Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/tonydzi/second-brain-starter-kit/fb-replynpx skills add tonydzi/second-brain-starter-kit --skill fb-replygit clone --depth 1 https://github.com/tonydzi/second-brain-starter-kitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/tonydzi/second-brain-starter-kit/fb-reply)<a href="https://agentmods.dev/skills/tonydzi/second-brain-starter-kit/fb-reply"><img src="https://agentmods.dev/badge/skills/tonydzi/second-brain-starter-kit/fb-reply.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00078 | $0.03525 |
| Opus 5 | $0.00039 | $0.01762 |
| Sonnet 5 | $0.00016 | $0.00705 |
| Haiku 4.5 | $0.00008 | $0.00352 |
Grade A, and why
fb-reply scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 158 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/fb-reply — reply to the comments under the owner's posts (safely)
Why. Comments pile up under the posts (often valuable — like the counter-thesis one engineer left about tailscale). Replying on your OWN posts is a low-risk task, but Facebook still bans for PACE. So: read safely, write personally in the owner's voice, post one at a time with pauses, under a counter.
Main rules (from Deep Research #32):
- Pace decides, not "bot vs human". Every reply passes
fb_guard check reply: ≤40/day, ≥5 min between replies, no back-to-back series. The guard physically will not let you overshoot. - Every reply is personal and different (top-tier model, the owner's voice). The same text sent to many people = a spam flag → a ban.
- Draft-first: show the owner a batch of drafts, post only after a
+. - Account safety: do NOT click "View more comments" on reshares — it navigates away. Read what already loaded under the original.
0. The fuse — status at the start
python "$USERPROFILE/.claude/scripts/fb_guard.py" status
Shows how many replies went out today and whether we are paused. If reply is already at the daily limit — tell the owner and defer.
1. Browser + reading the commenters (no risky clicks)
Strictly LOCAL, a live tab, we never touch the login. Is the Chrome MCP connected? (
list_connected_browsers). ⛔ IP gate (owner, 07-16): Facebook commenting happens ONLY from the hub (a stable IP). On another machine do NOT reply — send the task to the hub as text. Canon:ip-sensitive-actions-hub-only.
- Open the owner's post (he gives the link, or go to
facebook.com/<profile>→ his latest posts). ⛔ PITFALL 2026-07-28: the profile wall does NOT hand out permalinks. Scrolling the profile yields zeropfbidlinks (Facebook populates href only on hover), and the feed is virtualized — a JS scroll outruns lazy loading and the posts stay skeletons. The working entrance = the notifications feedfacebook.com/notifications: every row "X commented on your post" already carries a ready/posts/pfbid…and tells you WHO wrote and WHEN. One pass over it replaces the whole wall scroll. The Graph-API path (fb_posts_poll.py) is dead for now — there is noFB_USER_TOKEN. ⚠️ An open Messenger window pollutes the results: itsdiv[role="article"]elements are DM messages, not comments. Close the chat window before collecting. - Extract the commenters INSIDE THE PAGE ITSELF (Facebook hides names/links across the MCP boundary → match and filter inside the page, and hand out only safe text). Through
mcp__Claude_in_Chrome__javascript_tool:
You get back a list ofconst out = []; const seen = new Set(); document.querySelectorAll('div[role="article"][aria-label]').forEach(a => { const al = a.getAttribute('aria-label') || ''; if (!/^Comment by|^Reply by/i.test(al)) return; // comments only const blocks = [...a.querySelectorAll('div[dir="auto"]')] .map(d => (d.innerText || '').trim()).filter(Boolean); const text = (blocks.sort((x, y) => y.length - x.length)[0] || '').slice(0, 500); if (!text || seen.has(text)) return; seen.add(text); const link = a.querySelector('a[role="link"][href]'); // the author's profile const handle = link ? (new URL(link.href).pathname.replace(/\//g,'')) : ''; const hasImg = !!a.querySelector('img[src*="scontent"],img[src*="fbcdn"]'); out.push({ handle, text, hasImg }); // handle = username, not a display name }); out;{handle, text, hasImg}— no hidden strings, safe to display. (If Facebook runs in another language, add that locale'saria-labelprefixes to the regex.) - Virtualization: if there are few comments, gently scroll the comments area (
computerscroll down the page, WITHOUT clicking expander buttons) and repeat §1.2. On a RESHARED post do NOT press "View more". - ⚠️ MANDATORY: expand collapsed threads BEFORE choosing "who to reply to" (lesson 2026-07-05): Facebook hides existing replies under "View N replies" — the owner has often ALREADY replied himself, and from the outside you cannot see it (a duplicate = embarrassment + a spam signal). On YOUR OWN post the inline thread expanders are safe (not to be confused with "View more comments" on reshares). Through JS: click every toggle matching
/View (\d+ )?repl/i, wait ~3s, then collectaria-label^="Reply by <owner's name> to <Name>"→ the list of ALREADY answered people; reply only to those not on it. In the 2026-07-05 run this filtered out 7 of 8 "candidates".
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 158 lines · 78 tokens per session scan A 49db7fd2b75a
fb-reply is a skill published in the GitHub repository tonydzi/second-brain-starter-kit (5 stars, last pushed 4d ago), licensed MIT. It adds 78 tokens to every session and 3,525 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
defuddle
Plan and, with explicit network consent, use an optional external Defuddle cleaner to extract article-like HTTPS pages as Markdown. Use for defuddle, clean this URL, strip page clutter, readable Markdown from a web page, or preparing a web source for later wiki ingestion.
wiki-ingest
Ingest supplied source material into an Obsidian vault with provenance and claim tracking: pasted text, files staged in the selected vault's inbox or .raw archive, or explicitly approved URLs. Use for a single source or bounded batch, not for saving an assistant answer. Triggers: ingest, ingest this file, ingest this…
autoresearch
Run a bounded, source-grounded research loop, draft a cited dossier, and optionally propose a separately reviewed canonical vault merge. Use when the user wants autonomous or deep research that may access the public web. Triggers: /autoresearch, autoresearch, research this topic, deep dive into, investigate, find…
canvas
Create, inspect, and update Obsidian JSON Canvas boards with text, file, link, group, and edge nodes. Use for canvas status, canvas lists, visual maps, zones, spatial layouts, adding vault notes or media to a .canvas file, and requests such as create canvas, add to canvas, or put this on the canvas.
wiki-retrieve
Build and query a vault-local contextual BM25 retrieval index with optional multilingual Nomic cosine reranking; use for retrieve, hybrid retrieval, BM25, rerank, contextual retrieval, chunk search, vault search, semantic search, find relevant passages, or retrieval diagnostics. Derived caches stay under .vault-meta…
wiki
Initialize, adopt, and route work for a separate Obsidian knowledge vault through the portable claude-obsidian core. Use for vault setup, scaffolding, workspace selection, cross-project configuration, or choosing the correct wiki sub-skill. Triggers: /wiki, set up wiki, scaffold vault, create knowledge base, adopt…