Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/oceanjustinlin/qimennpx agentmods add skills/oceanjustinlin/qimen/qimen-dunjiaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/oceanjustinlin/qimen/qimen-dunjia)<a href="https://agentmods.dev/skills/oceanjustinlin/qimen/qimen-dunjia"><img src="https://agentmods.dev/badge/skills/oceanjustinlin/qimen/qimen-dunjia/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/oceanjustinlin/qimen/qimen-dunjia"><img src="https://agentmods.dev/badge/skills/oceanjustinlin/qimen/qimen-dunjia.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00064 | $0.05870 |
| Opus 5 | $0.00032 | $0.02935 |
| Sonnet 5 | $0.00013 | $0.01174 |
| Haiku 4.5 | $0.00006 | $0.00587 |
Grade A, and why
qimen-dunjia scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 617 lines — stays where its author put it; the contents beside it link to each section on GitHub.
奇门遁甲完整推演
核心定位
使用“确定性规则引擎 + 受约束模型推理”完成奇门问事。
固定计算负责盘面事实、用神定位、格局检测、评分和应期。模型负责理解开放问题、在规则低置信时提出候选目标、综合证据并生成适合当前问题的报告。
遵守四条底线:
- 盘面事实必须来自脚本。
- 低置信目标可以由模型推导,但必须经过白名单和盘面校验。
- 模型推导目标只能有界参与评分。
- 报告结构可以自由,但关键语义不得遗漏。
默认规则集为 mainline-cn-v1:
- 时家转盘奇门
- 拆补法定局
- 中宫寄坤
- 默认时区
Asia/Shanghai
工作模式
根据请求选择一种模式:
| 模式 | 使用条件 | 是否起局 |
|---|---|---|
| 正式问事 | 判断具体事件、成败、时机、方位或行动策略 | 是 |
| 同局追问 | 继续深挖已经生成的同一局 | 否 |
| 择时择方 | 比较行动时间或方向 | 是 |
| 理论教学 | 解释规则、格局、用神或案例 | 按需 |
长期命局、先天结构和多年人生趋势通常更适合八字。用户仍明确要求奇门时,可以分析当下事件切面,但不得把一局扩大成终生命运。
总工作流
严格按以下顺序执行:
- 结构化访谈
- 问题路由
- 固定时间起局
- 规则
targetSpec解析 - 必要时进行模型
targetSpec推导 - 宫位、格局和关系计算
- 问题域极性修正
- 有界评分
- 应期扫描
- 生成唯一证据包
- 模型组织用户报告
- 校验报告的证据引用和语义覆盖
不得跳过中间步骤直接自由解盘。
第一步:结构化访谈
正式起局前确认:
- 所问事项:一句话说清具体事情。
- 起局时间:默认取“问事当下”,即提问时的北京时间,由脚本解析真实时辰,模型不得臆测时辰。仅当用户明确要为某个指定时刻复盘时,才使用该指定公历时间。
- 事件发生时间(如面试、开庭、签约时刻)属于“事项背景”,用于理解问题,不作为起局时间,除非用户明确要求按该时刻起盘。
- 所在城市或时区。
- 最想判断的结果:能否成、何时动、如何选、往哪走或避开什么。
- 当前现实进展。
- 主动方与被动方。
- 用户偏好:直接结论或详细讲解。
只有事项、时间、时区和判断目标均明确后才能正式起局。
以下情况优先追问:
- 问题过于宽泛,无法确定判断对象。
- 用户明确要求按某个指定时刻起盘,却只给了日期没有具体时辰。
- 海外地点没有时区。
- 问题涉及多件彼此独立的事情。
- 主客身份会显著改变判断,但当前语义不明确。
医疗、法律、投资、孕产、失踪等高风险主题必须提示现实专业路径。
详细访谈规则见 references/interview.md。
第二步:问题路由
运行路由脚本:
python scripts/route_question.py \
--input tmp/question.json \
--output tmp/route.json
路由结果至少包含:
{
"branch": "qimen",
"category": "career_business",
"subcategory": "job_search",
"role": "client",
"confidence": "high",
"reason": ""
}
支持的主要领域:
career_businessfinance_wealthrelationshiphealth_actionitem_transactionexam_studylawsuit_legalfengshui_housepregnancy_birthgeneral
路由遵守:
- 规则优先。
- 规则置信度低时,允许模型辅助判断领域、子类型、主客身份和核心目标。
- 用户明确要求奇门时,不因模型判断而静默切换体系。
- 关键信息缺失时返回
clarify,不要强行分类。 - 路由置信度表示分类证据质量,不表示吉凶程度。
详细分类树见 references/routing.md。
第三步:固定排盘
将访谈结果写入输入文件:
{
"question": "",
"question_goal": "",
"time_input": "",
"calendar_type": "solar",
"location": {
"country": "",
"city": "",
"timezone": ""
},
"ruleset": "mainline-cn-v1"
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 617 lines · 64 tokens per session scan A 9899bec549cc
qimen-dunjia is a skill published in the GitHub repository oceanjustinlin/qimen (24 stars, last pushed 1mo ago), licensed MIT. It adds 64 tokens to every session and 5,870 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
analyzing-ios-app-security-with-objection
Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.
argent-tv-interact
Control and inspect TV apps via argent — Apple TV (tvOS), Android TV (leanback), and Amazon Fire TV (Vega). Boot the target, read focus, navigate with the D-pad remote, type, screenshot, and on Vega debug the JS runtime (evaluate, console logs, network inspector). Use when a task targets a TV (runtimeKind "tv", or…
mastg
Autonomous mobile security audit aligned with OWASP MASTG v2. Performs checklist-driven analysis across MASVS categories: storage, crypto, network, platform, code, resilience, privacy. Exports structured markdown report with MASTG test references.
maui-auth-secure-storage
Implement MAUI auth and secure storage. USE FOR: WebAuthenticator/MSAL, OAuth/OIDC redirects, Entra ID, callback URIs, Android intent filters, CFBundleURLTypes, token cache cleanup, SecureStorage, logout, Blazor Hybrid auth handoff. DO NOT USE FOR: architecture, API retries/offline data, UI debugging.
asc-app-create-ui
Create an App Store Connect app via iris API using web session from Blitz.
maui-app-architecture
Design MAUI app architecture. USE FOR: DI/MauiProgram, MVVM page/ViewModel wiring, Shell routes/GoToAsync/query params, trim-safe IQueryAttributable, x:DataType compiled bindings, page lifetimes, avoiding service locators. DO NOT USE FOR: resources, API versioning, runtime debug tools.