Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Morningstar202604/awesome-skillkit --skill oschina-publishergit clone --depth 1 https://github.com/Morningstar202604/awesome-skillkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/morningstar202604/awesome-skillkit/oschina-publisher)<a href="https://agentmods.dev/skills/morningstar202604/awesome-skillkit/oschina-publisher"><img src="https://agentmods.dev/badge/skills/morningstar202604/awesome-skillkit/oschina-publisher/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/morningstar202604/awesome-skillkit/oschina-publisher"><img src="https://agentmods.dev/badge/skills/morningstar202604/awesome-skillkit/oschina-publisher.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00019 | $0.00741 |
| Opus 5 | $0.00010 | $0.00370 |
| Sonnet 5 | $0.00004 | $0.00148 |
| Haiku 4.5 | $0.00002 | $0.00074 |
Grade A, and why
oschina-publisher scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
开源中国 Publisher
开源中国发布客户端,支持两种模式:
- 官方开放平台 API —— 博客发布,需申请 AppKey
- Web 内部 API —— 问答/动态发布,仅需 Cookie
功能
blog-publish—— 发布博客(官方 API)question-ask—— 提问(Web 内部 API)dynamic-post—— 发布动态(Web 内部 API)
安全设计
- 默认 dry-run:所有写操作默认只打印请求计划,不联网;加
--execute才真正发送。 - 凭据隔离:
- 官方 API:
OSCHINA_ACCESS_TOKEN - Web API:
OSCHINA_COOKIE环境变量或--cookie-file
- 官方 API:
使用示例
# 博客发布(官方 API)
export OSCHINA_ACCESS_TOKEN="your_token"
python oschina_publisher.py blog-publish --execute \
--title "我的博客" \
--content "# 标题\n正文内容..." \
--tags "Python,AI" \
--catalog 123
# 问答(Web Cookie)
export OSCHINA_COOKIE="your_cookie"
python oschina_publisher.py question-ask --execute \
--title "如何解决某问题?" \
--content "详细描述..." \
--tags "Python,异步编程"
# 动态发布
python oschina_publisher.py dynamic-post --execute \
--content "发个动态 #话题#" \
--images "https://example.com/img1.png"
端点核对(首次使用必做)
Web 内部 API 无官方文档,端点可能随时变更。首次使用前请在浏览器 DevTools 核对。
当前端点(需核对):
- 博客发布:
POST https://www.oschina.net/action/openapi/blog/add - 提问:
POST https://www.oschina.net/action/api/question/add - 动态:
POST https://www.oschina.net/action/api/dynamic/add
认证
官方 API:OSCHINA_ACCESS_TOKEN
Web 内部 API:OSCHINA_COOKIE 或 --cookie-file
export OSCHINA_COOKIE="your_cookie"
# 或
python oschina_publisher.py question-ask --cookie-file ~/.oschina_cookie ...
退出码
0成功1API 错误或参数错误
依赖
- Python 3.8+
- 标准库
publish_common
相关技能
v2ex-publisher— V2EX 发帖segmentfault-publisher— SegmentFault 发布douban-publisher— 豆瓣发布cross-post-orchestrator— 多平台编排
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 94 lines · 19 tokens per session scan A 533ca39b5801
oschina-publisher is a skill published in the GitHub repository Morningstar202604/awesome-skillkit (1 stars, last pushed 2d ago), licensed Apache-2.0. It adds 19 tokens to every session and 741 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
yao-geo-tracking
Build a company-specific GEO backend tracking plan from a company name plus optional supporting information, using authoritative retrieval anchored on the official website, business-feature recognition, and market-aware GEO monitoring methods, then deliver a direct-vs-indirect attribution design, data model, roadmap…
yao-geo-comparison-builder
A tool for creating evidence-based Chinese brand comparison content for AI search and answer platforms. It compares a target brand with competitors, traditional approaches, or self-built solutions.
yao-geo-explainer-builder
A tool for creating detailed, evidence-based educational articles about a topic for Chinese AI search and answer platforms. It can include explanations, how-to steps, selection guidance, common mistakes, FAQs, and a glossary.
yao-geo-page-audit
Diagnose a website page or small page set for GEO readiness with authoritative public evidence, systematic page analysis, code/content/schema fixes, and four-format Chinese report delivery.
yao-geo-brand-graph
A method for building a brand entity knowledge graph from company information, websites, products, customers, people, places, evidence sources, and use cases. A knowledge graph records entities and the supported relationships between them.
yao-deepseek-crawler
Use when a user provides DeepSeek web AI-search keywords, repeat count, target entity, and entity type, then needs repeated fresh-window crawls aggregated into JSON plus a Kami HTML GEO report. Not for generic website crawling, DeepSeek API chat, SEO writing, or one-off answer generation.