Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/to-agent/agent-exec/publicnpx skills add to-agent/agent-exec --skill publicgit clone --depth 1 https://github.com/to-agent/agent-execWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01368 |
| Opus 5 | $0.00000 | $0.00684 |
| Sonnet 5 | $0.00000 | $0.00274 |
| Haiku 4.5 | $0.00000 | $0.00137 |
Grade A, and why
public scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -s http://<host>/api/acl \ How it starts
The opening of the file, as written. The whole thing — 256 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SKILL: agent-exec
Endpoint: GET /
Description: Self-describing HTTP execution surface for AI agents
What is this?
agent-exec lets an AI agent discover this machine, inspect what is allowed, and execute only permitted commands through HTTP.
This is the root guide for this running agent-exec server.
Root surface
The root surface points agents to the API documents used for discovery.
{
"method": "GET",
"url": "/",
"document": "/SKILL.s.js",
"refs": [
"/api/acl/SKILL.s.js",
"/api/exec/SKILL.s.js"
]
}
Start
1. Inspect allowed operations
Protected API calls require API_KEY.
Use /api/acl to inspect allowed and denied commands.
curl -s http://<host>/api/acl \
-H "X-API-Key: <API_KEY>"
ACL request:
{
"method": "GET",
"url": "/api/acl",
"document": "/api/acl/SKILL.s.js",
"request": {
"headers": {
"X-API-Key": "API_KEY",
"Accept": "text/sjs"
}
},
"refs": [
"/api/exec/SKILL.s.js"
]
}
Allowed command values:
["<command> [<arg>]...", "..."]
Allowed command item kind:
"argv_string"
Allowed command item syntax:
"<command> [<arg>]..."
Allowed command item to exec args:
["<command>", "<arg>", "..."]
Denied pattern values:
["<denied pattern>", "..."]
2. Discover plugins
curl -s http://<host>/api/plugins \
-H "X-API-Key: <API_KEY>"
The skill URL in the response is the next document to read.
3. Execute an allowed command
curl -X POST http://<host>/api/exec \
-H "X-API-Key: <API_KEY>" \
-H "Content-Type: application/json" \
-d '{"args": ["aexec", "--version"]}'
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 256 lines · 0 tokens per session scan A 8a84874d2109
public is a skill published in the GitHub repository to-agent/agent-exec (1 stars, last pushed 3mo ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 1,368 tokens. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
add-provider
Add or extend an open-source OOMOL Connect provider under src/providers, including provider definition, action schemas, local executors, credential validation, examples, and generated catalog updates.
vs-product-qa
Answer Viking AI Search product questions, CLI usage questions, API/auth questions, configuration questions, and troubleshooting questions by grounding every claim in either the installed vs CLI's own output or official Volcengine documentation. Never fabricate.
vs-search
Search runtime and scene management: verify queries, inspect scenes, debug app readiness, and diagnose recall or scene-config issues.
vs-shared
Shared SearchCLI setup: install, authenticate, run doctor, and verify the local environment.
local-search
Skill "local-search" from taxueseek/argo, covering local search 子技能, 设计原则, 本地引擎列表(33 个,29 个默认启用), 调用方式 and 直接调用子技能(单引擎).
scrape-structured-data
Get the repeating records off a web page (product grids, search results, job listings, news feeds, tables) as JSON, without writing CSS selectors and without spending a model call to read the HTML. Works on sites with no API, including ones behind a login or bot protection. Runs locally, one binary, no API key. Use…