Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add open-octo/octo-agent --skill config-setupgit clone --depth 1 https://github.com/open-octo/octo-agentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/open-octo/octo-agent/config-setup)<a href="https://agentmods.dev/skills/open-octo/octo-agent/config-setup"><img src="https://agentmods.dev/badge/skills/open-octo/octo-agent/config-setup/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/open-octo/octo-agent/config-setup"><img src="https://agentmods.dev/badge/skills/open-octo/octo-agent/config-setup.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00117 | $0.03212 |
| Opus 5 | $0.00059 | $0.01606 |
| Sonnet 5 | $0.00023 | $0.00642 |
| Haiku 4.5 | $0.00012 | $0.00321 |
Grade C, and why
config-setup scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Harvests environment variableshighData exfiltration
Enumerating or grepping the environment for keys collects credentials unrelated to what the mod says it does.
3. **Collect the API key.** Ask for it once, never echo it back. If the user Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
on the running octo server at `http://localhost:<port>` (use `curl` via the `terminal` tool — do NOT use `web_fetch`, localhost is blocked by SSRF). How it starts
The opening of the file, as written. The whole thing — 356 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Configure octo
Your job is to turn "I need my agent to use model X" or "change setting Y" into a working configuration through octo's REST API. Not every user knows where settings live — briefly explain when needed.
Two categories of configuration
Agent Defaults Endpoints & Models
───────────────── ───────────────────
reasoning_effort provider selection
permission_mode API key
show_reasoning base URL (advanced)
coauthor model names
workspace_dir default / lite model
All of these live in ~/.octo/config.yml and are editable through the REST API
on the running octo server at http://localhost:<port> (use curl via the terminal tool — do NOT use web_fetch, localhost is blocked by SSRF).
Reaching the server
The server listens on 127.0.0.1:8088 by default (the desktop app's built-in
server uses the same port). Loopback requests need no access key.
- Try the default first:
curl -s http://127.0.0.1:8088/api/config. JSON back = you're connected; skip the rest of this section. - Connection refused? The server may be on a custom port:
- Started as a daemon (
octo serve -d):cat ~/.octo/serve.pidfor the PID, then find its listen port — macOS/Linux:lsof -iTCP -sTCP:LISTEN -P -n -a -p <PID>; Windows (PowerShell):Get-NetTCPConnection -State Listen -OwningProcess <PID>. - A foreground
octo servewrites no pid file — ask the user which port they started it on (it's also in the web UI's address bar).
- Started as a daemon (
- No server running at all? Don't stop — fall back to editing
~/.octo/config.ymldirectly (it is the same file every API call below mutates). Read the file first, apply the smallest edit that matches the structure you see, then validate withocto doctor. Changes are picked up by new CLI sessions and by the server next time it starts.
Agent Defaults
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 356 lines · 117 tokens per session scan C 11d91d1b1409
config-setup is a skill published in the GitHub repository open-octo/octo-agent (97 stars, last pushed today), licensed MIT. It adds 117 tokens to every session and 3,212 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it C with 2 findings (harvests environment variables, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
ha-mac-control
Hope Agent native macOS desktop control — the standard maccontrol status / diagnostics / apps / dock / spaces / snapshot / visual / windows / menu / clipboard / dialog loop, target-first action rules, no-blind-coordinate policy, and recovery for stale AX/window/menu/dialog state. Load whenever using maccontrol, or…
ha-skill-creator
Create, edit, improve, or audit Hope Agent skills. Use when the user wants to: (1) create a new skill from scratch, (2) edit or improve an existing skill, (3) review or clean up a SKILL.md file, (4) run evaluations to test skill effectiveness, (5) optimize skill descriptions for better trigger accuracy. Trigger…
ha-browser
Hope Agent browser automation — the standard status → tabs → snapshot → act loop, stale-ref recovery rules, and what to do when login / 2FA / captcha / camera-prompt / dialog blocks progress. Load this skill whenever you reach for the browser tool. Trigger on: user asks the agent to open / control / click / scrape /…
ha-logs
A read-only troubleshooting skill for querying Hope Agent’s local SQLite databases, which store logs, conversations, and background-job status.
ha-pet-import
Safely import, select, switch, or enable a compatible desktop pet in Hope Agent. Resolve packages from any origin, including local folders, zip archives, pet.json plus a sprite, PNG/WebP atlases, chat attachments, repository or cloud files, direct HTTPS artifact URLs, and download pages. Use whenever a user asks to…
feishu
A toolkit for working with Feishu, also called Lark, a workplace collaboration platform. It covers documents, spreadsheets, files, wikis, approvals, calendars, and contacts.