Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/skill-tools/skill-tools/valid-skillnpx skills add skill-tools/skill-tools --skill valid-skillgit clone --depth 1 https://github.com/skill-tools/skill-toolsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00033 | $0.00163 |
| Opus 5 | $0.00016 | $0.00081 |
| Sonnet 5 | $0.00007 | $0.00033 |
| Haiku 4.5 | $0.00003 | $0.00016 |
Grade A, and why
deploy-vercel scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Deploy to Vercel
Deploy your web application to Vercel with zero configuration.
Prerequisites
- Vercel CLI installed (
npm i -g vercel) - Authenticated with
vercel login
Steps
- Run
vercelin the project root - Follow the prompts to link your project
- Verify deployment at the provided URL
Error Handling
- Authentication failed: Run
vercel loginagain - Build failed: Check the build logs with
vercel logs
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 26 lines · 33 tokens per session scan A 467f0483cd0d
deploy-vercel is a skill published in the GitHub repository skill-tools/skill-tools (9 stars, last pushed 5mo ago), licensed Apache-2.0. It adds 33 tokens to every session and 163 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
skill-check
Validate Claude Code skills against Anthropic guidelines. Use when user says "check skill", "skillcheck", "validate SKILL.md", or asks to find issues in skill definitions. Covers structural and semantic validation. Do NOT use for anti-slop detection, security scanning, token analysis, enterprise checks, or Eval Kit…
tdd-methodoly-expert
Use when implementing features or fixing bugs with strict Test-Driven Development (TDD). Activate for coding tasks that require new functionality, refactoring, or comprehensive test coverage, especially when the user mentions TDD or Test Driven Development.
split-into-references
Use when skill-check reports body.maxlines and you need to modularize a long SKILL.md into maintainable references/.md docs after running split-body.
real-review-skill
Use when reviewing pull requests for regressions, missing tests, and release-blocking issues across multiple service boundaries.
agent-scan-guard
Use when you need to run security checks for MCP and agent workflows before merging changes in shared repositories.
content-qa
Use when reviewing long-form marketing or technical content for clarity, consistency, and executable examples before publishing.