Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add MontoyaAndres/ganju --skill ganju-cligit clone --depth 1 https://github.com/MontoyaAndres/ganjuWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/montoyaandres/ganju/ganju-cli)<a href="https://agentmods.dev/skills/montoyaandres/ganju/ganju-cli"><img src="https://agentmods.dev/badge/skills/montoyaandres/ganju/ganju-cli/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/montoyaandres/ganju/ganju-cli"><img src="https://agentmods.dev/badge/skills/montoyaandres/ganju/ganju-cli.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00148 | $0.03801 |
| Opus 5.5 | $0.00059 | $0.01520 |
| Sonnet 5.5 | $0.00030 | $0.00760 |
| Haiku 4.5 | $0.00015 | $0.00380 |
Grade A, and why
ganju-cli scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 304 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Ganju CLI
Ganju Functions are tools the user writes in TypeScript or JavaScript. They
run on Cloudflare Workers inside the user's Ganju project, and every MCP client
and channel (Claude, ChatGPT, Slack, Telegram…) connected to that project can
call them. The ganju CLI builds, tests, publishes and debugs them from a
terminal.
A project is one folder:
ganju.json the tools (names, descriptions, JSON schemas) and what the code may reach
src/<tool>.ts one handler per tool: export default defineTool(async (input, ctx) => …)
src/lib/*.ts shared helpers (optional)
The whole project deploys as one script. Every version carries both the code and the tool contract, so rolling back restores both.
Before you run anything
Some steps need the person, not you. Knowing which saves a round of failed commands.
| Step | Who | Why |
|---|---|---|
npm install -g @ganju/cli (Node 20+) |
You | Or use npx @ganju/cli <command> |
ganju login |
The user | Opens a browser to sign in. Ask them to run it; in Claude Code they can type ! ganju login |
ganju link |
You, with flags | Interactive prompts fail without a terminal. Use --organization "<name or id>" --project "<name or id>". A wrong name fails with a hint listing the available ones, so a best guess is safe; otherwise ask |
ganju secret set NAME |
Preferably the user | You shouldn't see or log secret values. See Secrets |
ganju token create |
The user | Requires a browser login; a token can't mint tokens |
| Connecting Gmail/Calendar/Slack… | The user, in the dashboard | Project → Tools page. The CLI can't connect accounts |
Check where you stand with ganju whoami and ganju link --status.
For help, run ganju help. It lists every command and flag and is safe on
every version. Current releases refuse unknown flags and accept --help on
any command. Older releases silently ignored flags they didn't know, so there
ganju init --help scaffolds a project and ganju deploy --help deploys.
Don't guess flags either way: the draft-only deploy is ganju deploy --draft,
not --dry-run.
GANJU_API_TOKEN in the environment replaces the stored login (used in CI).
GANJU_API_URL or apiUrl in ganju.json points at a non-default deployment.
The default is https://api.ganju.ai.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 304 lines · 148 tokens per session scan A 4416e7d213bf
ganju-cli is a skill published in the GitHub repository MontoyaAndres/ganju (4 stars, last pushed yesterday), licensed Apache-2.0. It adds 148 tokens to every session and 3,801 once invoked, about $0.0006 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-19.
Other skills, from other repositories
run-tests
Run Embody's test suite and write new tests (Embody development).
testing
MUST READ before declaring any TouchDesigner build, fix or show done, and before any soak or performance test: the verification ladder (structure, errors, frame, motion, data, performance, soak, end to end), runsoaktest and the observer-effect rules that keep measuring from perturbing the show, the iterate-by-capture…
agent-tests
MUST READ before calling RunAgentTests or touching agent-tier test infrastructure -- these tests spawn real AI clients (Claude Code, Codex) and SPEND SUBSCRIPTION USAGE; never run casually. Tier model, async runner rationale, auth/isolation rules.
blazemeter-integrations
Comprehensive guide for BlazeMeter Integrations, including APM tools, CI/CD pipelines, and development tools. Use when working with integrations for (1) Integrating APM tools (AppDynamics, Datadog, New Relic, CloudWatch, DX APM, Dynatrace, Delphix), (2) Integrating CI/CD tools (Jenkins, GitHub Actions, GitLab CI/CD…
elicitation-scenarios
Drive the elicitation tester's scenario catalogue over the modern protocol, where input requests arrive in the tool result and are answered from the chat.
elicitation-scenarios-legacy
Drive the elicitation tester's scenario catalogue over the legacy protocol, where the server sends elicitation requests during the call instead of returning them in the result.