Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add opencue/cuecards --skill nsauditor-aigit clone --depth 1 https://github.com/opencue/cuecardsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/opencue/cuecards/nsauditor-ai)<a href="https://agentmods.dev/skills/opencue/cuecards/nsauditor-ai"><img src="https://agentmods.dev/badge/skills/opencue/cuecards/nsauditor-ai.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00312 | $0.08820 |
| Opus 5 | $0.00156 | $0.04410 |
| Sonnet 5 | $0.00062 | $0.01764 |
| Haiku 4.5 | $0.00031 | $0.00882 |
Grade B, and why
nsauditor-ai scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Cloud metadata endpointmediumServer-side request forgery
One request to 169.254.169.254 can return temporary IAM credentials.
metadata endpoints (169.254.169.254) — this is SSRF protection, not a bug. Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
How it starts
The opening of the file, as written. The whole thing — 540 lines — stays where its author put it; the contents beside it link to each section on GitHub.
NSAuditor AI — Agent Skill
Version: 0.1.10 · Source: github.com/nsasoft/nsauditor-ai · npm:
nsauditor-ai· License: MIT (CE)
NSAuditor AI is a modular, AI-assisted network security audit platform with 27+ scanner plugins, CVE matching, MITRE ATT&CK mapping, and Zero Data Exfiltration by design. This skill teaches you how to operate it via MCP tools and CLI.
MCP Tools Reference
NSAuditor AI exposes tools via Model Context Protocol (stdio transport). Available tools depend on the license tier (Community / Pro / Enterprise).
Community Edition Tools (always available)
scan_host
Run a full plugin scan against a target host. Executes ALL enabled plugins in priority order (discovery → service probes → OS detection → result fusion).
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
host |
string | ✅ | — | Target hostname or IP address |
timeout |
number | ❌ | 30000 | Per-plugin timeout in ms |
Returns: { summary, host, services[], findings[] } — see references/schemas.md
Example:
{ "host": "192.168.1.1", "timeout": 10000 }
Important:
- For RFC 1918 / private IPs, the MCP server must have
NSA_ALLOW_ALL_HOSTS=1set. - The server blocks loopback (127.x, ::1), link-local (169.254.x, fe80:), and cloud metadata endpoints (169.254.169.254) — this is SSRF protection, not a bug.
- Plugins with unmet requirements auto-skip (e.g., SSH scanner skips if port 22 is closed).
list_plugins
List all available scanner plugins with metadata.
| Parameter | Type | Required | Description |
|---|---|---|---|
| (none) | — | — | — |
Returns: Array of { id, name, description, priority, protocols[], ports[], requirements }
When to use: Before a scan to understand available plugins, or to help the user select specific plugins for a targeted probe.
probe_service (Pro license required)
Run a single plugin against a specific host:port for deep-dive investigation.
What ships with it
8 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 540 lines · 312 tokens per session scan B 0193c2036b75
nsauditor-ai is a skill published in the GitHub repository opencue/cuecards (5 stars, last pushed yesterday), licensed MIT. It adds 312 tokens to every session and 8,820 once invoked, about $0.0016 per session on Opus 5. A static security scan graded it B with 1 finding (cloud metadata endpoint). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
loongsuite-pilot-insight
A reporting workflow for turning LoongSuite Pilot and AI coding-agent logs into structured reports about events, teams, data quality, development efficiency, and AI use. It defines the meaning of the log fields and the measurements used in dashboards.
loongsuite-pilot-ops
Skill "loongsuite-pilot-ops" from alibaba/loongsuite-pilot, covering loongsuite-pilot-ops, quick start, todo: add quick start commands and usage.
atomic-visual-options
Planning-phase visual comparison aid. Renders 2-4 side-by-side variants per decision dimension as a single throwaway, self-contained HTML file and captures the user's pick as typed terminal codes (e.g. "A2 B3"). Auto-fires on phrases like "show me a few options", "mock up some variants", "let me see this side by…
atomic-wiki
Conversational wiki and capture-bucket routing. Fires when the user wants a place, space, or folder for notes, research, tickets, raw dumps, or knowledge capture — checks the block in /.claude/CLAUDE.md; if the cwd is under a registered realm, creates the folder as a bucket via atomic wiki bucket add rather than a…
atomic-review
Compressed code review comments. Cuts noise from PR feedback while preserving the actionable signal. Each comment is one line: location, problem, fix. Use when user says "review this PR", "code review", "review the diff", or invokes /atomic-review. Auto-triggers when reviewing pull requests.
atomic-tdd
Test-first discipline. Auto-triggers on "let's implement X", "add feature Y", "fix bug Z", "write a test for", "implement", "build out", and similar pre-code-change phrases. Iron rule: failing test exists before production code. Skip only for pure docs/config changes with an explicit "skipped because:" note. Explicit…