Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Morningstar202604/awesome-skillkit --skill baijiahao-publishergit clone --depth 1 https://github.com/Morningstar202604/awesome-skillkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/morningstar202604/awesome-skillkit/baijiahao-publisher)<a href="https://agentmods.dev/skills/morningstar202604/awesome-skillkit/baijiahao-publisher"><img src="https://agentmods.dev/badge/skills/morningstar202604/awesome-skillkit/baijiahao-publisher/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/morningstar202604/awesome-skillkit/baijiahao-publisher"><img src="https://agentmods.dev/badge/skills/morningstar202604/awesome-skillkit/baijiahao-publisher.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00018 | $0.00688 |
| Opus 5 | $0.00009 | $0.00344 |
| Sonnet 5 | $0.00004 | $0.00138 |
| Haiku 4.5 | $0.00002 | $0.00069 |
Grade A, and why
baijiahao-publisher scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
百家号 Publisher
百家号发布客户端,基于百度百家号官方开放平台 API。
功能
article-publish—— 发布文章video-publish—— 发布视频draft-save—— 保存草稿
安全设计
- 默认 dry-run:所有写操作默认只打印请求计划,不联网;加
--execute才真正发送。 - 凭据隔离:
BAIJIAHAO_ACCESS_TOKEN或BAIJIAHAO_APPID/BAIJIAHAO_APPSECRET
使用示例
export BAIJIAHAO_ACCESS_TOKEN="your_token"
python baijiahao_publisher.py article-publish --execute \
--title "我的文章" \
--content "# 标题\n正文内容..." \
--cover-images "https://example.com/cover.png" \
--tags "Python,AI" \
--category-id 1
python baijiahao_publisher.py video-publish --execute \
--title "我的视频" \
--description "视频描述" \
--video-url "https://example.com/video.mp4" \
--cover-image "https://example.com/cover.png" \
--tags "Python,AI" \
--category-id 1
python baijiahao_publisher.py draft-save --execute \
--title "草稿标题" \
--content "# 标题\n正文..."
认证
BAIJIAHAO_ACCESS_TOKEN— 直接使用 access_token- 或
BAIJIAHAO_APPID+BAIJIAHAO_APPSECRET— 需自行实现 OAuth2 刷新
export BAIJIAHAO_ACCESS_TOKEN="your_token"
# 或
export BAIJIAHAO_APPID="xxx"
export BAIJIAHAO_APPSECRET="xxx"
端点
- 文章发布:
POST https://baijiahao.baidu.com/api/article/publish - 视频发布:
POST https://baijiahao.baidu.com/api/video/publish - 草稿保存:
POST https://baijiahao.baidu.com/api/article/draft/save
退出码
0成功1API 错误或参数错误
依赖
- Python 3.8+
- 标准库
publish_common
相关技能
toutiao-publisher— 今日头条发布csdn-publisher— CSDN 发布cross-post-orchestrator— 多平台编排
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 87 lines · 18 tokens per session scan A 40d7b8a976fb
baijiahao-publisher is a skill published in the GitHub repository Morningstar202604/awesome-skillkit (1 stars, last pushed 2d ago), licensed Apache-2.0. It adds 18 tokens to every session and 688 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
yao-geo-tracking
Build a company-specific GEO backend tracking plan from a company name plus optional supporting information, using authoritative retrieval anchored on the official website, business-feature recognition, and market-aware GEO monitoring methods, then deliver a direct-vs-indirect attribution design, data model, roadmap…
yao-geo-comparison-builder
A tool for creating evidence-based Chinese brand comparison content for AI search and answer platforms. It compares a target brand with competitors, traditional approaches, or self-built solutions.
yao-geo-explainer-builder
A tool for creating detailed, evidence-based educational articles about a topic for Chinese AI search and answer platforms. It can include explanations, how-to steps, selection guidance, common mistakes, FAQs, and a glossary.
yao-geo-page-audit
Diagnose a website page or small page set for GEO readiness with authoritative public evidence, systematic page analysis, code/content/schema fixes, and four-format Chinese report delivery.
yao-geo-brand-graph
A method for building a brand entity knowledge graph from company information, websites, products, customers, people, places, evidence sources, and use cases. A knowledge graph records entities and the supported relationships between them.
yao-deepseek-crawler
Use when a user provides DeepSeek web AI-search keywords, repeat count, target entity, and entity type, then needs repeated fresh-window crawls aggregated into JSON plus a Kami HTML GEO report. Not for generic website crawling, DeepSeek API chat, SEO writing, or one-off answer generation.