Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add SaikaAco/saika-hermes-skills --skill skill-lifecycle-managementgit clone --depth 1 https://github.com/SaikaAco/saika-hermes-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/saikaaco/saika-hermes-skills/skill-lifecycle-management)<a href="https://agentmods.dev/skills/saikaaco/saika-hermes-skills/skill-lifecycle-management"><img src="https://agentmods.dev/badge/skills/saikaaco/saika-hermes-skills/skill-lifecycle-management/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/saikaaco/saika-hermes-skills/skill-lifecycle-management"><img src="https://agentmods.dev/badge/skills/saikaaco/saika-hermes-skills/skill-lifecycle-management.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00046 | $0.02851 |
| Opus 5 | $0.00023 | $0.01425 |
| Sonnet 5 | $0.00009 | $0.00570 |
| Haiku 4.5 | $0.00005 | $0.00285 |
Grade A, and why
skill-lifecycle-management scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 280 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill Lifecycle Management
Overview
Use this umbrella whenever a task is about creating, editing, validating, publishing, consolidating, or archiving skills. Skills should capture class-level reusable procedures and experiential knowledge. They are not per-session bug logs; narrow session details belong in labeled subsections or support files under a broader umbrella.
A skill release is complete only when the public package can be consumed safely from a fresh Hermes environment and its remote bytes match the reviewed source. A successful local validator or Git push alone is not completion.
When to Use
- Writing a new
SKILL.md. - Editing frontmatter, descriptions, triggers, or related skills.
- Adding
references/,templates/,scripts/, orassets/files. - Deciding whether a local skill is focused and portable enough to publish.
- Preparing a public tap package, attribution, license notice, or catalog entry.
- Verifying a release through security scan, isolated installation, clone, and remote-byte checks.
- Consolidating narrow sibling skills into an umbrella.
- Archiving stale or absorbed skills safely.
- Debugging why a skill does not load or validate.
Required SKILL.md Shape
Minimum validator requirements:
- File starts at byte 0 with
---. - YAML frontmatter closes with a standalone
---line. - Frontmatter parses as a mapping.
nameanddescriptionare present.- Description stays within the current validator limit.
- Body after frontmatter is non-empty.
Peer-quality structure:
---
name: my-skill-name
description: "Use when <trigger class>. <what this skill helps do>."
version: 1.0.0
author: Hermes Agent
license: MIT
platforms: [linux, macos, windows]
metadata:
hermes:
tags: [short, descriptive, tags]
related_skills: [other-skill]
---
Recommended body sections: Overview, When to Use, workflow sections, Common Pitfalls, and Verification Checklist.
Placement
- User-local skills:
~/.hermes/skills/<category>/<name>/SKILL.md; create and edit withskill_manage. - Bundled/in-repo skills: repository
skills/<category>/<name>/SKILL.md; edit files directly in the repo and commit changes. - Profiles: each profile has its own skills tree under
~/.hermes/profiles/<profile>/skills/; do not modify another profile unless explicitly requested.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 280 lines · 46 tokens per session scan A f5545704b4fc
skill-lifecycle-management is a skill published in the GitHub repository SaikaAco/saika-hermes-skills (2 stars, last pushed 13d ago), licensed MIT. It adds 46 tokens to every session and 2,851 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
hunt-auth-bypass
Hunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty reports across SAML XSW / parser-differential (GitHub Enterprise CVE-2025-25291/25292), SAML signature stripping (Uber, Rocket.Chat, samlify CVE-2025-47949), SAML domain enforcement bypass via control characters (HackerOne 2024)…
m365-entra-attack
Microsoft 365 / Entra ID red-team attack chain — current 2026 reality. AADSTS code reference, user enumeration vectors (with hardening status), Smart Lockout math, Conditional Access bypass options, ROPC + SAML SSO browser flow, Burp/Playwright templates. Built from authorized red-team work where ROPC spray surfaced…
password-spray-methodology
End-to-end password spray playbook. User enumeration, lockout detection, password pattern generation, spray execution across all protocols, error code differentials, and engagement discipline. Unifies M365/Entra, Okta, Exchange, Kerberos, SharePoint, XMLRPC, OIDC, and AD SMB/WinRM spraying into one methodology.
cache-attack
Poison CDN cache or deceive when X-Cache header is detected.
hunt-django
Hunt Django-specific vulnerabilities: DRF permission gaps, ORM injection, and admin exploitation.
tianya-gods-team
A decision-making system in which 20 fictional specialist viewpoints analyze one question in parallel before a coordinating AI combines them. It covers areas such as history, economics, relationships, technology, mysteries, and culture.