Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/rudrendupaul/skillguard/vault-readernpx skills add RudrenduPaul/skillguard --skill vault-readergit clone --depth 1 https://github.com/RudrenduPaul/skillguardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/rudrendupaul/skillguard/vault-reader)<a href="https://agentmods.dev/skills/rudrendupaul/skillguard/vault-reader"><img src="https://agentmods.dev/badge/skills/rudrendupaul/skillguard/vault-reader.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00105 | $0.00260 |
| Opus 5 | $0.00053 | $0.00130 |
| Sonnet 5 | $0.00021 | $0.00052 |
| Haiku 4.5 | $0.00011 | $0.00026 |
Grade A, and why
vault-reader scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Vault Reader (SG09 fixture)
Paired with the sibling report-uploader skill in this same directory:
neither skill trips a HIGH finding on its own, but scanning the two
together with skillguard-cli scan-set should flag SG09 -- cross-skill
privilege chaining -- because this skill can reach a sensitive file and
report-uploader can send data over the network, and neither declares
per-skill sandboxing.
Run:
npx skillguard-cli scan-set ./examples/skill-set-cross-privilege
to see SkillGuard flag the combination.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 31 lines · 105 tokens per session scan A 3e715bbdf3a0
vault-reader is a skill published in the GitHub repository RudrenduPaul/skillguard (1 stars, last pushed yesterday), licensed Apache-2.0. It adds 105 tokens to every session and 260 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
outrider-experimentation
Trigger, debug, and interpret Outrider Action runs on target repos as part of Claude-Code-driven paper-to-code work. Covers manual dispatch patterns, using remyxai-cli to scope paper search, fetching run logs and RUN SUMMARY JSON to interpret outcomes, checking GitHub coordination signals (existing PRs/Issues…
remyxai
Guidance for using remyxai-cli — managing research interests, querying paper recommendations, dispatching Outrider action runs, and running batched design-review cycles. Trigger when the user mentions Outrider, GitRank, paper recommendations, remyxai commands, or research-implementation workflows against a target repo.
pastewatch
Sensitive data scanner — deterministic detection and obfuscation for text content.
migrationpilot
Check PostgreSQL DDL and migrations for lock and downtime hazards before writing or running them. Use before creating or editing any migration file, before writing CREATE INDEX / ALTER TABLE / DROP / ADD CONSTRAINT, and before running any migration command (psql, prisma migrate, alembic upgrade, flyway migrate, rails…
slop-chop
Remove AI writing tells from text with the slop-chop CLI. Use when the user wants to clean up a draft, strip em-dashes, semicolons, and stock buzzwords, enforce a spelling dialect, or make text read like a person wrote it instead of a chatbot. Also use before handing back a written draft, or to flag slop in Markdown…
immunogen
Scan an AI-built ("vibe-coded") repo for launch-blocking issues — leaked secrets, exposed API keys, broken auth, missing row-level security, unsafe payment wiring, vulnerable dependencies, and risky AI-layer surface (skills/MCP servers/agent prompts). Returns a 0-100 Ship Score with a banded verdict and ranked…