Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add rp1-run/rp1 --skill analyse-securitygit clone --depth 1 https://github.com/rp1-run/rp1Wrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/rp1-run/rp1/analyse-security)<a href="https://agentmods.dev/skills/rp1-run/rp1/analyse-security"><img src="https://agentmods.dev/badge/skills/rp1-run/rp1/analyse-security/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/rp1-run/rp1/analyse-security"><img src="https://agentmods.dev/badge/skills/rp1-run/rp1/analyse-security.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00035 | $0.01423 |
| Opus 5 | $0.00017 | $0.00711 |
| Sonnet 5 | $0.00007 | $0.00285 |
| Haiku 4.5 | $0.00003 | $0.00142 |
Grade A, and why
analyse-security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 160 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Analyse Security
ROLE: Tracked workflow dispatcher. Bootstrap run tracking, pass canonical directories and resolved arguments to security-validator, register the produced report once, and stop. MUST NOT perform the security assessment directly.
Target Resolution
Before emitting the first status:
- Set
TARGET_TOPICtoTOPICwhen non-empty; otherwise set it towhole project. - Set
REPORT_IDfromFEATURE_IDwhen non-empty; otherwise derive it fromTOPIC. In both cases, normalize by lowercasing, replacing path separators, whitespace, and punctuation with-, trimming duplicate separators, and falling back toprojectif the normalized value is empty. IfTOPICis empty andFEATURE_IDis empty, setREPORT_IDtoproject. - Use
TARGET_TOPICas the assessment scope selector.FEATURE_IDis only a report grouping slug and must not narrow the assessment whenTOPICis empty. - Set
OUTPUT_PATHtosecurity/{REPORT_ID}/report.mdandOUTPUT_ABSOLUTE_PATHto{workRoot}/{OUTPUT_PATH}.
STATE-MACHINE
stateDiagram-v2
[*] --> prepare_context
prepare_context --> analyse : context_ready
analyse --> register : report_written
register --> [*] : done
On each phase transition, emit:
rp1 agent-tools emit --harness $CURRENT_HOST \
--workflow analyse-security \
--type status_change \
--run-id {RUN_ID} \
--name "Security assessment: {REPORT_ID}" \
--step {CURRENT_STATE} \
--data '{"status":"running","target":"{TARGET_TOPIC}","reportId":"{REPORT_ID}","scope":"{SECURITY_SCOPE}"}'
Terminal state register uses --data '{"status":"completed","target":"{TARGET_TOPIC}","reportId":"{REPORT_ID}","scope":"{SECURITY_SCOPE}"}'.
Governance
Role: workflow dispatcher.
Scope limits: dispatch only; no direct code scanning, report writing, or remediation.
Error degradation: missing KB directory or validator failure -> emit failed status for the current step and stop. Do not retry or produce a partial report.
Artifact contract: exactly one artifact_registered event, after the validator reports OUTPUT_PATH. Use storageRoot: "work_dir".
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 160 lines · 35 tokens per session scan A b5417589a8c0
analyse-security is a skill published in the GitHub repository rp1-run/rp1 (38 stars, last pushed yesterday), licensed Apache-2.0. It adds 35 tokens to every session and 1,423 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
skill-curator
A Chinese-language evaluator for deciding whether developer tools and agent resources are suitable for a curated collection. It checks real repositories, installation paths, activity, duplicates, and security boundaries using evidence.
git-workflow
A guide for handling Git repository work safely, including status checks, branches, commits, pushes, pull requests, and rebasing. Git is a version-control system that records code changes and coordinates work between developers.
i18n-helper
A helper for adding internationalization, which lets software show different languages and regional text. It finds user-visible text written directly in code and moves it into language files.
brainstorm
Explore ambiguous or early-stage ideas interactively — tracks wish-readiness and crystallizes into a design for wish.
refactor-advisor
A code review helper that finds common design and maintenance problems in a codebase and suggests ways to restructure the code.
acceptance-test-authoring
Use when creating or modifying acceptance tests, configuring cucumber-js or behave runners, writing or refactoring step definitions, linting executable Gherkin specs, choosing an acceptance stack, or implementing OpenSpec tasks that involve acceptance tests.