Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Nimbleway/agent-skills --skill market-findergit clone --depth 1 https://github.com/Nimbleway/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/nimbleway/agent-skills/market-finder)<a href="https://agentmods.dev/skills/nimbleway/agent-skills/market-finder"><img src="https://agentmods.dev/badge/skills/nimbleway/agent-skills/market-finder/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/nimbleway/agent-skills/market-finder"><img src="https://agentmods.dev/badge/skills/nimbleway/agent-skills/market-finder.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 2 findings, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Rogue Agent · line 30 Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.Fix: Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent.
- medium Rogue Agent · line 377 Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.Fix: Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00203 | $0.04691 |
| Opus 5 | $0.00102 | $0.02346 |
| Sonnet 5 | $0.00041 | $0.00938 |
| Haiku 4.5 | $0.00020 | $0.00469 |
Grade A, and why
market-finder scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 483 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Market Finder
Market intelligence powered by Nimble Web Search Agents.
User request: $ARGUMENTS
Before running any commands, read references/nimble-playbook.md for Claude Code
constraints (no shell state, no &/wait, sub-agent permissions, communication style).
Instructions
Step 0: Preflight
Follow the transport selection + standard preflight from references/nimble-playbook.md — pick CLI or MCP at session start, then run the standard preflight calls (date calc, today, profile, memory index) in parallel.
Also simultaneously:
mkdir -p ~/.nimble/memory/{reports,market-finder/checkpoints}- Check for existing checkpoints:
ls ~/.nimble/memory/market-finder/checkpoints/ 2>/dev/null
From the results:
- CLI missing or API key unset ->
references/profile-and-onboarding.md, stop - Tag all
nimbleCLI calls:nimble --client-source nimble-agent-skills <subcommand>. MCP requests are attributed at the transport level — seereferences/nimble-playbook.md. - Profile exists -> note industry keywords if any. Apply smart date windowing from
references/nimble-playbook.md. Market-finder tweak: in quick refresh mode, skip enrichment and only discover new metros. - No profile -> fine. Market-finder doesn't require onboarding. Proceed to Step 1.
Step 1: Parse Request & Detect Mode
Parse $ARGUMENTS for business type, geography, qualifiers, and mode detection.
Mode detection
Check $ARGUMENTS for a reference list. Read references/audit-mode.md for the
full detection signals and parsing rules.
| Signal | Mode |
|---|---|
| Google Sheet URL, CSV path, or inline list of 3+ businesses | Audit |
| Explicit audit language ("audit my list", "compare against", "gap analysis") | Audit |
| No reference list provided | Discovery (default) |
If a reference list is present but intent is ambiguous, ask: "Want me to audit your list against fresh discovery, or use it as a starting point?"
If audit language is detected but no reference list is provided, ask: "You mentioned auditing — please provide your list (Google Sheet URL, CSV file path, or paste inline)." Do not proceed with Audit mode until a reference list is received.
What ships with it
5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 483 lines · 203 tokens per session scan A 874996f89ece
market-finder is a skill published in the GitHub repository Nimbleway/agent-skills (53 stars, last pushed 16d ago), licensed MIT. It adds 203 tokens to every session and 4,691 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
docs
Scale up scraping and drive interactive pages. Use batchscrape for many URLs, getbatchresults to page through async output, scrapewithactions to interact before scraping, and generatellmstxt to produce a site's AI policy file.
crawlforge-web-scraping
Scrapes web pages and returns clean Markdown, HTML, plain text, links, or metadata using CrawlForge's scrape, fetchurl, extractcontent, extracttext, extractlinks, extractmetadata, mapsite, and crawldeep tools. Use when the user wants to scrape a URL, fetch a page, get the markdown or text of a website, extract links…
crawlforge-change-tracking
Monitors web pages for changes over time with CrawlForge's trackchanges tool. Use when the user wants to track changes to a page, watch a URL, monitor competitor pricing, detect when content updates, get notified of regulation or product-availability changes, or diff a page against a saved baseline. Workflow: create a…
crawlforge-deep-research
Runs multi-source web research and autonomous question-answering with CrawlForge's deepresearch, agent, searchweb, and redditsearch tools. Use when the user wants to research a topic, do a deep dive, compare competitors, gather facts with citations, answer a question from the web, search the web, or get a synthesized…
crawlforge-getting-started
Orientation and tool-selection guide for the CrawlForge MCP server's 30 web tools. Use when the user is getting started with CrawlForge, asks which CrawlForge tool to use, how to set up the API key, how skills or the CLI work, what a tool costs in credits, or when one tool fails and a fallback is needed. Routes…
crawlforge-structured-extraction
Extracts structured JSON and analyzes content with CrawlForge's extractstructured, extractwithllm, extractembeddedstate, scrapestructured, scrapetemplate, processdocument, analyzecontent, summarizecontent, and listollamamodels tools. Use when the user wants to extract specific fields, pull data into a JSON schema…