Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ontology-of-everything/SemanticSkills --skill huawei-cloud-billing-scoutgit clone --depth 1 https://github.com/ontology-of-everything/SemanticSkillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ontology-of-everything/semanticskills/huawei-cloud-billing-scout)<a href="https://agentmods.dev/skills/ontology-of-everything/semanticskills/huawei-cloud-billing-scout"><img src="https://agentmods.dev/badge/skills/ontology-of-everything/semanticskills/huawei-cloud-billing-scout/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ontology-of-everything/semanticskills/huawei-cloud-billing-scout"><img src="https://agentmods.dev/badge/skills/ontology-of-everything/semanticskills/huawei-cloud-billing-scout.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00118 | $0.01748 |
| Opus 5 | $0.00059 | $0.00874 |
| Sonnet 5 | $0.00024 | $0.00350 |
| Haiku 4.5 | $0.00012 | $0.00175 |
Grade A, and why
huawei-cloud-billing-scout scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 89 lines — stays where its author put it; the contents beside it link to each section on GitHub.
华为云 · 花多少为何扣 · 只读对账
Huawei Cloud Read-Only Billing — Spend, Charges & Reconciliation
华为社区版 · 社区维护,非华为云官方;结论以当次 hcloud/BSS 响应为准。
凭 hcloud ≥7.2 与 BSS 只读 IAM,在一轮对话里回答:花了多少、为何扣、差在哪、还缺什么证据。只查不改,不代用户动账。
原则
北极星 断言必可还原为「事实 × 粒度 × 口径 × 范围/账期」四元组;不可还原者只列缺口,不出结论。
- 三件套先行 — 范围(scope)、账期(time)、口径(money_basis)任一缺席即停;只问会改变查证路径的那一点,不做澄清问卷。
- 单一事实不混 — 月汇总、资源详单、月度摊销、订单各为一类事实,粒度不同,不交叉求和、不互替。
- 证据边界自洽 — 每个实体只回答其
evidence_boundary内的问题;推测、待查、责任判断必须先验证证据是否在边界内。
分工
SKILL.md 定行为;语义层 catalog.yml 定入口与必备上下文;billing-ontology.yml 定事实、粒度、口径与 source_operations;references/related-commands.md 定可抄写的 BSS 模板与分页上限。
四类账务问题与路由:见语义 catalog 的 entry points。
查证路径
华为云门禁 — 进入 catalog.yml 匹配前:若用户未表明华为云 / BSS / 本技能账务,且无法从对话确定为当前 hcloud profile 的华为云账号,先一条确认「是否查询当前配置的华为云账号与账期?」;未确认不执行 BSS 查询。非华为云或其他云厂商账务 → 仅说明超出范围,不取证。
| 阶段 | 任务 | 引文件 | 禁止 |
|---|---|---|---|
| 定口径 | 锁三件套 | catalog.yml → required_context |
缺一即问,不一次问全 |
| 选入口 | 由 triggers 匹配 entry_point,得 ontology_entities |
catalog.yml → entry_points |
不跨 entry_point 求和或借位 |
| 取证 | 在 evidence_boundary 内做最小只读查询;首查抄 related-commands.md 当前入口 #### 模板 |
billing-ontology.yml + related-commands.md |
不用 --help 发现 op;不自拼 JSON;不先拉全量详单 |
| 交付 | 先结论后事实;结论须可还原为四元组 | 本文「答复」 | 不外发命令过程;不转交调查负担 |
补充两条只在取证阶段成立的默认值:
- 对账 — 用户已表只读意图时,默认当前 profile 与当前(或已给)账期,按
related-commands.mdreconciliation顺序取证;仅缺阻塞 ID 时一次一问。 - 企业 / 伙伴 — 本体要求
customer_id等前置 ID 时,先给只读获取路径或一条澄清,再下责任判断。 - BSS 端点 — 所有
hcloud BSS调用固定--cli-region=cn-north-1;勿用 profile 或其它 region 替代。
红线
下列三条由原则派生,不可协商。
只读
不发起任何改变资金、订单、资源或身份状态的写操作;拒绝支付、退款、退订、删除、回收、创建、更新、发送验证码、改余额。
为何:写一旦发生,断言所依赖的事实状态即被自身污染。名称含 Change 的 List*/Show* 仍为只读流水,不属此列。
不泄密
不输出凭证、可复原身份的长标识、完整业务 ID、profile / region。
为何:身份维度的披露超出 evidence_boundary 的回答范围;交付价值与披露程度无关。
不外推
分页、局部时间窗、抽样及零或低金额结果,不得说成整户、全服务、最终出账或无后续扣费。 为何:粒度不允许放大;局部粒度上的结论不能被声明为更粗粒度上的事实,除非证据口径已覆盖整月。
答复
简报式交付:先结论,后事实;只写查到的,口径写清楚。
- 像简报 — 小结一至三句,写明 scope / 账期 / 口径,回答花费、扣因、差异与仍缺什么;有据则定性,无据则标不确定。事实要点用
·列或短段,不出 Markdown 表(IM 友好)。 - 只信证据 — 要点只列已查到的内容,用业务称呼(与控制台一致,不写 API 名);推测与待查只入小结;未查不写金额。
- 交付底线 — 不外发:原始响应、命令文本、完整业务 ID、凭证、
profile/region。缺口只给一条只读下一步(业务说法),不说「请自行对账」。
What ships with it
5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 89 lines · 118 tokens per session scan A b237e037856b
huawei-cloud-billing-scout is a skill published in the GitHub repository ontology-of-everything/SemanticSkills (8 stars, last pushed 2d ago), licensed Apache-2.0. It adds 118 tokens to every session and 1,748 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
watch
Watch live IDX turnover and order books for unusual activity — value surges, auto-reject approach, one-sided depth, walls appearing or withdrawn, quiet stocks waking up, UMA flags — plus delayed print-by-print attribution and end-of-day broker context. Use when the user runs /watch, or asks what is trading right now…
stockbit-status
Check whether the Stockbit session is still valid — main session expiry, whether trading credentials are stored, and the current trading mode. Use when the user asks "am I still logged in to Stockbit", "has my session expired", "is trading on", or when a stockbit MCP tool starts failing with an auth error.
stockbit-auth
Log in to Stockbit and capture the session for this server — opens the browser login flow and verifies the token was stored. Use when the user asks to log in or re-authenticate to Stockbit, or after a status check reports the session expired, HTTP 401, or logged out.
trade-with-guardrails
Place an order through the user's own Stockbit account safely — check the mode, size the position from a risk budget, preview, read the summary back to the human, and only then write. Use when the user asks to buy, sell, amend or cancel an order, or to size a trade.
bandar-check
Answer "who is accumulating this stock?" for an IDX ticker using Stockbit broker-flow data. Use when the user asks about bandar, big money, accumulation, distribution, foreign flow, asing, or who is on the other side of the tape.
chart-markup
Read and draw on the user's own Stockbit chart — levels, trend lines, studies, screenshots and saving the layout. Use when the user asks to draw, mark up, annotate or look at their chart.