Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Stijnman/grok-custom-skills --skill hybrid-execution-bridgegit clone --depth 1 https://github.com/Stijnman/grok-custom-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/stijnman/grok-custom-skills/hybrid-execution-bridge)<a href="https://agentmods.dev/skills/stijnman/grok-custom-skills/hybrid-execution-bridge"><img src="https://agentmods.dev/badge/skills/stijnman/grok-custom-skills/hybrid-execution-bridge/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/stijnman/grok-custom-skills/hybrid-execution-bridge"><img src="https://agentmods.dev/badge/skills/stijnman/grok-custom-skills/hybrid-execution-bridge.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00045 | $0.00649 |
| Opus 5 | $0.00023 | $0.00324 |
| Sonnet 5 | $0.00009 | $0.00130 |
| Haiku 4.5 | $0.00005 | $0.00065 |
Grade A, and why
hybrid-execution-bridge scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 55 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Hybrid Execution Bridge
Purpose
Use this skill to plan work that may span sandbox processing, user-approved local resources, connected services, and public-web research. Select the least-privileged environment for each step and keep external actions explicit.
Routing workflow
- Decompose the task into local, sandbox, connected-service, and public-web steps.
- Use sandbox tools for code, documents, data processing, and ordinary public research whenever sufficient.
- Use a local desktop bridge only after the user authorizes the scope and the bridge health check succeeds.
- Use connected services only for the accounts and operations the user has approved.
- Use responsible browsing methods; stop at login walls, CAPTCHAs, paywalls, or other access restrictions.
- Present planned external writes, uploads, messages, deployments, or publications for explicit approval before carrying them out.
- Summarize which environments were used, what data moved between them, and any limitations.
Environment selection
| Need | Preferred environment | Boundary |
|---|---|---|
| Code, files, reports, or data analysis | Sandbox | Keep data within the task workspace unless the user authorizes export. |
| Existing user session, local software, or local files | Authorized desktop bridge | Verify scope and connection health; never assume access. |
| Drive, GitHub, or other connected account | Connected-service integration | Read first; require approval for writes or publication. |
| Public web information | Browser or approved research tool | Respect access restrictions and site rules. |
Local desktop safeguards
When a user-authorized desktop bridge is needed, ask for clear permission, run its documented health check, and limit operations to the agreed files or application. Do not request or expose raw tokens in summaries. Stop immediately if the connection fails or the user revokes permission.
Error handling
| Situation | Response |
|---|---|
| Local bridge is unavailable | Continue with sandbox alternatives and state the limitation. |
| Connected service lacks authorization | Do not retry with another account; ask the user to authorize or choose a local alternative. |
| Website presents a restriction | Stop automated access and explain the permitted options. |
| External action is pending | Present scope, destination, and user-visible effect; wait for approval. |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 55 lines · 45 tokens per session scan A 53208b571a23
hybrid-execution-bridge is a skill published in the GitHub repository Stijnman/grok-custom-skills (9 stars, last pushed today), licensed MIT. It adds 45 tokens to every session and 649 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
goal-meta-skill
A guide for turning an unclear or complex task into a reviewable /goal instruction for coding agents.
workflow-to-skill
Turn a goal and existing CLI, MCP, HTTP, API, or external workflow capabilities into one reviewable reusable Agent Skill. Use when the user asks to create or revise a workflow SKILL.md without a dedicated interface for invocation or result presentation. A webpage, UI, image, or report produced as workflow output does…
rss-digest
Collect RSS or Atom sources and produce a traceable intelligence digest through the configured Weft workflow.
workflow-docs-sync
A project-documentation synchronisation workflow for rebuilding project facts from a local Git folder, GitHub repository, or current working directory, then updating core workflow documents.
workflow-to-skill-with-surface
Create or revise one reusable workflow Skill plus an optional harness-native Prompt Surface that maps a dedicated form, Page, button set, command UI, or result view to ordinary Skill messages and Harness results. Use only when the user explicitly requests a dedicated interface for invoking the Skill or presenting its…
setup-matt-pocock-skills
A setup skill that configures engineering skills for a repository, including its issue tracker, labels, and documentation layout. A repository is the project folder managed by version control.