Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add sloemo01/hermes-skills-bundle --skill research-automation-bundlegit clone --depth 1 https://github.com/sloemo01/hermes-skills-bundleWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/sloemo01/hermes-skills-bundle/research-automation-bundle)<a href="https://agentmods.dev/skills/sloemo01/hermes-skills-bundle/research-automation-bundle"><img src="https://agentmods.dev/badge/skills/sloemo01/hermes-skills-bundle/research-automation-bundle/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/sloemo01/hermes-skills-bundle/research-automation-bundle"><img src="https://agentmods.dev/badge/skills/sloemo01/hermes-skills-bundle/research-automation-bundle.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00037 | $0.00930 |
| Opus 5 | $0.00018 | $0.00465 |
| Sonnet 5 | $0.00007 | $0.00186 |
| Haiku 4.5 | $0.00004 | $0.00093 |
Grade A, and why
research-automation-bundle scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 106 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Research Automation Bundle
Overview
This skill bundles research and automation skills for comprehensive web research, OSINT, and domain-specific analysis workflows — for any topic the user wants to research.
Included Skills
| Skill | Category | Purpose |
|---|---|---|
| kimi-webbridge | automation | Browser automation via Kimi WebBridge daemon |
| deep-web-research | research | 10+ tab deep research with tab groups |
| job-search-automation | automation | Search any role across 5 platforms (LinkedIn, Indeed, Glassdoor, Naukri, Dice) |
| linkedin-automation | automation | LinkedIn people search & filtering |
| mcp-server-research | research | Find free MCP servers for any topic — data, APIs, dev tools, automation |
| osint-person-search | research | Cross-platform person profile verification (12+ platforms) |
When to Use
- User wants to research any topic comprehensively
- Job search + company research workflows
- OSINT investigations combining person search + social media + domain data
- Market research combining deep web + MCP servers + social signals
- Hiring landscape analysis across LinkedIn, X/Twitter, job boards
Usage Pattern
# Load all skills in sequence for a research workflow
skill_view(name="kimi-webbridge")
skill_view(name="deep-web-research")
skill_view(name="job-search-automation")
skill_view(name="linkedin-automation")
skill_view(name="mcp-server-research")
skill_view(name="osint-person-search")
Workflow Examples
Job Hunt + Company Research
job-search-automation— Find remote roles for [USER'S TOPIC]linkedin-automation— Research company employees & hiring managersdeep-web-research— Deep dive on target companies
OSINT Investigation
osint-person-search— Cross-platform person verificationkimi-webbridge— Browser automation for evidence collectiondeep-web-research— Multi-tab organized research
MCP Server Discovery + Domain Research
mcp-server-research— Find MCP servers for [USER'S TOPIC]deep-web-research— Market sentiment, regulatory news, docs
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 106 lines · 37 tokens per session scan A bbe072addade
research-automation-bundle is a skill published in the GitHub repository sloemo01/hermes-skills-bundle (9 stars, last pushed 1mo ago), licensed MIT. It adds 37 tokens to every session and 930 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
wstg-web-pentest
Full WSTG-aligned web application pentest — 12-phase methodology from information gathering through reporting, with concrete commands, expected outputs, pitfalls, and verification per phase.
hunt-cors
Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled origin can perform a CREDENTIALED cross-origin read of sensitive…
hunt-dom
Hunt client-side DOM vulnerabilities — DOM Clobbering (overwrite JS globals via HTML injection), PostMessage hijacking (missing origin check), Service Worker abuse (intercept requests from same-origin script), CSS Injection/Exfiltration (attribute selectors → token char-by-char via OOB), client-side template…
web-enumeration
Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect.
http2-header-impersonation
Spoof HTTP/2 SETTINGS frames and pseudo-header order per browser profile.
humanize-automation
Human-like mouse, keyboard and scroll behavior for behavioral bot bypass.