Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add YunTaiHua/illusion-agent --skill illusion-usagegit clone --depth 1 https://github.com/YunTaiHua/illusion-agentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/yuntaihua/illusion-agent/illusion-usage)<a href="https://agentmods.dev/skills/yuntaihua/illusion-agent/illusion-usage"><img src="https://agentmods.dev/badge/skills/yuntaihua/illusion-agent/illusion-usage/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/yuntaihua/illusion-agent/illusion-usage"><img src="https://agentmods.dev/badge/skills/yuntaihua/illusion-agent/illusion-usage.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 2 findings, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Privilege Escalation · line 72 Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
- low Excessive Agency · line 367 Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.Fix: Limit the skill's scope to its documented purpose. Remove instructions that enable the agent to perform actions outside its stated functionality.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00076 | $0.04215 |
| Opus 5 | $0.00038 | $0.02107 |
| Sonnet 5 | $0.00015 | $0.00843 |
| Haiku 4.5 | $0.00008 | $0.00421 |
Grade A, and why
illusion-usage scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 420 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Illusion Agent Usage: Agent Dual-Role Guide
This skill serves two scenarios. Detect your role first, then follow the matching track.
Live documentation: ALWAYS fetch the latest docs from GitHub before acting — do not rely on hardcoded commands in this skill. Repo:
https://github.com/YunTaiHua/illusion-agent. Docs:https://github.com/YunTaiHua/illusion-agent/tree/main/docs. UseWebFetch,web_fetch, or an equivalent tool to read the URLs in Reference URLs below.
Role Detection
| Your situation | Track to follow |
|---|---|
You (the agent) will invoke illusion -p as a subprocess to do coding tasks autonomously |
Track A: Agent-Driven Print Mode |
| Your human master wants to install/use Illusion Agent themselves, and you guide them | Track B: Human-Friendly TUI & Web |
| Both — you'll drive it AND teach your master | Read both tracks; Track A for your own use, Track B for your master |
Track A: Agent-Driven Print Mode
Use print mode when YOU (the agent) operate Illusion Agent as a non-interactive subprocess. Every -p invocation is an atomic request-response — no waiting for interactive input within the same turn.
A.0 Fetch Current Docs (MANDATORY before install)
Use a web fetch tool to read these in order. This skill only outlines the workflow — concrete flags, file paths, and auth providers may have changed.
- README —
https://github.com/YunTaiHua/illusion-agent - Getting Started —
https://github.com/YunTaiHua/illusion-agent/blob/main/docs/en/getting-started.md - Commands —
https://github.com/YunTaiHua/illusion-agent/blob/main/docs/en/commands.md - Settings —
https://github.com/YunTaiHua/illusion-agent/blob/main/docs/en/settings.md
If any URL 404s, fall back to PyPI (
https://pypi.org/project/illusion-agent/) and follow its homepage link. Do NOT assume commands below are current — verify against fetched docs.
A.1 Installation
Recommended (no Node.js required):
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 420 lines · 76 tokens per session scan A bf6a13bc9dac
illusion-usage is a skill published in the GitHub repository YunTaiHua/illusion-agent (51 stars, last pushed 6d ago), licensed MIT. It adds 76 tokens to every session and 4,215 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
html-artifacts
Author the HTML for a plan artifact, dashboard iframe, or Slack attachment — structure, design plan, available runtime, theming, and craft. Read this before writing HTML for saveplan, outputiframe, or slackattachhtml.
langbot-eba-adapter-dev
Build, refactor, and test LangBot platform adapters for the Event-Based Agents architecture. Use when adding or migrating Telegram, Discord, or other messaging platform adapters to the EBA adapter layout, validating unified event/message conversion, writing live adapter probes, or using standalone plugin runtime plus…
langbot-plugin-dev
Develop, debug, and test LangBot plugins. Use when creating new LangBot plugins, fixing plugin bugs, setting up a LangBot test environment, or testing plugins via WebSocket. Covers plugin component architecture (EventListener, Command, Tool), the plugin SDK API (invokellm, getllmmodels, sendmessage, plugin storage)…
bootstrap-repo-analysis
First-time analysis of a repository with no prior reviewer outcomes. Crawl historical merged-PR review feedback with the gh CLI (plus any preloaded samples), extract the team's review norms, and synthesize the initial per-repo review-style prompt. Use this for a cold-start repo; use continual-learning instead once the…
langbot-mcp-ops
Operate a LangBot instance through its built-in MCP (Model Context Protocol) server. Use when an AI agent needs to manage LangBot — list/create/update/delete bots, pipelines, models, knowledge bases, MCP servers, and skills — over MCP instead of raw HTTP. Covers the /mcp endpoint, API-key auth (web-UI lbk keys and the…
langbot-dev
Develop, build, and debug the LangBot core backend and web frontend. Use when working inside the LangBot repository — backend (Python/Quart, src/langbot/pkg), the Vite/React web UI, HTTP API controllers/services, Alembic migrations, or the MCP server. Covers the dev environment (uv, pnpm), repo layout, the API auth…