Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/machinepulse-ai/world2agent-plugins/world2agent-managenpx skills add machinepulse-ai/world2agent-plugins --skill world2agent-managegit clone --depth 1 https://github.com/machinepulse-ai/world2agent-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/machinepulse-ai/world2agent-plugins/world2agent-manage)<a href="https://agentmods.dev/skills/machinepulse-ai/world2agent-plugins/world2agent-manage"><img src="https://agentmods.dev/badge/skills/machinepulse-ai/world2agent-plugins/world2agent-manage.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00070 | $0.03040 |
| Opus 5 | $0.00035 | $0.01520 |
| Sonnet 5 | $0.00014 | $0.00608 |
| Haiku 4.5 | $0.00007 | $0.00304 |
Grade C, and why
world2agent-manage scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
`--purge` additionally `rm -rf`s the handler skill directory and runs Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
subscribe`, jq mutations, curl calls, or YAML edits inline.** Your job is: How it starts
The opening of the file, as written. The whole thing — 345 lines — stays where its author put it; the contents beside it link to each section on GitHub.
World2Agent sensor management
You manage the user's W2A sensors. All host-side work is delegated to shell
scripts in scripts/ — you never invoke the package manager, hermes webhook subscribe, jq mutations, curl calls, or YAML edits inline. Your job is:
- Decide which script to run, with which args.
- Run it via
bash <abs-path>(the scripts ship without the executable bit). - Parse the JSON the script prints on stdout — every script except
log.shemits exactly one JSON object, either{"ok":true,...}or{"ok":false,"error":"..."}. - Branch on the result, ask the user when needed, generate handler content yourself when needed.
Script path
The canonical install location is ~/.hermes/skills/world2agent-manage/scripts/.
A developer override via the WORLD2AGENT_MANAGE_SCRIPTS env var is honored
in case you're testing against an unpacked checkout. Use this expansion in
every invocation so both work in one line:
"${WORLD2AGENT_MANAGE_SCRIPTS:-$HOME/.hermes/skills/world2agent-manage/scripts}/<name>.sh"
(Examples below abbreviate this to $SCRIPTS/<name>.sh for readability.)
Conversation language
Run the entire Q&A in the user's current conversation language. Translate SETUP.md questions before asking. Don't dump English questions on a Chinese user, or vice versa.
Pre-flight: bootstrap
Before any sensor install or remove, call bootstrap.sh once. It is
idempotent; second runs just confirm existing state.
bash "$SCRIPTS/bootstrap.sh"
What it does:
- verifies
world2agent-hermes-supervisorandworld2agent-sensor-runnerare on PATH; - creates / preserves
~/.world2agent/.bridge-state.json(hmac_secret/control_token/control_port, mode 0600); - enables Hermes's webhook platform via a managed config block (refuses if
the user already has a hand-written top-level
platforms:block); - mirrors the same secret into the Hermes runtime env file;
- starts the supervisor (foreground,
nohup-detached).
What ships with it
13 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- scripts/_lib.sh 14 KB runs code
- scripts/bootstrap.sh 2.8 KB runs code
- scripts/install-launchd.sh 1.8 KB runs code
- scripts/install-sensor.sh 7.2 KB runs code
- scripts/install-systemd.sh 1.4 KB runs code
- scripts/list-sensors.sh 1.3 KB runs code
- scripts/log.sh 1.3 KB runs code
- scripts/read-setup.sh 1.5 KB runs code
- scripts/remove-sensor.sh 3.5 KB runs code
- scripts/start.sh 1.4 KB runs code
- scripts/status.sh 1.6 KB runs code
- scripts/stop.sh 1.1 KB runs code
- scripts/uninstall-bootstrap.sh 1.6 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 345 lines · 70 tokens per session scan C 987e4b7e8461
world2agent-manage is a skill published in the GitHub repository machinepulse-ai/world2agent-plugins (5 stars, last pushed 2d ago), licensed Apache-2.0. It adds 70 tokens to every session and 3,040 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it C with 2 findings (recursive force delete, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…
chronicle
Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…