Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add u9401066/rootcause-mcp --skill asset-aware-mcp-harnessgit clone --depth 1 https://github.com/u9401066/rootcause-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/u9401066/rootcause-mcp/asset-aware-mcp-harness)<a href="https://agentmods.dev/skills/u9401066/rootcause-mcp/asset-aware-mcp-harness"><img src="https://agentmods.dev/badge/skills/u9401066/rootcause-mcp/asset-aware-mcp-harness/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/u9401066/rootcause-mcp/asset-aware-mcp-harness"><img src="https://agentmods.dev/badge/skills/u9401066/rootcause-mcp/asset-aware-mcp-harness.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00047 | $0.00472 |
| Opus 5 | $0.00023 | $0.00236 |
| Sonnet 5 | $0.00009 | $0.00094 |
| Haiku 4.5 | $0.00005 | $0.00047 |
Grade A, and why
asset-aware-mcp-harness scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
2 near-identical copies found in the catalogue:
- asset-aware-mcp-harness — 100% identical, 0 lines differ
- asset-aware-mcp-harness — 100% identical, 0 lines differ
What it actually says
asset-aware-mcp: Cline Harness Skill
Use this skill when working in this repo with Cline and you want a reliable, production-grade loop: change -> verify -> ship.
What To Use First
- Rules:
.clinerules/(always-on, with conditional scopes) - Workflows:
.clinerules/workflows/- Run
/full-check.mdfor the full local gates - Run
/release-publish.mdfor a guided tagged release
- Run
- VSIX assistant assets:
vscode-extension/resources/repo-assets/asset-aware/- Keep them synchronized with
cd vscode-extension && npm run sync-assets:check
- Keep them synchronized with
- Skills: this repo already has multiple skills under
.claude/skills/(Cline can load them too)- If any
.claude/skillsinstruction conflicts with current repo behavior, treat.clinerules/as the source of truth.
- If any
Canonical Commands
- Python:
uv run ruff check .,uv run mypy src --ignore-missing-imports,uv run pytest - Extension (in
vscode-extension/):npm run test:ci - Docker smoke:
docker build -t asset-aware-mcp:smoke .thendocker run --rm --entrypoint python asset-aware-mcp:smoke -c "import src.presentation.server"
Citation-Ready Mindset
- Prefer stable, verifiable spans (line/char/byte offsets + hashes) over loose “source: page 3” citations.
- Treat CRAAP fields as a conservative scaffold: avoid claiming more confidence than you can actually verify.
MCP Auto-Config Mindset
- VSIX install/update must keep Copilot
.vscode/mcp.json, Clinecline_mcp_settings.json, and Codexconfig.tomlidempotent. - Preserve unrelated MCP servers and user-local Cline/Codex metadata.
- Do not create duplicate Asset-Aware server entries under alternative names.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 33 lines · 47 tokens per session scan A e5af27a7740a
asset-aware-mcp-harness is a skill published in the GitHub repository u9401066/rootcause-mcp (0 stars, last pushed 8d ago), licensed Apache-2.0. It adds 47 tokens to every session and 472 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
detecting-pv-signals
Computes disproportionality signals — PRR, ROR, EBGM, and IC (BCPNN) — over FAERS / OpenFDA drug-event data to flag potential safety signals. Use when the user wants to mine spontaneous-report data for drug-reaction associations, build a 2x2 contingency table, compute a Proportional Reporting Ratio or Reporting Odds…
coding-icd10
Suggests candidate ICD-10-CM diagnosis codes (and ICD-10-PCS procedure codes) for diagnoses and procedures extracted by OpenMed, with rationale and a human-coder caveat. Use when the user wants to code a problem list, map a diagnosis span to a billable ICD-10-CM code, route a finding to the right chapter, cross-walk…
deidentifying-clinical-text
Remove, mask, or replace PHI/PII in clinical free text on-device with OpenMed's deidentify(). Use when the user needs to de-identify medical notes, strip patient identifiers, redact PHI before sharing or analysis, anonymize discharge summaries, or pick a de-id method (mask vs remove vs replace vs hash vs shiftdates).…
evaluating-with-leakage-gates
Evaluate an OpenMed de-identification or clinical NER model against the leakage-first release gates G1a through G8, which gate releases on residual PHI leakage rather than on F1. Use when the user wants to run the OpenMed eval harness on a synthetic golden set, decide whether a de-id model is RELEASABLE or…
extracting-sdoh
Extracts social determinants of health (SDOH) — housing instability, food insecurity, unemployment, transportation barriers, social isolation, financial strain — from clinical narrative and maps the spans to ICD-10-CM Z-codes (Z55–Z65). Use after running OpenMed NER when the user wants SDOH surfacing, Z-code…
mapping-to-snomed
Maps clinical concept spans extracted by OpenMed to SNOMED CT concepts through a USER-SUPPLIED terminology server (the user's own Ontoserver, Snowstorm, or UMLS/UTS), never a bundled vocabulary. Use when the user wants to code findings, disorders, procedures, body structures, or substances to SNOMED CT, run an ECL…