Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add terrylica/cc-skills --skill notes-inventorygit clone --depth 1 https://github.com/terrylica/cc-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/terrylica/cc-skills/notes-inventory)<a href="https://agentmods.dev/skills/terrylica/cc-skills/notes-inventory"><img src="https://agentmods.dev/badge/skills/terrylica/cc-skills/notes-inventory.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00092 | $0.00593 |
| Opus 5 | $0.00046 | $0.00296 |
| Sonnet 5 | $0.00018 | $0.00119 |
| Haiku 4.5 | $0.00009 | $0.00059 |
Grade A, and why
notes-inventory scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
notes-inventory — the Notes sidebar as data
Self-Evolving skill — if macOS Notes' AppleScript behavior drifts from what's below (folder flattening, trash visibility, counts), fix this SKILL.md and the shared engine
scripts/lib/notes-core.ts/scripts/notes.ts(+ a test innotes-core.test.ts); see the Post-Execution Reflection at the bottom.
Read-only survey of the whole Notes tree, across ALL accounts (iCloud, Google, Exchange…).
NC="$HOME/.claude/plugins/marketplaces/cc-skills/plugins/notes-commander/scripts/notes.ts"
bun "$NC" inventory # human tree: account → folders (indented) with counts
bun "$NC" inventory --json # [{account, path, count}, …] for analysis
- Nested folders appear as paths with
/separators (e.g.To-Do / Done) — folder names are not unique (two "Done" folders is normal), paths are. - Counts are direct notes per folder (subfolder notes count under the subfolder), matching the Notes sidebar.
Recently DeletedIS visible to AppleScript (verified live 2026-07-18) — inventory shows it but reports its notes separately from the live total;exportskips it entirely.- First run may prompt once for Automation permission to control Notes; one AppleScript pass, so it's fast even on hundreds of notes.
- If it fails with
-600/"not running" repeatedly, open Notes once, then retry (the engine already retries transient errors).
This is the data source the notes-audit skill analyzes and the notes-organize skill acts on.
Post-Execution Reflection
After an inventory run, check: (1) did the tree match the Notes sidebar (folders, nesting, counts)? If not, the flattened-folders of account filter or trash handling drifted — fix OSA_INVENTORY in scripts/notes.ts and document the macOS change here. (2) Did a transient -600/-1712 require a manual retry? If the built-in retry didn't absorb it, tune runOsa in notes-core.ts. Only update for real, reproducible drift — not speculation.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 30 lines · 92 tokens per session scan A 6ad148274ccd
notes-inventory is a skill published in the GitHub repository terrylica/cc-skills (62 stars, last pushed today), licensed MIT. It adds 92 tokens to every session and 593 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
session-status
Analyzes current session state without any cleanup. Full mode (default): resolves the active plan file, reads plan checklist + TaskList, gathers unfinished work/issues from conversation history, and emits a /handoff-built next-session prompt. Mid-session mode (/session-status mid): a fast plain-language 'done vs…
ship
Commit, push, create PR(s), and auto-finalize — full automation pipeline. Handles uncommitted changes and recently created PRs.
calendar
Google Calendar integration — check schedule, create events, daily briefings, proactive reminders. Triggers on "what's on my calendar", "add to calendar", "schedule a meeting", "when am I free", "daily briefing", or any calendar-related request.
native-first
Stack-agnostic discovery playbook for finding the native, non-custom way to do something before writing any script or wrapper. Use when tempted to write a shell/python/glue script, add a dependency, or build a custom helper — and whenever a script-guards hook blocks a script write. Climbs a fixed ladder (tool's own…
configure
Set up the Telegram channel — save the bot token and review access policy. Use when the user pastes a Telegram bot token, asks to configure Telegram, asks "how do I set this up" or "who can reach me," or wants to check channel status.
github-release-management
GitHub release orchestration — automated versioning, testing, deployment, and rollback. Use when cutting a release, tagging a version, drafting release notes, or coordinating a deploy/rollback workflow.