use-404-directory

use-404-directory is a skill for Claude Code from MM-sheng/404-directory. It costs 83 tokens per session (1,497 once invoked), scanned A, original, MIT.

A set of procedures for checking Polymarket decisions and unfamiliar tools before an AI agent uses them. Polymarket is a platform where people trade contracts on whether events will happen.

In plain words
What is it for?
Reviewing one exact Polymarket market or assessing a third-party tool before installation or first use.
Why use it?
It helps identify settlement, timing, liquidity, location-blocking, and execution risks before a decision or tool action is made.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the 404-directory plugin — 1 skill shipped together

Good fit Reviewing one exact Polymarket market or assessing a third-party tool before installation or first use.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/mm-sheng/404-directory/use-404-directory
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add MM-sheng/404-directory --skill use-404-directory
Clone the repo
git clone --depth 1 https://github.com/MM-sheng/404-directory

Made for: Claude Code.

Or install 404-directory, the plugin that ships this one along with the rest of its 1 skill.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for use-404-directory

README.md
[![agentmods](https://agentmods.dev/badge/skills/mm-sheng/404-directory/use-404-directory/github.svg)](https://agentmods.dev/skills/mm-sheng/404-directory/use-404-directory)
Your own site
<a href="https://agentmods.dev/skills/mm-sheng/404-directory/use-404-directory"><img src="https://agentmods.dev/badge/skills/mm-sheng/404-directory/use-404-directory/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for use-404-directory

Your own site · 80×15
<a href="https://agentmods.dev/skills/mm-sheng/404-directory/use-404-directory"><img src="https://agentmods.dev/badge/skills/mm-sheng/404-directory/use-404-directory.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 83 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,497 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00083 $0.01497
Opus 5 $0.00042 $0.00749
Sonnet 5 $0.00017 $0.00299
Haiku 4.5 $0.00008 $0.00150

Measured 10d ago against content hash bb879df5574e, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

use-404-directory scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

distribution/404-directory/skills/use-404-directory/SKILL.md · 140 lines

How it starts

The opening of the file, as written. The whole thing — 140 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Use 404.directory

Route the user's task to the smallest relevant 404.directory workflow. Produce a useful answer from a real tool call; never call tools only to create traffic.

Connect when needed

Use the hosted Streamable HTTP endpoint:

https://404.directory/mcp

If the server is not connected, configure it before continuing. Prefer the client-specific configuration generated at:

https://404.directory/connect?source=agent-skill

When direct configuration is possible, generate one random UUID locally and keep it stable for that installation. Send agent:<uuid> in X-404-Agent-ID and the lowercase client name in X-404-Source. Never derive the ID from an email, username, hostname, prompt, or other personal data.

Do not clone or run the server locally unless the user explicitly requests local development. No account or API key is required.

Choose the workflow

  • For a concrete risk decision about one exact Polymarket market, use evaluate_prediction_market. This is the primary workflow.
  • Before installing or first invoking a third-party catalog tool, call evaluate_tool_risk with the exact action, data sensitivity, execution mode, and requested permissions. Obey block; pause for human review on review.
  • For current AI or cloud documentation, call search_official_docs first.
  • For a deployment claim, call verify_web with explicit expected status or text.
  • For the visible state, entities, or actions on a webpage, call understand_webpage.
  • To find an MCP capability, call search_tools or recommend_tools, then inspect candidates with get_tool and get_trust_score.
  • To call a third-party MCP tool, require an active, provider-verified, read-only catalog entry. Preflight it, then call inspect_tool_server before invoke_registered_tool.

Preflight a third-party tool

  1. If the exact catalog slug is unknown, use search_tools to find it.
  2. Call evaluate_tool_risk immediately before installation or first use.
  3. Include every requested permission. Missing context is uncertainty, not evidence of safety.
  4. On allow, proceed with minimum permissions. On review, pause for human approval or choose another tool. On block, do not proceed.
  5. After the decision or action, call report_tool_outcome with only the receipt token and bounded action/result fields. Never report prompts, arguments, outputs, secrets, or personal data.

Read the full file on GitHub · 140 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 140 lines · 83 tokens per session scan A bb879df5574e

Subscribe to this mod's changes

use-404-directory is a skill published in the GitHub repository MM-sheng/404-directory (1 stars, last pushed 4d ago), licensed MIT. It adds 83 tokens to every session and 1,497 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

coingecko-openapi-skill

Operate CoinGecko and GeckoTerminal market data APIs through UXC with a curated OpenAPI schema, API-key auth, and read-first guardrails.

holon-run/uxc · 38 tokens

blocknative-openapi-skill

Operate Blocknative gas intelligence APIs through UXC with a curated OpenAPI schema, API-key auth, and read-first guardrails.

holon-run/uxc · 33 tokens

scrape-structured-data

Get the repeating records off a web page (product grids, search results, job listings, news feeds, tables) as JSON, without writing CSS selectors and without spending a model call to read the HTML. Works on sites with no API, including ones behind a login or bot protection. Runs locally, one binary, no API key. Use…

sderosiaux/chrome-agent · 111 tokens

stock-quotes-list

A paginated list of current market quotes for Shanghai, Shenzhen, and Beijing A-share stocks. It can filter by market section and sort stocks by measures such as price change, turnover, volume, or market value.

FTShare-Lab/FTShare-skill · 64 tokens

eastmoney-hk-index-daily-kline

A lookup for daily price bars of Hong Kong stock indexes such as the Hang Seng Index, the Hang Seng China Enterprises Index and the Hang Seng Tech Index. Each record can include open, high, low, close, trading volume and daily changes.

FTShare-Lab/FTShare-skill · 136 tokens

eastmoney-us-stock-daily-ohlc

A lookup for historical daily open, high, low and close prices of a US stock from Eastmoney. With dates, it retrieves the range in small batches and combines the results.

FTShare-Lab/FTShare-skill · 77 tokens