Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Rubby2001/quake-skills --skill quake-skillsgit clone --depth 1 https://github.com/Rubby2001/quake-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/rubby2001/quake-skills/quake-skills)<a href="https://agentmods.dev/skills/rubby2001/quake-skills/quake-skills"><img src="https://agentmods.dev/badge/skills/rubby2001/quake-skills/quake-skills/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/rubby2001/quake-skills/quake-skills"><img src="https://agentmods.dev/badge/skills/rubby2001/quake-skills/quake-skills.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00027 | $0.13527 |
| Opus 5 | $0.00014 | $0.06764 |
| Sonnet 5 | $0.00005 | $0.02705 |
| Haiku 4.5 | $0.00003 | $0.01353 |
Grade D, and why
quake scanned grade D with 3 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Sends data to an external URLmediumData exfiltration
A POST to an outside endpoint may be telemetry or may be exfiltration; either way the mod talks to somewhere, and you should know where.
curl -X POST -H "X-QuakeToken: d17140ae-xxxx-xxx-xxxx-c0818b2bbxxx" -H "Content-Type: application/json" https://quake.360.net/api/v3/search/quake_service -d '{"query": "port: 443", "start": 0, "size": 10}' Encoded or obfuscated payloadhighSupply chain
base64 or hex that is decoded and executed hides what actually runs from anyone reading the file.
"data": "AAABAAEAICAAAAEAIADSAgAAFgAAAIlQTkcNChoKAAAADUlIRFIAAAAgAAAAIAgGAAAAc3p69AAAAplJREFUWIXt1j2IHGUYB/DfOzdnjIKFkECIVWIKvUFsIkRExa9KJCLaWAgWJx4DilZWgpDDiI0wiViIoGATP1CCEDYHSeCwUBBkgiiKURQJFiLo4d0eOxYzC8nsO9m9XcXC+8M Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -s -X POST "https://quake.360.net/api/v3/search/quake_service" \ How it starts
The opening of the file, as written. The whole thing — 1,324 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Quake 网络空间测绘
使用 360 Quake API 进行网络资产查询。需要在 MEMORY.md 中配置 API Key 后使用。
配置 API Key
首次使用前,需要在 MEMORY.md 中添加配置:
## 工具设置
### Quake API
- **API Key**: your_quake_api_key_here
获取 API Key:登录 Quake 控制台 → 个人中心 → API 管理
基础查询命令
标准查询(表格输出)
curl -s -X POST "https://quake.360.net/api/v3/search/quake_service" \
-H "X-QuakeToken: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"query":"查询语句","size":20,"start":0}' | python3 -c "
import json, sys
data = json.load(sys.stdin)
print(f\"总数: {data['meta']['pagination']['total']} 条记录\\n\")
print(f\"{'IP:端口':<22} {'服务':<12} {'国家':<10} {'城市':<15} {'组织':<30}\")
print('-' * 100)
for item in data.get('data', []):
ip_port = f\"{item.get('ip', '-')}:{item.get('port', '-')}\"
service = item.get('service', {}).get('name', 'unknown') or 'unknown'
loc = item.get('location', {})
country = loc.get('country_cn', '-') or '-'
city = loc.get('city_cn', '-') or '-'
org = item.get('org', '-') or '-'
print(f'{ip_port:<22} {service:<12} {country:<10} {city:<15} {org[:28]:<30}')
"
查看配额
curl -s "https://quake.360.net/api/v3/user/info" \
-H "X-QuakeToken: YOUR_API_KEY" | python3 -c "
import json, sys
data = json.load(sys.stdin)
print(f\"剩余配额: {data.get('data', {}).get('remaining_quota', 'N/A')}\")
"
查询字段大全
网络基础字段
| 字段 | 说明 | 示例 |
|---|---|---|
ip |
IP 地址 | ip:1.2.3.4 |
port |
端口号 | port:443 |
transport |
传输协议 | transport:tcp / transport:udp |
protocol |
应用层协议 | protocol:http / protocol:ssh |
hostname |
主机名 | hostname:www.example.com |
domain |
域名 | domain:example.com |
服务识别字段
| 字段 | 说明 | 示例 |
|---|---|---|
service |
服务名称 | service:http / service:ssh |
app |
应用名称 | app:nginx / app:apache / app:mysql |
version |
版本信息 | version:1.18.0 |
os |
操作系统 | os:linux / os:windows |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 1,324 lines · 27 tokens per session scan D 601b0796955e
quake is a skill published in the GitHub repository Rubby2001/quake-skills (5 stars, last pushed 5mo ago), licensed MIT. It adds 27 tokens to every session and 13,527 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it D with 3 findings (sends data to an external url, encoded or obfuscated payload, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…