Borrowing it
Nothing to install: this file belongs to piyushptiwari1/mcpkernel. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/piyushptiwari1/mcpkernel/main/.github/skills/research-and-improve/SKILL.mdgit clone --depth 1 https://github.com/piyushptiwari1/mcpkernelWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/piyushptiwari1/mcpkernel/research-and-improve)<a href="https://agentmods.dev/skills/piyushptiwari1/mcpkernel/research-and-improve"><img src="https://agentmods.dev/badge/skills/piyushptiwari1/mcpkernel/research-and-improve/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/piyushptiwari1/mcpkernel/research-and-improve"><img src="https://agentmods.dev/badge/skills/piyushptiwari1/mcpkernel/research-and-improve.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00048 | $0.00441 |
| Opus 5 | $0.00024 | $0.00220 |
| Sonnet 5 | $0.00010 | $0.00088 |
| Haiku 4.5 | $0.00005 | $0.00044 |
Grade A, and why
research-and-improve scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Research and Improve Workflow
When to Use
- Discovering and implementing latest security techniques
- Optimizing performance based on current best practices
- Upgrading protocol support (MCP, A2A)
- Adding new sandboxing or taint tracking capabilities
Procedure
Step 1: Research
- Search for latest MCP protocol specification updates
- Research current security approaches for:
- Taint analysis and information flow control
- Container sandboxing advancements
- eBPF security monitoring
- Policy engine improvements
- Look for Python async optimization techniques
- Check for new OWASP ASI guidelines
Step 2: Evaluate Applicability
- Read current MCPKernel implementation in
src/mcpkernel/ - Compare with researched techniques
- Identify improvements that:
- Fit MCPKernel's async Python architecture
- Don't break existing APIs
- Have measurable impact
Step 3: Implement
- Create a feature branch:
feature/<improvement-name> - Write tests first for the new behavior
- Implement the improvement with minimal changes
- Run full test suite:
python -m pytest tests/ -v --tb=short
Step 4: Document
- Update
docs/USAGE.mdif usage changes - Update
CHANGELOG.mdwith the improvement - Update
README.mdif it's a notable feature
Step 5: Report
Return research findings, what was implemented, and validation results.
References
- MCPKernel architecture:
src/mcpkernel/ - Configuration:
src/mcpkernel/config.py - Proxy layer:
src/mcpkernel/proxy/ - Policy engine:
src/mcpkernel/policy/ - Taint tracking:
src/mcpkernel/taint/
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 54 lines · 48 tokens per session scan A 0b5de00c821a
research-and-improve is a skill published in the GitHub repository piyushptiwari1/mcpkernel (2 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 48 tokens to every session and 441 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
skill-inspector
Review AI agent skills before installation using NVIDIA SkillSpector and source-aware semantic review. Use when asked whether a skill or downloaded skill folder is safe, trustworthy, installable, over-permissioned, or malicious.
integrate-arcjet-guard-claude-agent-sdk
Integrate Arcjet security into a Claude Agent SDK agent using @arcjet/guard — wrap tool() handlers, screen inbound prompts with UserPromptSubmit, and deny unwrapped built-in/MCP tools with PreToolUse. Use when asked to add Arcjet to a Claude Agent SDK or Claude Code agent, rate limit its tools, screen inbound…
integrate-arcjet-guard-genkit
Integrate Arcjet security into a Genkit JS agent using @arcjet/guard — wrap ai.defineTool, put guardMiddleware on generate({ use }) for unwrapped / MCP / filesystem tools, and read a caller-owned id from generate({ context }). Use when asked to add Arcjet to genkit, rate limit its tools, screen inbound messages, or…
integrate-arcjet-guard-langchain
Integrate Arcjet security into a LangChain JS createAgent using @arcjet/guard — wrap tool() / StructuredTool, put guardMiddleware on createAgent({ middleware }) for MCP / unwrapped tools, and read configurable.threadid for correlation. Use when asked to add Arcjet to langchain createAgent, rate limit its tools, screen…
integrate-arcjet-guard-langgraph
Integrate Arcjet security into a LangGraph Graph API agent using @arcjet/guard — wrap tool() / StructuredTool, wrap ToolNode for unwrapped MCP tools, and read threadid for correlation. Use when asked to add Arcjet to a LangGraph StateGraph / ToolNode agent, rate limit its tools, screen inbound messages, or block…
integrate-arcjet-guard-mastra
Integrate Arcjet security into a Mastra agent using @arcjet/guard — wrap createTool execute, screen input/output with a Processor tripwire, and gate unwrapped MCP/workspace tools with hooks. Use when asked to add Arcjet to a Mastra agent, rate limit its tools, screen inbound messages, or block prompt injection / PII.