Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/shenjingnan/xiaozhi-client/commit-push-prnpx skills add shenjingnan/xiaozhi-client --skill commit-push-prgit clone --depth 1 https://github.com/shenjingnan/xiaozhi-clientWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/shenjingnan/xiaozhi-client/commit-push-pr)<a href="https://agentmods.dev/skills/shenjingnan/xiaozhi-client/commit-push-pr"><img src="https://agentmods.dev/badge/skills/shenjingnan/xiaozhi-client/commit-push-pr.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00012 | $0.00552 |
| Opus 5 | $0.00006 | $0.00276 |
| Sonnet 5 | $0.00002 | $0.00110 |
| Haiku 4.5 | $0.00001 | $0.00055 |
Grade B, and why
commit-push-pr scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directoriesmediumAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
jq -r '.env.ANTHROPIC_MODEL' ~/.claude/settings.json What it actually says
上下文
- 当前 git 状态: !
git status - 当前 git diff(已暂存和未暂存的变更): !
git diff HEAD - 当前分支: !
git branch --show-current
Attribution 信息
每次 commit 的 body 和 PR 描述中必须附加以下 attribution 信息(使用上方上下文中的"当前模型"和"模型公司域名"):
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: <当前模型>
你的任务
根据上述变更:
- 如果当前在 main 分支,则创建一个新分支
- 使用中文创建一个包含合适提交信息的 commit,commit body 中必须包含 ## Attribution 中指定的 attribution 信息
- 将分支推送到 origin
- 使用
gh pr create创建 Pull Request,PR 描述中必须包含 ## Attribution 中指定的 attribution 信息 - 你可以在单次响应中调用多个工具。你必须在单条消息中完成上述所有操作。不要使用任何其他工具或执行任何其他操作。除了工具调用之外,不要发送任何其他文本或消息。
Commit Message 格式要求
语言要求:Commit subject、body 和 PR 描述均必须使用中文编写。
Commit message 必须以以下格式结尾:
<commit subject 和 body>
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: <模型名称> <noreply@<对应主域名>>
模型与域名映射
根据当前会话实际使用的模型,选择对应的 noreply 邮箱域名:
| 模型系列 | 域名示例 |
|---|---|
| GLM (智谱) | [email protected] |
| Claude (Anthropic) | [email protected] |
| GPT (OpenAI) | [email protected] |
| Gemini (Google) | [email protected] |
| DeepSeek | [email protected] |
| Qwen (通义) | [email protected] |
如何获取模型名称
jq -r '.env.ANTHROPIC_MODEL' ~/.claude/settings.json
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 64 lines · 12 tokens per session scan B 63c730fd7a22
commit-push-pr is a skill published in the GitHub repository shenjingnan/xiaozhi-client (337 stars, last pushed today), licensed MIT. It adds 12 tokens to every session and 552 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…