Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add SummerSec/SumSec-Skills --skill sumsec-illustrationsgit clone --depth 1 https://github.com/SummerSec/SumSec-SkillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/summersec/sumsec-skills/sumsec-illustrations)<a href="https://agentmods.dev/skills/summersec/sumsec-skills/sumsec-illustrations"><img src="https://agentmods.dev/badge/skills/summersec/sumsec-skills/sumsec-illustrations.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00316 | $0.03381 |
| Opus 5 | $0.00158 | $0.01690 |
| Sonnet 5 | $0.00063 | $0.00676 |
| Haiku 4.5 | $0.00032 | $0.00338 |
Grade A, and why
sumsec-illustrations scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 135 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SumSec Observer 正文配图
核心定位
为 sumsec.me 风格中文文章设计和生成 16:9 横版正文配图,也可产出单张图的生成 prompt 或修改建议。目标不是做商业插画、PPT 信息图或可爱卡通,而是把安全研究、AI Agent、Skill 仓库、工具链和工程实践里的关键判断、流程、结构、状态或隐喻,变成一张清爽、冷幽默、有记忆点、可读但不说明书的手绘解释图。
默认人物角色是“SumSec Observer”:SumSec 在白纸工程草图里的个人化分身。它是克制、冷静、长期写 sumsec.me、做安全研究、Agent 工程和个人 Skill 仓库的人,而不是品牌吉祥物。${CLAUDE_SKILL_DIR}/assets/sumsec-observer-target.png 是 SumSec Observer 的人物生成形象模板图;所有实际生图/重生成都必须参考它来约束人物一致性。生成正文配图时可以换构图,但不要重设计角色。
稳定外观必须贴近目标图:年轻成人比例、自然挺直的脊背与稳定站姿、深炭干净轮廓线、少量发丝线、深墨或深棕黑短发、略凌乱侧分、柔软碎发压住部分额头、细框眼镜、窄而清醒的低情绪眼神、安静克制的轻微工作疲惫感、干净下颌、无胡子/胡茬/小胡子。稳定服装与物件必须保留:浅冷灰高领轻量连帽夹克、暗青蓝内衬和拉绳、黑色内搭、深色裤子、胸前暗青蓝斜挎包带、侧身灰褐工具包、黑色夹板/平板、日志纸、便签、小夹子、细小青蓝线缆、红橙证据标签、小工作证式 SummerSec 铭牌、两枚青蓝 S 戒指和一个黑色 S 工具芯片。人物本身不能只是黑白线稿;默认要有克制的色彩锚点:浅冷灰夹克、暗青蓝内衬/包带、很浅的暖肤色面部与手部、深墨色头发、灰褐工具包。SummerSec 铭牌默认优先做成胸前工作证/调查牌,挂在胸前拉链旁、夹克胸口或斜挎包带经过胸前的位置;全身构图中可移到工具包或卡扣,但仍要小而可读。SummerSec 徽记以人物手指上的两个低调 S 徽记戒指作为固定识别件出现,也可作为工具芯片、证据封签或小铭牌参与结构,但不能取代人物。
先读这些参考
按任务需要读取,不要一次塞满上下文;工具调用语义中以 ${CLAUDE_SKILL_DIR} 为根定位资源。
${CLAUDE_SKILL_DIR}/references/style-dna.md:风格 DNA、颜色、文字、禁忌。${CLAUDE_SKILL_DIR}/references/sumsec-observer.md:SumSec Observer 的个人形象、稳定外观、动作库和禁忌。${CLAUDE_SKILL_DIR}/references/composition-patterns.md:结构类型、原创隐喻方法和反复刻规则。${CLAUDE_SKILL_DIR}/references/prompt-template.md:单张生图提示词模板。${CLAUDE_SKILL_DIR}/references/qa-checklist.md:生成后检查和迭代规则。${CLAUDE_SKILL_DIR}/assets/sumsec-observer-target.png:SumSec Observer 人物生成形象模板图;优先提取表情、发型、夹克结构、暗青蓝包带、工具包、夹板、日志纸、证据牌、戒指、工具芯片与设定图信息密度。只要进入“实际生成图片 / 重生成图片 / 局部改图后输出成图”流程,就必须参考这张图来保持人物情绪、衣服物件系统和身份锚点;若当前生图工具支持参考图输入,优先把它一起提供给工具,但这不是硬门槛。生成正文配图时不要复刻整张 character sheet 布局;用户明确要“角色设定图 / 个人形象 prompt / 提取图片提示词”时,可复用“大半身 + 3/4 工作姿态 + 小图标形态 + 戒指/工具芯片 callout”的设定图结构。 不要依赖旧案例图生成角色;本 skill 当前以文字规则定义 SumSec 专属人物角色。
工作流
1. 消化正文
先读用户给的正文、链接、Notion 页面、Markdown 文件或截图内容。提炼:
- 核心观点是什么
- 哪些段落承担认知转折
- 哪些内容适合用图解释
- 哪些地方只适合文字,不需要图
不要平均配图。优先选择“认知锚点”,例如:核心判断、两个断点、输入输出闭环、分流、前后对比、一鱼多吃、承接路径、常见坑、角色状态变化。
2. 判断输出类型
- 用户说“分析怎么配图 / 哪些地方需要配图 / shot list”:只输出配图策略,不生成图片。
- 用户说“给我 prompt / 优化个人形象 prompt / SumSec Observer 设定 / 设计一套人物形象 / 提取这张图的提示词”:输出可直接用于生图的角色 prompt、character sheet prompt 或单图 prompt,优先读取
${CLAUDE_SKILL_DIR}/references/sumsec-observer.md与${CLAUDE_SKILL_DIR}/references/prompt-template.md。如果用户给的是${CLAUDE_SKILL_DIR}/assets/sumsec-observer-target.png或同类角色设定图,使用“角色设定图提示”分支:保留大半身、3/4 工作姿态、小图标形态、双 S 戒指、工具芯片、手写 callout、冷灰夹克、暗青蓝包带、工具包和工作中气质;说明这是基于画面反推的稳定 prompt,不要声称是原始 prompt。若后续真的执行生图,仍必须参考${CLAUDE_SKILL_DIR}/assets/sumsec-observer-target.png;若工具支持参考图输入,可一并传入,但不是强制。 - 用户给参考图并说“提取人物特征 / 基于这个角色 / 增加铭牌”:先提取可复用人物锚点,再把变化写成局部增量;优先保持深色凌乱短发、细框眼镜、冷灰夹克、暗青蓝包带、斜挎工具包、双 S 戒指和胸前工作证式
SummerSec铭牌,不把参考图里的标题、布局说明或边角小样照搬到成图。 - 用户说“生成 / 输出 / 做图 / 帮我生成”:直接生成图片,不停下来等确认。
- 用户给已有图并说“去标题 / 改图 / 更像 SumSec”:给局部编辑或重生成 prompt,优先保持构图,只修问题。
What ships with it
7 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 135 lines · 316 tokens per session scan A d48f71eb20c4
sumsec-illustrations is a skill published in the GitHub repository SummerSec/SumSec-Skills (8 stars, last pushed 23d ago), licensed Apache-2.0. It adds 316 tokens to every session and 3,381 once invoked, about $0.0016 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
gpt-image-2-style-library
Choose GPT-Image2 / gpt-image-2 visual styles and industrial prompt templates from the awesome-gpt-image-2 style library. Use when an agent needs to create, rewrite, classify, or improve image-generation prompts with repository-backed templates, categories, style tags, scene tags, pitfalls, and example cases.
dsh-web-pet-developer
Create a pet for the dsh-pet plugin and integrate it into the dsh web GUI — author a v2 pet.json manifest plus an 8-column x 9-row atlas per the Codex/hatch-pet contract (live2d pets, voice packs and status decorations included), drop it into the pet-center user directory or contribute it as a built-in asset under…
superdesign
Design or redesign frontend UI, presentations, and graphics on the Superdesign canvas with a choice of leading AI models. Use whenever the user wants to design a page, feature, flow, slide deck, or brand-new product; improve or reproduce existing UI; compare design results across top models; explore visual variants…
yao-image
Image expert. ALWAYS invoke this skill when you need to read, analyze, describe, or generate images. Use for screenshots, photos, charts, diagrams, AI-generated images, or any visual content.
yao-audio
Audio expert. ALWAYS invoke this skill when the user asks to transcribe, recognize, or convert speech/audio to text.
agent-first-screenshots
Agent-first screenshots — an agent drives the real app via CDP and produces clean, defect-free product screenshots (newsletters, landing pages, social, decks, PR). Dual-channel verification (DOM + pixels + vision) in a capture loop. Use for any "take/redo screenshots of the app" task.