Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add stark-ai-de/agent-skills --skill jev-capability-advisorgit clone --depth 1 https://github.com/stark-ai-de/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/stark-ai-de/agent-skills/jev-capability-advisor)<a href="https://agentmods.dev/skills/stark-ai-de/agent-skills/jev-capability-advisor"><img src="https://agentmods.dev/badge/skills/stark-ai-de/agent-skills/jev-capability-advisor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/stark-ai-de/agent-skills/jev-capability-advisor"><img src="https://agentmods.dev/badge/skills/stark-ai-de/agent-skills/jev-capability-advisor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00053 | $0.03794 |
| Opus 5.5 | $0.00021 | $0.01518 |
| Sonnet 5.5 | $0.00011 | $0.00759 |
| Haiku 4.5 | $0.00005 | $0.00379 |
Grade A, and why
jev-capability-advisor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 135 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Jev Capability Advisor
Goal
Return a task-specific recommendation from capabilities actually available in the current client. The default general profile can recommend one to three capabilities; explicit next_skill recommends one skill without assessing remaining work. The client retains discovery, activation, permissions, and execution.
Network prerequisite
Recommendations need host-authorized HTTPS access to api.typesafe.ai:443 and
existing TypeSafe credentials. Installation, hook trust, processing consent and
network permission are separate. The user or administrator owns permissions;
the skill never edits sandbox, firewall, proxy or approval policy. Use an
applicable native approval route only when needed. A denial ends the attempt:
no alternate route, repeated prompt or automatic retry. Follow the
network and failure contract for actionable,
secret-free messages. Without usable API access, no Jev recommendation was
produced; native selection and local Inspect are not Jev advice.
The contract is the same on native Windows, macOS and Linux; WSL is a separate environment, not a prerequisite. Use the installed OS-native Python interpreter. Concrete host approval controls belong in the hook reference.
Enabled-hook entry
Hook guidance requests Recommend, general/current. First distinguish the delivered mode. A repository-adopted reminder follows the repository policy prerequisites, including adoption, scoped host-owner processing authority and qualification; it has no installer binding and must not invent one. The following bound-status and receipt steps apply to the optional installer-managed reminder. Resolve this SKILL.md from its current eligible host card. Use that exact directory for every reference and script; a repository/workspace search cannot establish whether installed support files exist. First read this copy's references/hook-integration.md, then run this copy's scripts/jev_hooks.py status with the delivered registration's --host and --scope; add --project-root only for project scope. Use absolute paths or that skill directory as the command working directory. Require an active registration and advice_consent.status: recorded; a key or native hook trust does not establish processing consent. Never install or grant consent to repair a missing prerequisite during ordinary advice.
What ships with it
19 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- agents/openai.yaml 615 B
- assets/hook-guidance.txt 1.1 KB
- assets/openai-icon.png 15 KB
- assets/openai-icon.svg 504 B
- assets/repository-hook-guidance.txt 1.2 KB
- references/contract.md 25 KB
- references/hook-catalog.md 7.5 KB
- references/hook-integration.md 41 KB
- references/network-access.md 6.6 KB
- references/session-integration.md 11 KB
- scripts/decision_cache.py 4.5 KB runs code
- scripts/hook_catalog.py 9.3 KB runs code
- scripts/https_transport.py 14 KB runs code
- scripts/index_cache.py 13 KB runs code
- scripts/jev_advisor.py 48 KB runs code
- scripts/jev_hooks.py 41 KB runs code
- scripts/jev_session.py 19 KB runs code
- scripts/retrieval.py 17 KB runs code
- scripts/routing_metadata.py 3.3 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +19 lines 5f209ae35fe0
- 3d ago Changed · +16 lines · -1 tokens per session 944d44d295f3
- 4d ago First seen · 100 lines · 54 tokens per session scan A 70d02472f8d8
jev-capability-advisor is a skill published in the GitHub repository stark-ai-de/agent-skills (5 stars, last pushed today), licensed Apache-2.0. It adds 53 tokens to every session and 3,794 once invoked, about $0.0002 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-26.
Other skills, from other repositories
cancel
Cancel an active tracked Claude Code job in this repository. Args: [job-id]. Use only when the user wants to stop a queued or running Claude Code job.
codex-conductor
Situational awareness across local Codex sessions. Use when the user says "sort out my Codex sessions", "what is Codex doing", "summarize my Codex windows", "codex conductor", or "what's running".
ralph
Persistent completion mode. Use when the user explicitly says /ralph or clearly wants you to keep iterating until the task is actually finished, repeating implement-verify-fix loops instead of stopping at partial progress.
mulmoterminal-keys
Bind keyboard shortcuts and fix keyboard/clipboard behaviour in MulmoTerminal. Writes keymap, which Settings can only add a fixed starter set to — its Keyboard shortcuts section lists every action bound or not plus a send row, read-only, with a Recommended keys block that adds this platform's starter set. Explains…
slides
A slide generator that creates PNG images for presentation decks, including simple backgrounds for spoken-video scripts and fuller layouts for standalone presentations.
typescript-project
Modern TypeScript project architecture guide for 2025. Use when creating new TS projects, setting up configurations, or designing project structure. Covers tech stack selection, layered architecture, and best practices.