Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add terrylica/cc-skills --skill send-notificationgit clone --depth 1 https://github.com/terrylica/cc-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/terrylica/cc-skills/send-notification)<a href="https://agentmods.dev/skills/terrylica/cc-skills/send-notification"><img src="https://agentmods.dev/badge/skills/terrylica/cc-skills/send-notification.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00103 | $0.00732 |
| Opus 5 | $0.00051 | $0.00366 |
| Sonnet 5 | $0.00021 | $0.00146 |
| Haiku 4.5 | $0.00010 | $0.00073 |
Grade A, and why
send-notification scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 41 lines — stays where its author put it; the contents beside it link to each section on GitHub.
send-notification
Self-Evolving Skill: This skill improves through use. If instructions are wrong, parameters drifted, or a workaround was needed — fix this file immediately, don't defer. Only update for real, reproducible issues.
Send a Pushover notification via the TypeScript core pushover_core.ts (Bun). Secrets resolve via _lib/resolve_pushover_secret.sh from an env-configured 1Password item (PUSHOVER_OP_VAULT / PUSHOVER_OP_ITEM, set in your private config — see _lib/references/private-config-setup.md) with a macOS Keychain fallback — never hardcode tokens.
Usage
env -u HTTPS_PROXY -u HTTP_PROXY bun "$(cc-plugin-root pushover-commander)/skills/_lib/pushover_core.ts" send \
--message "your message" --title "Title" [--priority N] [--attach image.png] \
[--sound NAME] [--url https://link] [--url-title "link title"] [--html|--monospace] [--app main|test] [--force]
--app test(default) uses the test application token;--app mainuses the production token.--html/--monospaceenable rich formatting (mutually exclusive — preflight refuses both).- All limits live in
skills/_lib/pushover_api_limits.json(SSoT). Preflight validates every send: it refuses url>512, attachment>5 MB, html+monospace (override with--force) and warns on message/title truncation or a sound not in the account — turning Pushover's silent failures into explicit output. - Every send is audited to
~/.local/state/pushover/po-audit.jsonl(UUID-keyed) and quota remaining is read from the response headers (warns when low). See health-check fordoctor/quota.
Notes
env -u *PROXY*makes Bun'sfetchbypass the sandbox MITM proxy (else 502). Validatesuser+devicebefore sending; transient 5xx/network errors are retried (×3, backoff). Type-checked viabunx tsc --noEmit.
Post-Execution Reflection
After this skill completes, check before closing:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 41 lines · 103 tokens per session scan A b0a0d7cebfdd
send-notification is a skill published in the GitHub repository terrylica/cc-skills (62 stars, last pushed yesterday), licensed MIT. It adds 103 tokens to every session and 732 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
session-status
Analyzes current session state without any cleanup. Full mode (default): resolves the active plan file, reads plan checklist + TaskList, gathers unfinished work/issues from conversation history, and emits a /handoff-built next-session prompt. Mid-session mode (/session-status mid): a fast plain-language 'done vs…
ship
Commit, push, create PR(s), and auto-finalize — full automation pipeline. Handles uncommitted changes and recently created PRs.
calendar
Google Calendar integration — check schedule, create events, daily briefings, proactive reminders. Triggers on "what's on my calendar", "add to calendar", "schedule a meeting", "when am I free", "daily briefing", or any calendar-related request.
native-first
Stack-agnostic discovery playbook for finding the native, non-custom way to do something before writing any script or wrapper. Use when tempted to write a shell/python/glue script, add a dependency, or build a custom helper — and whenever a script-guards hook blocks a script write. Climbs a fixed ladder (tool's own…
configure
Set up the Telegram channel — save the bot token and review access policy. Use when the user pastes a Telegram bot token, asks to configure Telegram, asks "how do I set this up" or "who can reach me," or wants to check channel status.
cron-manager
Create, inspect, pause, and remove scheduled jobs using natural language descriptions.