLAUDE.md', 'push insights', 'set up trigger', 'when I open this file', 'when this keyword appears', or when you want to…