Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add withoneai/one-agent-plugin --skill brexgit clone --depth 1 https://github.com/withoneai/one-agent-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/withoneai/one-agent-plugin/brex)<a href="https://agentmods.dev/skills/withoneai/one-agent-plugin/brex"><img src="https://agentmods.dev/badge/skills/withoneai/one-agent-plugin/brex/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/withoneai/one-agent-plugin/brex"><img src="https://agentmods.dev/badge/skills/withoneai/one-agent-plugin/brex.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00120 | $0.05680 |
| Opus 5 | $0.00060 | $0.02840 |
| Sonnet 5 | $0.00024 | $0.01136 |
| Haiku 4.5 | $0.00012 | $0.00568 |
Grade A, and why
brex scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
75% identical to 2-chat — 279 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 252 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Brex through One
Brex combines corporate cards, business accounts, expense management, bill pay, and travel booking into a single AI-powered financial operations platform—offering unified spend control, real-time visibility, automated workflows, and modern treasury tools designed for startups and enterprises across 120+ countries.
One exposes Brex through four MCP tools. The table below carries real action ids from One's knowledge base, so for a common operation you can skip search and go straight to reading the action's parameters.
How to run an action
- Find the action in the table below, or call
search_one_platform_actionswith platformbrexif it is not listed. - Call
get_one_action_knowledgewith the action id. Do this every time, including for actions in this table. The table gives you the id, not the parameters. - Call
execute_one_actionwith parameters copied from that knowledge.
Never guess a parameter name, a body field, or an enum value. The knowledge has the real schema, and a guessed field is either a 400 or a silent write of the wrong thing.
Before you start
Call list_one_integrations once and confirm Brex is connected. If it is missing, the user has not connected it: say so and point them at https://app.withone.ai rather than reaching for raw HTTP.
Each connection carries an access field. If it reports {"policy": "methods", "methods": ["GET"]} the agent is read-only here, so plan a read-only answer instead of attempting a write that will be refused.
Before a write
Creates, updates, deletes and sends land on a real Brex account and cannot be recalled. State the action and the specific target in one line before the first write in a task, and let the user stop you. Reads need no confirmation.
Actions
Budgets
| Action | Method | Path | Action id |
|---|---|---|---|
| Get a Budget by ID | GET | /v2/budgets/{{id}} |
conn_mod_def::GJ094hSR8nE::Z4He1qh-SfGiP8JuXyLXww |
| Get a Spend Limit by ID | GET | /v1/budgets/{{id}} |
conn_mod_def::GJ09-jcQaTU::ZmKtsfSmQOyi8XzCA4luzw |
| List Budgets | GET | /v2/budgets |
conn_mod_def::GJ094q6dtMY::1uQwvjk6R928D49LMnzCrw |
| List Spend Limits | GET | /v1/budgets |
conn_mod_def::GJ09-qOKmWE::oFeeoTxJQku6eUilAEGYQA |
| Archive a Budget | POST | /v2/budgets/{{id}}/archive |
conn_mod_def::GJ094RIHbtQ::VnWj4-OmSYewvpL6Uur_8w |
| Archive a Spend Limit | POST | /v1/budgets/{{id}}/archive |
conn_mod_def::GJ09-SSCsRM::atiUQpjvTFSlLRcGfzVBBA |
| Create a Spend Limit | POST | /v1/budgets |
conn_mod_def::GJ09-aEiULY::G5M1llCBTEm4DWpYPpI49A |
| Create Budget | POST | /v2/budgets |
conn_mod_def::GJ094Z8EAKM::_MF_lncnRcO0Fr2Cuor5jA |
| Update a Budget | PUT | /v2/budgets/{{id}} |
conn_mod_def::GJ094y8cYgw::OrUQReSGQqyXexDH-ie8iQ |
| Update a Spend Limit | PUT | /v1/budgets/{{id}} |
conn_mod_def::GJ09-yXPMqU::LYPOEFUoSzy6snCkEFLzTw |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 252 lines · 0 tokens per session scan A 0d00a980550b
brex is a skill published in the GitHub repository withoneai/one-agent-plugin (1 stars, last pushed 19d ago), licensed MIT. It adds 120 tokens to every session and 5,680 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. It is 75% identical to 2-chat, differing in 279 lines, and is treated as a copy.
Other skills, from other repositories
cargo-billing
Understand what Cargo is costing — remaining credits, usage broken down by workflow, connector, or agent, subscription state, and invoice history. Triggers: "how many credits do I have left", "what did that cost", "why is my bill so high", "am I about to run out", "will this fit in our budget", "show me my invoices"…
finance-accounting
Skill "finance-accounting" from frank-luongt/faos-skills-marketplace, covering finance & accounting operations, use this skill when, do not use this skill when, instructions and journal entry templates.
upbit
A command-line tool for using Upbit, a cryptocurrency exchange, through its programming interface.
smart-cost-tracker
Track AI agent spending in real time. Shows cost per message, per conversation, per day. Budget alerts, daily/weekly reports, cost-per-task breakdown. Use when the user asks about spending, costs, tokens, budget, or billing. Triggers on: "how much did that cost", "show my spending", "token usage", "budget", "cost…
sector-rotation
An analysis framework for comparing industries in the Chinese A-share stock market, using business conditions, price momentum, valuation, and money flows. It produces rankings and higher- or lower-allocation suggestions.
dsql
Build with Aurora DSQL — manage schemas, execute queries, handle migrations, diagnose query plans, diagnose cluster performance, load data, and develop applications with a serverless, distributed SQL database. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL and PostgreSQL-to-DSQL schema conversion, foreign key…