Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/nebulae/trudi/memory-analysisnpx skills add nebulae/trudi --skill memory-analysisgit clone --depth 1 https://github.com/nebulae/trudiWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.03774 |
| Opus 5 | $0.00000 | $0.01887 |
| Sonnet 5 | $0.00000 | $0.00755 |
| Haiku 4.5 | $0.00000 | $0.00377 |
Grade B, and why
memory-analysis scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Asks for rootmediumPrivilege escalation
A mod that escalates privileges can change anything on the machine, not only the project.
(`sudo su`) — some plugins require elevated privileges to resolve symbols. How it starts
The opening of the file, as written. The whole thing — 379 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill: Memory Forensics (Volatility 3 / Memory Baseliner)
Overview
Use this skill for all memory image analysis on the SIFT workstation. Always run as root
(sudo su) — some plugins require elevated privileges to resolve symbols.
Tools
| Tool | Binary | Purpose |
|---|---|---|
| Volatility 3 | /opt/volatility3-2.20.0/vol.py |
Process, network, registry, injection, and artifact extraction |
| Memory Baseliner | /opt/memory-baseliner/baseline.py |
Diff suspect image against clean baseline |
CRITICAL:
/usr/local/bin/vol.pyis Volatility 2 (Python 2) — do NOT use it. Always use the full path:/opt/volatility3-2.20.0/vol.py
Symbol Downloads: Volatility 3 downloads PDB symbol tables from Microsoft on first use per OS version. Requires internet access unless symbols are already cached locally. Test with
ping 8.8.8.8. Use--offlineto fail fast rather than hanging.
Quick Setup (Recommended)
# Add alias to avoid typing full path every command
alias vol="/opt/volatility3-2.20.0/vol.py"
# Elevate once per session — required for some plugins
sudo su
# Create output dirs before starting
mkdir -p ./analysis/memory ./exports/dumpfiles ./exports/malfind ./exports/memdump
Output renderers (use -r <renderer> flag):
| Renderer | Description |
|---|---|
quick |
Default: fast tab-separated output |
pretty |
Human-readable table with column headers (use for pstree) |
csv |
Comma-separated (pipe to file for spreadsheet analysis) |
json |
JSON output (for scripted processing) |
jsonl |
JSON Lines (one JSON object per line — stream-friendly) |
none |
Suppress output (useful for dump-only runs) |
Plugin Reference by Category
Process Enumeration
| Plugin | Method | Notes |
|---|---|---|
windows.pslist |
EPROCESS linked list walk | Fast; misses unlinked (hidden) processes |
windows.psscan |
Pool tag scan (Proc) |
Finds hidden + exited processes — use this |
windows.pstree |
EPROCESS hierarchy | Parent-child relationships |
windows.psdisptree |
Dispatcher objects | Alternative tree view |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 379 lines · 0 tokens per session scan B 8bd1d2cb15bc
memory-analysis is a skill published in the GitHub repository nebulae/trudi (52 stars, last pushed 5d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 3,774 tokens. A static security scan graded it B with 1 finding (asks for root). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…