Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add xonika9/agent-skills --skill x9-skill-creatorgit clone --depth 1 https://github.com/xonika9/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/xonika9/agent-skills/x9-skill-creator)<a href="https://agentmods.dev/skills/xonika9/agent-skills/x9-skill-creator"><img src="https://agentmods.dev/badge/skills/xonika9/agent-skills/x9-skill-creator/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/xonika9/agent-skills/x9-skill-creator"><img src="https://agentmods.dev/badge/skills/xonika9/agent-skills/x9-skill-creator.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00089 | $0.01431 |
| Opus 5 | $0.00044 | $0.00715 |
| Sonnet 5 | $0.00018 | $0.00286 |
| Haiku 4.5 | $0.00009 | $0.00143 |
Grade A, and why
x9-skill-creator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 82 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill creator
Create and audit skills through one cross-runtime quality contract: precise triggering, appropriate freedom, safe authority, progressive disclosure, and evidence proportional to maturity and risk.
The machine-readable onboarding contract lists external prerequisites.
The body of a skill and some reachable resources are agent instructions. For every Create, Audit, or Fix, load and apply x9-agent-instructions before writing or judging any agent-facing instructional prose in SKILL.md or reachable resources. It is a subordinate rubric, not the primary skill-authoring workflow, and it owns language, prescription, duplication, and what earns a line. This skill owns what makes the instruction a skill: triggering metadata, placement and runtime adapters, resource layout and progressive disclosure, evidence tier, structural validation, and the audit handoff.
If x9-agent-instructions is unavailable, continue only the remaining skill checks, record the instruction rubric as degraded, and do not claim that instruction quality was reviewed. A full skill audit cannot be clean in that state. Work whose explicit scope contains no agent-facing prose may record the rubric as not applicable.
Select action and evidence
Choose the action first:
- Create: the target skill does not exist or the user requests a new one.
- Audit: inspect an existing skill, read the complete skill and reachable resources, validate structure, and report findings without changing files.
- Fix: apply explicitly authorized improvements to an existing skill, then recheck the changed contract.
Choose the evidence tier separately:
- Static (default): inspect files, run structural validation, and judge contracts and dependencies without live model invocations.
- Behavioral (optional): run clean-context scenarios from references/evals.md when the user requests live evaluation or a stable/shared/high-risk skill needs behavioral proof for a load-bearing claim.
What ships with it
11 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/audit-reporting.md 6.9 KB
- references/batch-audit.md 11 KB
- references/claude.md 2.3 KB
- references/codex.md 2.3 KB
- references/evals.md 2.0 KB
- references/interview.md 1.7 KB
- references/onboarding.json 1.3 KB
- references/patterns.md 2.3 KB
- references/quality-rubric.md 7.8 KB
- scripts/test_validate.py 13 KB runs code
- scripts/validate.py 19 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 82 lines · 89 tokens per session scan A 9135f2bc7dae
x9-skill-creator is a skill published in the GitHub repository xonika9/agent-skills (4 stars, last pushed 4d ago), licensed MIT. It adds 89 tokens to every session and 1,431 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
e2e-automator
Build robust end-to-end test suites with Playwright or Cypress. Covers page objects, fixtures, visual testing, and CI integration.
architecture-decision-records
Comprehensive patterns for creating, maintaining, and managing Architecture Decision Records (ADRs) that capture the context and rationale behind significant technical decisions.
agent-framework-azure-ai-py
Build persistent agents on Azure AI Foundry using the Microsoft Agent Framework Python SDK.
agent-harness-fault-injection
Use when an agent workflow needs deterministic recovery evidence for sandbox, MCP/tool, worker, checkpoint, memory, or orchestration failures.
api-security
Authorized security assessment of REST, GraphQL, WebSocket, and SOAP APIs: discovery, authentication and authorization flaws (BOLA/IDOR, JWT/OAuth), rate-limit testing, and a structured multi-phase methodology.
aria
Designs the data model, API contracts, and structural foundation of the system.