Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add malob/nix-config --skill malo-find-skillsgit clone --depth 1 https://github.com/malob/nix-configWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/malob/nix-config/malo-find-skills)<a href="https://agentmods.dev/skills/malob/nix-config/malo-find-skills"><img src="https://agentmods.dev/badge/skills/malob/nix-config/malo-find-skills/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/malob/nix-config/malo-find-skills"><img src="https://agentmods.dev/badge/skills/malob/nix-config/malo-find-skills.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 6 findings, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium MCP Rug Pull · line 27 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
- medium MCP Rug Pull · line 38 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
- medium MCP Rug Pull · line 43 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
- medium MCP Rug Pull · line 44 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
- medium MCP Rug Pull · line 45 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
- medium MCP Rug Pull · line 62 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00069 | $0.00877 |
| Opus 5 | $0.00034 | $0.00439 |
| Sonnet 5 | $0.00014 | $0.00175 |
| Haiku 4.5 | $0.00007 | $0.00088 |
Grade A, and why
malo-find-skills scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 96 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Find Skills
This skill helps you discover and install skills from the open agent skills ecosystem (https://skills.sh). Based on the find-skills skill by Vercel, adapted for this Nix-managed environment.
When to Use This Skill
Use this skill when the user:
- Asks "how do I do X" where X might be a common task with an existing skill
- Says "find a skill for X" or "is there a skill for X"
- Asks "can you do X" where X is a specialized capability
- Expresses interest in extending agent capabilities
- Wants to search for tools, templates, or workflows
How Skills Work in This Setup
All paths below (e.g. home/claude.nix, configs/claude/skills/) are relative to the nix-config directory.
Skills are split into two categories:
- Custom skills: Directories in
configs/claude/skills/committed to the nix-config repo. These are skills we author and maintain. - External skills: Installed from skills.sh via
npx skills add. These are managed by an activation script inhome/claude.nixand are gitignored (they appear as symlinks in the skills directory, not regular directories).
The activation script defines a list called externalSkills. On every nh darwin switch --no-nom, it removes all Claude Code external skills and reinstalls only the declared ones. This keeps external skills declarative and reproducible.
Finding Skills
Step 1: Search
Run the find command with a relevant query:
npx skills find [query]
For example:
- "how do I make my React app faster?" ->
npx skills find react performance - "can you help me with PR reviews?" ->
npx skills find pr review - "I need to create a changelog" ->
npx skills find changelog
You can also browse skills at https://skills.sh/
Step 2: Present Options
When you find relevant skills, present them with:
- The skill name and what it does
- The install command
- A link to learn more
Step 3: Install
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 96 lines · 69 tokens per session scan A 25ef0b62a8dd
malo-find-skills is a skill published in the GitHub repository malob/nix-config (463 stars, last pushed 5d ago), licensed MIT. It adds 69 tokens to every session and 877 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
restart__pull_request
A pull-request restart workflow for replacing a messy review with a new pull request containing one clean commit and a summary of the earlier discussion.
validate__japanese
A Japanese-language review for Markdown documents, such as READMEs, manuals, and blog drafts. It checks writing style, spacing, line breaks, and links to real code symbols.
prepare__issue
An orchestration workflow that prepares an already acknowledged issue for implementation and changes its status to ready when finished.
rescue__pull_request_review
An automated workflow for handling GitHub pull-request review comments, applying requested code changes, committing them, and pushing them back.
submit__pull_request
An automated pull-request submission workflow. A pull request is a request for a code change to be reviewed and merged; this workflow writes its explanation, creates it, watches its automated checks, and fixes failed checks.
write__structured_comment
A code-commenting rule for recording only knowledge that cannot be expressed in the code, such as unfinished facts, outside-world facts, or explicit user instructions. Each comment must use an approved marker such as TODO or FIXME and stay short.