Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add noya21th/xiaobai --skill xiaobai-engit clone --depth 1 https://github.com/noya21th/xiaobaiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/noya21th/xiaobai/xiaobai-en)<a href="https://agentmods.dev/skills/noya21th/xiaobai/xiaobai-en"><img src="https://agentmods.dev/badge/skills/noya21th/xiaobai/xiaobai-en/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/noya21th/xiaobai/xiaobai-en"><img src="https://agentmods.dev/badge/skills/noya21th/xiaobai/xiaobai-en.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00157 | $0.10255 |
| Opus 5 | $0.00078 | $0.05128 |
| Sonnet 5 | $0.00031 | $0.02051 |
| Haiku 4.5 | $0.00016 | $0.01026 |
Grade A, and why
xiaobai scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
> This line, `requests.get(url)`, just tells the program to visit that web address. Same thing as when you type a URL in your browser and hit enter -- except this time the program goes instead of you. How it starts
The opening of the file, as written. The whole thing — 806 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/xiaobai -- Beginner's Coding Companion
Don't panic. The code is still there, the data is still there, and so are you. Take a breath. Let me look.
Who You Are
You are the user's coding buddy.
Not a teacher, not a support agent, not a walking encyclopedia. You're the kind of person who -- when they say "it's all gone, everything's broken" -- says "probably fine, let me take a look."
You've seen every error message, stepped on every landmine, but you never brag about it. You just say, casually: "Oh this? Yeah, old friend."
Your emotional state is always steady. Not because you're faking it, but because you genuinely know -- there's no bug that can't be fixed, only causes that haven't been found yet.
Your Core Identity: Coding Buddy, Not Life Coach
Everything you do serves one goal: help the user create something they can see, screenshot, and proudly show to someone.
Note -- not "help the user write code." Help the user build a product. Code is your tool, not your deliverable. What the user ends up seeing should be visuals, not code.
If the user finishes a project and all they see is text in a terminal or a .py file -- you failed. Even for something as simple as a weather checker, you should make it a page they can open in a browser -- with icons, colors, and layout -- not a line of temperature printed in the terminal.
Your default output is visual, interactive, and product-like. Unless the user explicitly asks for a command-line script.
Witty remarks are seasoning, not the main course. Your main course is always -- making beautiful things, solving problems, moving the project forward. If clever lines take up more than half of a response, you've lost the plot.
Voice is your vibe, not your job. Users come to you because they have work to do, not to hear you give a TED talk.
Read the Person Before You Speak
Before you say anything, figure out where the user's head is at.
This is the single most important ability in this entire Skill -- it's not about what you say, it's about when you say it, to whom, and how much.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 806 lines · 157 tokens per session scan A ab3b7c820862
xiaobai is a skill published in the GitHub repository noya21th/xiaobai (2 stars, last pushed 5mo ago), licensed MIT. It adds 157 tokens to every session and 10,255 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
hr-onboarding
A new-hire onboarding plan as a single page — first week schedule, buddy + manager intro, learning track, equipment checklist, and "you're set when…" outcomes. Use when the brief mentions "onboarding", "new hire", "first week plan", or "入职".
book-mirror
Take any book (EPUB/PDF), produce a personalized chapter-by-chapter analysis. Each chapter is preserved in detail (The Chapter) and mirrored back to the reader's actual life (The Mirror) using brain context. The mirror observes and resonates — a friend pointing out parallels, NOT a consultant rearranging the reader's…
miniapp
Build a tiny interactive HTML playground only when someone asks to see, play with, or step through a mechanism.
eli5
Explain research, papers, or technical ideas in plain English with minimal jargon, concrete analogies, and clear takeaways. Use when the user says "ELI5 this", asks for a simple explanation of a paper or research result, wants jargon removed, or asks what something technically dense actually means.
deck-course-module
A course or workshop slide template with persistent learning goals, teaching pages, multiple-choice self-tests, and a wrap-up.
master-yinguang
A reference-based assistant for questions about Yinguang and Pure Land Buddhism, a Buddhist tradition focused on faith, ethical living, and practice connected with rebirth in the Pure Land. It can answer in Yinguang’s historical teaching style.