Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/pilotspace/pilot-space/generate-filenpx skills add pilotspace/pilot-space --skill generate-filegit clone --depth 1 https://github.com/pilotspace/pilot-spaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pilotspace/pilot-space/generate-file)<a href="https://agentmods.dev/skills/pilotspace/pilot-space/generate-file"><img src="https://agentmods.dev/badge/skills/pilotspace/pilot-space/generate-file.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00017 | $0.01530 |
| Opus 5 | $0.00009 | $0.00765 |
| Sonnet 5 | $0.00003 | $0.00306 |
| Haiku 4.5 | $0.00002 | $0.00153 |
Grade A, and why
generate-file scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 137 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Generate File Skill
Produce a downloadable file artifact from chat. The agent picks the format
(Markdown for portable text, HTML for styled / print-ready output), drafts the
content, then calls the create_file tool. The file appears in chat as an
inline download card and can be previewed via the Peek panel.
Phase: 87.1 (foundation — MD + HTML only). DOCX / XLSX land in 87.2; PDF in 87.3.
Quick Start
Use this skill when the user asks for any of:
- A file, an export, a download
- A "report", "summary", "doc", "spec", "README"
- A styled / printable / formatted document
- "Save this as a file" / "give me a downloadable version"
- A standalone deliverable (resume, proposal, meeting notes, retro doc)
Format Choice
Strict decision rule — pick exactly one based on intent:
Use md when… |
Use html when… |
|---|---|
| Content is editable / portable plain text | Output needs visual styling or layout |
| User will paste into another markdown surface (notes, GitHub, Slack) | User wants a print-ready or shareable rendered doc |
| Headings, bullet lists, code blocks are enough | Tables need cell styling, page breaks, color, custom fonts |
| Examples: specs, READMEs, summaries, meeting notes, brain-dump exports | Examples: status report, formatted retrospective, styled receipt, dashboard snapshot |
When uncertain, prefer md — it is portable and the user can always export to
HTML later. Do not invent other formats; this phase only supports md and
html.
Tool Reference
create_file(
filename: string, # suggested name; sanitised server-side
content: string, # UTF-8 body, must be non-empty and ≤ 10 MB encoded
format: "md" | "html"
)
Returns: { artifact_id, filename, mime_type, size_bytes, format }.
Constraints
- Max 10 MB per file. Content over the limit is rejected with
FILE_TOO_LARGEbefore any storage I/O. - Filename is sanitised server-side. Path components (
../etc/...), control characters, and unsafe characters are stripped. The extension is forced to matchformat, so the agent cannot smuggle e.g.report.exe.md. - Empty content is rejected with
EMPTY_FILE. - MIME map is server-controlled.
format='md'maps totext/markdown,format='html'totext/html. The model cannot override the MIME type. - Auto-executes without approval prompt. This is an intentional UX
deviation from
create_note/create_issue(which require approval). Rationale: file generation is non-destructive content creation the user explicitly requested in conversation; the file is private to the requester until they share it. Document this when explaining the action to the user ("I generated the file — here's the download"). - HTML rendered in a sandboxed iframe on preview. Do NOT include
<script>tags, external script references, orjavascript:URLs in HTML content — the preview iframe explicitly does not allow scripts.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 137 lines · 17 tokens per session scan A 36be7162796e
generate-file is a skill published in the GitHub repository pilotspace/pilot-space (2 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 17 tokens to every session and 1,530 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
instrument-data-to-allotrope
Convert laboratory instrument output files (PDF, CSV, Excel, TXT) to Allotrope Simple Model (ASM) JSON format or flattened 2D CSV. Use this skill when scientists need to standardize instrument data for LIMS systems, data lakes, or downstream analysis. Supports auto-detection of instrument types. Outputs include full…
baoyu-youtube-transcript
Downloads YouTube video transcripts/subtitles and cover images by URL or video ID. Supports multiple languages, translation, chapters, and speaker identification. Caches raw data for fast re-formatting. Use when user asks to "get YouTube transcript", "download subtitles", "get captions", "YouTube字幕", "YouTube封面"…
feishu
Work with Feishu or Lark bots, docs, sheets, bitables, approval flows, and OpenAPI/MCP setup without hardcoding credentials.
read
Reads URLs and PDFs by fetching source content, defaulting to concise summaries for plain read requests and clean Markdown when asked to convert, save, quote, cite, or feed downstream work. Use when users ask in any language to read, fetch, check, summarize, quote, cite, convert, or save a URL or PDF. Not for local…
overleaf-sync
Two-way sync between a local paper directory and an Overleaf project, so ARIS audit/edit workflows stay on the local copy while collaborators edit in the Overleaf web UI. Use when user says "同步 overleaf", "overleaf sync", "推送到 overleaf", "connect overleaf", "Overleaf 桥接", "pull overleaf", "push overleaf", or wants to…
pdf-verification-cli
Verify PDF page count and content using command-line tools when Python libraries unavailable.