Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add TimSimpsonJr/magpie --skill redaction-checkgit clone --depth 1 https://github.com/TimSimpsonJr/magpieWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/timsimpsonjr/magpie/redaction-check)<a href="https://agentmods.dev/skills/timsimpsonjr/magpie/redaction-check"><img src="https://agentmods.dev/badge/skills/timsimpsonjr/magpie/redaction-check/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/timsimpsonjr/magpie/redaction-check"><img src="https://agentmods.dev/badge/skills/timsimpsonjr/magpie/redaction-check.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00144 | $0.01505 |
| Opus 5 | $0.00072 | $0.00753 |
| Sonnet 5 | $0.00029 | $0.00301 |
| Haiku 4.5 | $0.00014 | $0.00151 |
Grade A, and why
redaction-check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 101 lines — stays where its author put it; the contents beside it link to each section on GitHub.
redaction-check
Find BAD REDACTIONS in a PDF and emit each as a FLAG-FOR-A-HUMAN LEAD -- NEVER an
"improper redaction" verdict. A layered set of independent checks runs over one
PDF and returns a RedactionReport. This is the INPUT side of Phase 7 (the output
side is redact-output).
The verified library facts (the x-ray inspect() contract, the pikepdf /
pdfminer APIs, the AGPL/PyMuPDF licensing call, the coordinate trap) live in
references/prior-art.md -- consult it before changing a check or a dependency.
The one entrypoint
from scripts.redaction_check import check_redactions
report = check_redactions(pdf_path, mode="received") # or mode="pre-publish"
publishable = report.publishable_view() # safe to route to Librarian
mode:
received-- inspect a FOIA response WE GOT for the AGENCY's bad redactions. Findings are investigative LEADS (recover/quantify what they failed to hide; feedrequest-the-gap).safe_to_publishisNone(no pass/fail).pre-publish-- inspect OUR OWN output before release. A finding is a STOP signal; severities come from a pinned map and the report carriessafe_to_publish: bool.
The checks (each a LEAD)
- box_over_text -- Free Law
x-ray(lazy -> PyMuPDF): a rectangle drawn over still-extractable text. The recovered under-box text is LOCAL-only. - text_layer -- pdfminer.six: extractable text that CO-OCCURS (page-level) with another redaction signal. NOT a standalone "text exists" alarm.
- metadata -- pikepdf docinfo + XMP: leaked author / producer / title / dates.
- incremental_save -- raw bytes:
%%EOFpaired withstartxref> 1 (a prior revision may hold pre-redaction content). A lead, not proof. - unapplied_redact -- pikepdf: a
/Subtype /Redactannot MARKED but never APPLIED (underlying content still present). - embedded_files -- pikepdf: attachments +
/AF+/FileAttachment(may carry un-redacted source). Name + size only; never extract contents. - acroform_values -- pikepdf: form field
/Vvalues behind a flat-looking page. - annotation_text -- pikepdf: comment-annot
/Contents(a reviewer note).
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 101 lines · 144 tokens per session scan A 74a0c3a17d2e
redaction-check is a skill published in the GitHub repository TimSimpsonJr/magpie (2 stars, last pushed 2mo ago), licensed MIT. It adds 144 tokens to every session and 1,505 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
pdf-table-extractor-brief
Produces a structured extraction plan and clean spreadsheet template for pulling tabular data out of a PDF document — identifying the table structure, defining column headers, flagging extraction pitfalls, and providing a ready-to-use template that ensures the data lands in a consistent, analysable format.
pdf-design
Designs PDF reports and proposals from HTML with previews and branding. Use to create, export, or securely upload a PDF.
document-design
Creates print-ready HTML that exports to PDF. Use to make a proposal, report, one-pager, newsletter, slides, or flyer.
data-table-formatter
Formats raw or messy data into a clean, publication-ready table with appropriate headers, sorted rows, consistent number formatting, and a source note — ready to drop into an article, report, or web page.
foia-request-writer
Drafts legally complete public records requests (federal FOIA and all 50 state laws), administrative appeals, and redaction challenge strategies for U.S. government records.
osint-tool-catalog
Produces a categorised catalog of open-source intelligence tools relevant to a journalist's investigation, with practical guidance on what each tool does, when to use it, and what its limitations are.