Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add unknowbug/anchorlaw --skill anchor-noisegit clone --depth 1 https://github.com/unknowbug/anchorlawWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/unknowbug/anchorlaw/anchor-noise)<a href="https://agentmods.dev/skills/unknowbug/anchorlaw/anchor-noise"><img src="https://agentmods.dev/badge/skills/unknowbug/anchorlaw/anchor-noise/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/unknowbug/anchorlaw/anchor-noise"><img src="https://agentmods.dev/badge/skills/unknowbug/anchorlaw/anchor-noise.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00040 | $0.00506 |
| Opus 5 | $0.00020 | $0.00253 |
| Sonnet 5 | $0.00008 | $0.00101 |
| Haiku 4.5 | $0.00004 | $0.00051 |
Grade A, and why
anchor-noise scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
anchor.noise — 噪声卡管理
Protocol: spec/protocol-v0.20.md §3 (Noise Card JSON Schema) Layer: L3 (Noise) Execution: inline
触发场景
运行时观察到失败/异常;或存在未解决噪声卡积压时。
操作步骤
- 创建(§14.4 唯一代码内钩子,无 CLI 入口)——在捕获失败的
except块中调用:
必填字段:import anchorlaw as pract # 需已安装 anchorlaw(stub 仅含 test/idk) try: result = func(bad_input) except Exception as e: pract.create_noise_card( trigger="func(bad_input)", function_name="func", observed=f"抛出 {type(e).__name__}: {e}", expected="应返回默认值而非崩溃", discovery="函数未处理该输入形态", curriculum="处理外部输入时先校验形态,再执行运算", ) raisenoise_id(自动) /timestamp(自动) /trigger/function_name/observed/expected(§3 schema)。 - 列出:
anchorlaw noise list(--all含已解决) - 搜索:
anchorlaw noise search <keyword> - 解决(转为回归测试):
anchorlaw noise resolve <noise_id> --converted-test "<测试描述>"
输出
创建的噪声卡 / 积压清单 / 搜索命中 / 解决记录。
约束
curriculum必须可操作(可复用教训),不写空话。- 除创建外的所有管理操作一律 CLI(§14.4)。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago Changed 29cfa2ac6e4a
- 10d ago First seen · 48 lines · 40 tokens per session scan A 17afe5af2b01
anchor-noise is a skill published in the GitHub repository unknowbug/anchorlaw (5 stars, last pushed yesterday), licensed MIT. It adds 40 tokens to every session and 506 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
solid-principles
SOLID principles checklist with Java examples. Use when a class has too many responsibilities, an abstraction leaks, or a dependency points the wrong way, and when the user asks about Single Responsibility, Open/Closed, Liskov, Interface Segregation or Dependency Inversion. For naming, duplication and method length…
security-audit
Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. Works with Spring, Quarkus, Jakarta EE, and plain Java. Use when reviewing code security, before releases, or when user asks about vulnerabilities.
issue-triage
Triage and categorize GitHub issues with priority labels. Use when user says "triage issues", "check issues", "review open issues", or during regular maintenance of GitHub issue backlog.
ring:migrating-to-lib-observability
Migrating a Lerian Go app off lib-commons observability imports (deprecated shims or removed APIs) to lib-observability via a fixed mapping table, then bumps go.mod and validates the build; ring:backend-go applies the edits. Covers log/zap/runtime/assert, opentelemetry/tracing, HTTP middleware, context helpers, and…
ring:searching-code
Forensic code search and analysis with optional Chain of Draft (CoD) ultra-concise mode. Five-phase methodology (clarification, planning, execution, analysis, synthesis) with severity assessment. Use for targeted investigation of specific patterns, bugs, or vulnerabilities. Skip for broad architecture mapping (use…
ring:exploring-codebases
Exploring a codebase across phases: scopes the target, detects architecture, components, and layers, deep-dives each discovered perspective, then synthesizes findings into actionable guidance with file:line evidence. Use to understand how a feature or system works before planning changes, or to orient on an unfamiliar…