Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add naveedharri/benai-skills/plugin install agentic-osWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/naveedharri/benai-skills/os-mcp)<a href="https://agentmods.dev/skills/naveedharri/benai-skills/os-mcp"><img src="https://agentmods.dev/badge/skills/naveedharri/benai-skills/os-mcp/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/naveedharri/benai-skills/os-mcp"><img src="https://agentmods.dev/badge/skills/naveedharri/benai-skills/os-mcp.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00115 | $0.01716 |
| Opus 5 | $0.00057 | $0.00858 |
| Sonnet 5 | $0.00023 | $0.00343 |
| Haiku 4.5 | $0.00012 | $0.00172 |
Grade A, and why
os-mcp scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl https://<the-domain>/health How it starts
The opening of the file, as written. The whole thing — 177 lines — stays where its author put it; the contents beside it link to each section on GitHub.
OS MCP — Railway Deploy
This skill deploys the Relay MCP v2 server to the user's own Railway account. The MCP source is bundled at ${CLAUDE_PLUGIN_ROOT}/skills/os-mcp/reference/relay-mcp-server/ — copy from there, do not fetch from anywhere else. The deployed server lets Claude clients (Claude Code or claude.ai) read/write the user's Obsidian vault by talking to the Relay.md sync protocol.
What the user provides
One thing: a Railway account token — created at https://railway.com/account/tokens.
That's it. After deploy, the user signs in with their Relay.md credentials via OAuth; the MCP then auto-discovers their relay vault and the folders inside it via PocketBase. No vault GUIDs, no folder maps.
Values set automatically by the skill
| Var | Source | Value |
|---|---|---|
RELAY_API_URL |
preset | https://api.system3.md |
PB_AUTH_URL |
preset | https://auth.system3.md |
PB_COLLECTION |
preset | users |
DATA_DIR |
preset | /data |
PORT |
preset | 3000 |
JWT_SECRET |
auto-generated | openssl rand -hex 32 |
STATIC_MCP_BEARER |
auto-generated | openssl rand -hex 24 |
ALLOWED_EMAILS |
preset | blank (any authenticated Relay.md user) |
RELAY_AUTH_TOKEN |
preset | blank (OAuth-only; no static fallback) |
RELAY_ID |
not set | auto-discovered at runtime per user |
PUBLIC_URL |
derived | from railway domain after first deploy |
Save the generated STATIC_MCP_BEARER in the chat for the user — they'd use it for any CLI/script access bypassing OAuth.
If the user has multiple Relay vaults, the MCP auto-picks the first one. They can call the vault_relays tool after connecting to see which is active and pin a different one by setting RELAY_ID in railway variables.
Workflow
Execute in order. Confirm each step before moving on.
Step 1 — Verify Railway CLI
railway --version
If missing:
- macOS:
brew install railway - Anywhere:
npm i -g @railway/cli
What ships with it
20 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- reference/relay-mcp-server/.env.example 823 B
- reference/relay-mcp-server/AUTH.md 4.4 KB
- reference/relay-mcp-server/Dockerfile 216 B
- reference/relay-mcp-server/package-lock.json 94 KB
- reference/relay-mcp-server/package.json 676 B
- reference/relay-mcp-server/railway.json 267 B
- reference/relay-mcp-server/src/auth/clients.ts 1.3 KB runs code
- reference/relay-mcp-server/src/auth/codes.ts 1.6 KB runs code
- reference/relay-mcp-server/src/auth/jsonfile.ts 692 B runs code
- reference/relay-mcp-server/src/auth/pending.ts 2.0 KB runs code
- reference/relay-mcp-server/src/auth/pocketbase.ts 2.4 KB runs code
- reference/relay-mcp-server/src/auth/provider.ts 14 KB runs code
- reference/relay-mcp-server/src/auth/refresh-loop.ts 1.6 KB runs code
- reference/relay-mcp-server/src/auth/sessions.ts 3.1 KB runs code
- reference/relay-mcp-server/src/auth/tokens.ts 2.2 KB runs code
- reference/relay-mcp-server/src/config.ts 1.5 KB runs code
- reference/relay-mcp-server/src/index.ts 21 KB runs code
- reference/relay-mcp-server/src/relay-client.ts 19 KB runs code
- reference/relay-mcp-server/tsconfig.json 361 B
- scripts/.gitkeep 0 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 177 lines · 115 tokens per session scan A 4fbbc5fb0a35
os-mcp is a skill published in the GitHub repository naveedharri/benai-skills (61 stars, last pushed today), licensed MIT. It adds 115 tokens to every session and 1,716 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
dell-idrac-bmc-ops
Bring a Dell PowerEdge BMC (iDRAC) onto the network headlessly, standardize its baseline settings, stage its firmware, and drive an unattended Proxmox/Linux install through it — including generation-specific Redfish/racadm gotchas, the identity-before-power-action rule, and the phantom-drive failure mode caused by…
terrakube-ops
Operate self-hosted Terrakube (remote OpenTofu/Terraform plan/apply, state, and workspace locking) — the canonical login/plan/apply workflow, why a targeted apply is dangerous, workspace lock recovery, the offline-mirror gotcha, and the token-rotation trap. Use when running or observing a Terrakube plan/apply…
openbao-dynamic-aws-creds
Replace a static AWS access key on a workstation or CI runner with short-lived STS credentials minted on demand by OpenBao's (or Vault's) AWS secrets engine, via an AWS credentialprocess wrapper. Covers the architecture, bring-up order, verification, plugin-upgrade caution, and common failure modes. Use when a…
homelab-runbooks
Use when powering on a sleeping DR node, converging DNS records for a new ingress vhost, or bringing up OpenBao/Terrakube JWT identity — homelab operational runbooks for power management, DNS, and secrets-engine bring-up.
llm-router-ops
Operate a self-hosted OpenAI-compatible LLM router/proxy (e.g. LiteLLM) in front of one or more backends — the minimal client-wiring block for every client type, the context-window advertisement gotcha, the env-vs-persisted-config gotcha, and why an unauthenticated health probe should 401, not 200. Use when wiring a…
proxmox-cluster-ops
Operate a Proxmox VE cluster safely — read-only inspection with pvesh/pct/qm/pvecm instead of hand-editing a live guest, node-by-node package updates that respect quorum, and the shape of joining a new node to an existing cluster. Use when inspecting cluster or guest state, planning a rolling update across cluster…