Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add pitimon/8-habit-ai-dev/plugin install 8-habit-ai-devWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pitimon/8-habit-ai-dev/security-check)<a href="https://agentmods.dev/skills/pitimon/8-habit-ai-dev/security-check"><img src="https://agentmods.dev/badge/skills/pitimon/8-habit-ai-dev/security-check.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00051 | $0.01120 |
| Opus 5 | $0.00026 | $0.00560 |
| Sonnet 5 | $0.00010 | $0.00224 |
| Haiku 4.5 | $0.00005 | $0.00112 |
Grade A, and why
security-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 105 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Security Check (ตรวจความปลอดภัย)
Habit: H1 — Be Proactive | Anti-pattern: Bundling security into general code review where it competes for attention
Why a Separate Skill
Cognitive load research confirms: reviewing for 5 concerns simultaneously degrades all of them. Security deserves its own focused lens — the Security Champions model (Shopify, Atlassian) outperforms bundled review.
Process
-
Get the scope:
git diff --name-onlyor the files/directory specified. -
Auth & Access Control (CRITICAL):
- New endpoints require auth (unless explicitly public)
- Access control uses role/permission checks, not just "is logged in"
- No privilege escalation paths (user A accessing user B's data)
- Verify: search for auth middleware and protect guards in changed files
-
Secrets & Credentials (CRITICAL):
- No hardcoded keys, tokens, or credentials in source code
- Secrets loaded from environment variables
- No secrets in comments, logs, or error messages
- Verify: use Grep tool to search for secret patterns in changed files
-
Input Handling (HIGH):
- All user input validated (type, length, format)
- Database queries use parameterized statements (no string interpolation)
- HTML output escaped (XSS prevention)
- File uploads validated (type, size, content)
- Verify: search for innerHTML, dangerouslySetInnerHTML, exec(), eval()
-
Data Protection (HIGH):
- Sensitive data not logged (credentials, PII)
- API responses don't over-expose data (no SELECT *)
- Error messages don't leak internal details or stack traces
- Verify: search for debug print statements in production code paths
-
Infrastructure (MEDIUM):
- HTTPS enforced for external communication
- CORS configured restrictively (not wildcard)
- Rate limiting on auth endpoints
- Content security policy headers configured
- Alerting/email templates, SMTP settings, webhooks, notification links, Docker/Kubernetes/Compose/Swarm config, and env/secret interpolation do not expose secrets or widen runtime access
- Verify mounted config paths, rendered templates, and live source-of-truth when config can drift from repo state
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 105 lines · 51 tokens per session scan A 29a0323ee1d8
security-check is a skill published in the GitHub repository pitimon/8-habit-ai-dev (3 stars, last pushed 1mo ago), licensed MIT. It adds 51 tokens to every session and 1,120 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
crap-analyzer
Use to produce a risk-based refactor + test plan for recently-changed code on a diff/branch/PR by computing CRAP (complexity × untested) on changed methods. Multi-language — TypeScript, JavaScript, Python, Java, Kotlin, Go, Ruby, C#, Rust, PHP — auto-discovers how the repo generates coverage. Triggers …
challenge
Adversarial review — Fable 5 stress-tests reasoning, Gemini checks knowledge. Use before plan or architecture decisions.
review
Business review — weekly health check, monthly close, or ad-hoc audit. Subcommands: weekly, monthly, check. Use for periodic reviews or metrics assessment.
nextjs-patterns
Next.js App Router — Server Components, Actions, streaming, caching. Use when building or migrating Next.js apps.
rust-skills
Rust best practices — 179 rules across 14 categories for idiomatic, optimized Rust code.
sitrep
Situational awareness — where am I, what was I doing, what's next. Context recovery after compression, confusion, or mid-session reorientation.