Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/larsboes/axon/ha-clinpx skills add larsboes/Axon --skill ha-cligit clone --depth 1 https://github.com/larsboes/AxonWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/larsboes/axon/ha-cli)<a href="https://agentmods.dev/skills/larsboes/axon/ha-cli"><img src="https://agentmods.dev/badge/skills/larsboes/axon/ha-cli.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00052 | $0.00265 |
| Opus 5 | $0.00026 | $0.00133 |
| Sonnet 5 | $0.00010 | $0.00053 |
| Haiku 4.5 | $0.00005 | $0.00026 |
Grade A, and why
ha-cli scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
ha-cli
Generic Home Assistant REST tooling. Non-secret connection facts come from the active overlay; the API token comes from the configured private secret mechanism at runtime.
Commands
scripts/ha-cli config
scripts/ha-cli domains
scripts/ha-cli states [DOMAIN]
scripts/ha-cli get ENTITY_ID
scripts/ha-cli automations
scripts/ha-cli unavailable
scripts/ha-cli entries
scripts/ha-cli call DOMAIN SERVICE [JSON]
scripts/ha-cli reload-automations
scripts/ha-inventory [--overlay PATH] [--output PATH]
Read operations may reveal private entity IDs, locations, devices, URLs, and integration names.
Keep their output local. ha-inventory writes to the active overlay by default and must never
target the Axon repository.
Service calls and reloads are writes. Confirm the target and requested action before invoking them. A missing token or endpoint is an error; do not substitute remembered deployment facts.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 33 lines · 52 tokens per session scan A b9144e50db6c
ha-cli is a skill published in the GitHub repository larsboes/Axon (0 stars, last pushed 3d ago), licensed MIT. It adds 52 tokens to every session and 265 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
device-and-ui
Work with physical devices and UI automation. Use when implementing device commands, touch/swipe simulation, IDB integration, accessibility inspection, or editing files under src/core/devices.ts or src/core/ui-interaction.ts.
beryl-it-tech
🛠️ Device, system, and network diagnosis.
it-work-reviewer
🔍 Evidence audit for device repair claims.
eight-sleep
Unofficial Eight Sleep pod data for AI agents. Writes stay fail-closed. Prefer MCP tools if connected; otherwise the package CLI. Use when the user wants Eight Sleep data or actions through an agent.
wellness-cgm
Local-first CGM MCP for agents. Prefer MCP tools if connected; otherwise the package CLI. Use when the user wants Wellness CGM data or actions through an agent.
apple-shifu
Apple Shifu — keeps your Mac and iPhone healthy and tidy. System health (disk, apps, caches, dashboard) plus iPhone/Mac photo-video cleanup. Use --web for the interactive dashboard, or run directly in chat.