Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add MilkyWay008/Hermes-OTG --skill unbrokergit clone --depth 1 https://github.com/MilkyWay008/Hermes-OTGWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/milkyway008/hermes-otg/unbroker)<a href="https://agentmods.dev/skills/milkyway008/hermes-otg/unbroker"><img src="https://agentmods.dev/badge/skills/milkyway008/hermes-otg/unbroker/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/milkyway008/hermes-otg/unbroker"><img src="https://agentmods.dev/badge/skills/milkyway008/hermes-otg/unbroker.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00015 | $0.06304 |
| Opus 5 | $0.00008 | $0.03152 |
| Sonnet 5 | $0.00003 | $0.01261 |
| Haiku 4.5 | $0.00002 | $0.00630 |
Grade A, and why
unbroker scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
98% identical to unbroker — 10 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 318 lines — stays where its author put it; the contents beside it link to each section on GitHub.
unbroker
Find where a person's personal information (name, addresses, phone, email, relatives) is exposed on data brokers and people-search sites, then remove it - automatically where possible, with guided human steps only where a site demands a CAPTCHA, government ID, phone call, or fax. Manages multiple people independently. It does not defeat anti-bot systems, does not act on anyone without recorded consent, and does not remove public records (voter/property/court) or accounts the person controls.
The Python CLI (scripts/pdd.py) owns the deterministic state - config, dossiers + consent, the
broker database, tier planning, the ledger, drafts, reports, email sending (SMTP), verification-link
polling (IMAP), and the autonomous action queue (next). You (the agent) do the scanning and
form-driving with native tools: web_extract and browser_navigate for searching and web forms, and
cronjob for recurring re-scans.
Autonomy contract
This skill is designed to run hands-off. After intake (+ recorded consent) there are exactly TWO
legitimate human touchpoints: (1) the intake conversation itself, and (2) ONE consolidated human-task
digest at the end of the run ($PDD tasks). Between those:
- Never ask the operator to choose configuration.
$PDD setup --autodetects capabilities and picks the most autonomous valid config itself. - Never pause before individual submissions when
autonomy=full(the default): the consent recorded at intake is standing authorization for T0-T2 opt-outs. (autonomy=assistedrestores per-submission confirmation for cautious operators - honorconfirm_firstflags innextoutput.) - Never interrupt the run for human-only work. Record it (
record ... human_task_queued --reason "...") and keep going; it all surfaces once in the final digest. - Drive the whole run as a loop over
$PDD next <subject>- it returns the exact ordered actions to take right now (scan, poll verification, re-check, opt out parents-first, requeue blocked), plus the human digest. Execute every action, record outcomes, re-runnext, repeat untildone_for_now. Then present the digest, report, and schedule the cron.
What ships with it
55 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- assets/unbroker.png 350 KB
- README.md 10 KB
- references/brokers/addresses.json 1.8 KB
- references/brokers/advancedbackgroundchecks.json 2.9 KB
- references/brokers/beenverified.json 3.5 KB
- references/brokers/clustal.json 2.3 KB
- references/brokers/clustrmaps.json 1.4 KB
- references/brokers/cyberbackgroundchecks.json 1.4 KB
- references/brokers/familytreenow.json 1.4 KB
- references/brokers/fastpeoplesearch.json 2.2 KB
- references/brokers/intelius.json 11 KB
- references/brokers/mylife.json 974 B
- references/brokers/nuwber.json 1.4 KB
- references/brokers/peekyou.json 1.4 KB
- references/brokers/peoplefinders.json 1.5 KB
- references/brokers/radaris.json 3.4 KB
- references/brokers/rehold.json 2.1 KB
- references/brokers/searchpeoplefree.json 1.4 KB
- references/brokers/socialcatfish.json 2.1 KB
- references/brokers/spokeo.json 3.1 KB
- references/brokers/thatsthem.json 2.5 KB
- references/brokers/truepeoplesearch.json 2.7 KB
- references/brokers/usphonebook.json 1.4 KB
- references/brokers/whitepages.json 4.0 KB
- references/legal/ccpa.md 1.1 KB
- references/legal/drop.md 2.1 KB
- references/legal/gdpr.md 737 B
- references/methods.md 27 KB
- references/site-playbooks.md 5.1 KB
- references/state-machine.md 3.2 KB
- scripts/autopilot.py 21 KB runs code
- scripts/badbool.py 6.0 KB runs code
- scripts/brokers.py 2.6 KB runs code
- scripts/cdp.py 5.8 KB runs code
- scripts/config.py 6.0 KB runs code
- scripts/crypto.py 3.0 KB runs code
- scripts/dossier.py 4.8 KB runs code
- scripts/email_modes.py 3.0 KB runs code
- scripts/emailer.py 14 KB runs code
- scripts/ledger.py 7.8 KB runs code
- scripts/legal.py 2.3 KB runs code
- scripts/paths.py 2.1 KB runs code
- scripts/pdd.py 46 KB runs code
- scripts/registry.py 14 KB runs code
- scripts/report.py 7.0 KB runs code
- scripts/scan.py 1.3 KB runs code
- scripts/storage.py 4.3 KB runs code
- scripts/tiers.py 14 KB runs code
- scripts/vectors.py 2.1 KB runs code
- templates/consent/authorization.md 742 B
- templates/emails/ccpa-authorized-agent.txt 792 B
- templates/emails/ccpa-deletion.txt 686 B
- templates/emails/ccpa-indirect-deletion.txt 1.4 KB
- templates/emails/gdpr-erasure.txt 606 B
- templates/emails/generic-optout.txt 470 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 318 lines · 15 tokens per session scan A 075d93606b0a
unbroker is a skill published in the GitHub repository MilkyWay008/Hermes-OTG (15 stars, last pushed 28d ago), licensed MIT. It adds 15 tokens to every session and 6,304 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 98% identical to unbroker, differing in 10 lines, and is treated as a copy.
Other skills, from other repositories
policy-lookup
Find and explain company policies in plain language. Trigger with "what's our PTO policy", "can I work remotely from another country", "how do expenses work", or any plain-language question about benefits, travel, leave, or handbook rules.
crisis-holding
Draft crisis holding statements, journalist Q&A posture, and what-not-to-say guidance from confirmed incident facts, with a hard legal-counsel gate. Builds each statement through proven crisis-comms frameworks (holding-statement anatomy, SCCT, CAP order, the legitimate non-answer, bridge/flag/block).
carl-file-organizer
A cautious tool for surveying and organising a messy folder, or analysing where disk space is being used. It first creates a proposed plan and waits for the user's approval before moving files.
vault-organization
Audit and reorganize the user's Obsidian vault. Run when asked to organize, clean up, or audit the vault structure — or to set up a sensible structure for a new/empty vault.
session-artifact-indexing
Use this skill when a session creates or references several documents, trackers, plans, templates, source links, or skills that the user may need later.
collecting-volatile-evidence-from-compromised-host
Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.