Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/miru-zero/zero-brain/type-jugglingnpx skills add miru-zero/zero-brain --skill type-jugglinggit clone --depth 1 https://github.com/miru-zero/zero-brainWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/miru-zero/zero-brain/type-juggling)<a href="https://agentmods.dev/skills/miru-zero/zero-brain/type-juggling"><img src="https://agentmods.dev/badge/skills/miru-zero/zero-brain/type-juggling.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00054 | $0.03228 |
| Opus 5 | $0.00027 | $0.01614 |
| Sonnet 5 | $0.00011 | $0.00646 |
| Haiku 4.5 | $0.00005 | $0.00323 |
Grade A, and why
type-juggling scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
97% identical to type-juggling — 4 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 292 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SKILL: PHP Type Juggling — Weak Comparison & Magic Hash Bypass
AI LOAD INSTRUCTION: PHP
==coercion, magic hashes (0e…), HMAC/hash loose checks, NULL from bad types, and CTF-stylestrcmp/json_decode/intvaltricks. Use strict routing: map the sink (==vshash_equals), PHP major version, and whether both operands are attacker-controlled. Routing note: when you encounter PHP login/signature logic or code likemd5($_GET['x'])==md5($_GET['y']), start with this skill; ifhash_equals/===is already used, this path usually does not apply.
0. QUICK START
First-pass goal: prove the server branch treats unequal secrets/tokens as equal via coercion, not guess the real password.
First-pass payloads (auth / token shape)
password[]=x
password=
0
0e12345
240610708
QNKCDZO
true
[]
{"password":true}
admin%00
Minimal PHP probes (local or php -r in lab)
<?php
// Loose compare probes — run in target PHP major version if possible
var_dump('0e123' == '0e999');
var_dump('123a' == 123);
var_dump(md5('240610708') == md5('QNKCDZO'));
Routing hints
| Clue | Next step |
|---|---|
Source code uses == to compare passwords, tokens, or HMAC values |
Go to Sections 1-3 |
md5($a) == md5($b) or loose sha1 comparison |
Section 2 magic hashes |
hash_hmac(...) != '0' or compared with "0" |
Section 3 |
strcmp、json_decode(..., true)、intval |
Section 5 |
1. LOOSE COMPARISON (==) — TRUTH TABLE & VERSIONS
PHP compares operands with type juggling unless you use === or hash_equals() for secrets.
1.1 Core examples (strings vs numbers)
| Expression | Result | Mechanism (short) |
|---|---|---|
'0010e2' == '1e3' |
true | Both strings look numeric → compared as floats; both parse to 1000.0 (not zero — common exam trap; see next row for real “both zero”) |
'0e462097431906509019562988736854' == '0e830400451993494058024219903391' |
true | Both parse as 0.0 in scientific notation |
'123a' == 123 |
true | String cast to int stops at first non-digit → 123 |
'abc' == 0 |
true (PHP 7.x and earlier) | Non-numeric string compared to int → string becomes 0 |
'' == 0 |
true | Empty string → 0 |
'' == false |
true | both “falsy” in loose rules |
false == NULL |
true | loose equality |
0 == false |
true | loose equality |
'' == 0 == false == NULL |
true (chain) | Each adjacent pair is true under == (''==0, 0==false, false==NULL) — classic “falsy” chain |
'0' == false |
true | String '0' is the only non-empty string that compares as false to boolean |
'php' == 0 |
false (PHP 8+) | PHP 8: non-numeric string no longer equals 0 |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 292 lines · 54 tokens per session scan A c216b5ec861b
type-juggling is a skill published in the GitHub repository miru-zero/zero-brain (0 stars, last pushed 18d ago), licensed MIT. It adds 54 tokens to every session and 3,228 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 97% identical to type-juggling, differing in 4 lines, and is treated as a copy.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…