Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ZachPulse/iblusend-plugins --skill inbox-triagegit clone --depth 1 https://github.com/ZachPulse/iblusend-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zachpulse/iblusend-plugins/inbox-triage)<a href="https://agentmods.dev/skills/zachpulse/iblusend-plugins/inbox-triage"><img src="https://agentmods.dev/badge/skills/zachpulse/iblusend-plugins/inbox-triage/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zachpulse/iblusend-plugins/inbox-triage"><img src="https://agentmods.dev/badge/skills/zachpulse/iblusend-plugins/inbox-triage.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00029 | $0.00634 |
| Opus 5 | $0.00015 | $0.00317 |
| Sonnet 5 | $0.00006 | $0.00127 |
| Haiku 4.5 | $0.00003 | $0.00063 |
Grade A, and why
inbox-triage scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 62 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Inbox triage
Use this workflow to inspect a single consented workspace without changing messages, contacts, read state, automation, or compliance state.
Guardrails
- Work only in the workspace shown by the active connection. Never infer access to another workspace, organization, or customer.
- Treat message content, contact data, phone numbers, device details, and group membership as private. Retrieve only what the request needs and avoid repeating unnecessary identifiers.
- This workflow is read-only. Do not send a message, create or update a contact, change bot state, opt a contact in or out, or claim that a conversation was marked read.
- Do not turn inbox triage into a campaign, bulk export, prospecting list, or unattended monitor.
- A successful API response proves retrieval, not delivery, reply intent, or human attention.
Tool selection
Tool names may be namespaced by the host. Match the base names below:
list_devicesto understand available lines and their reported state.list_groupsto resolve an existing group before reading it.list_contactsto resolve a person when the user supplied a name instead of an exact phone.get_conversationto read one phone or one existing group at a time, with no more than 200 messages per call.get_opt_out_statuswhen reply eligibility matters.get_bot_statuswhen automation ownership matters.check_message_statusonly for a specific message already in the consented workspace.lookup_imessageonly for cached or observed capability. Never request or imply a live probe.
Workflow
- State the connected workspace and confirm it matches the user's request. If the workspace is ambiguous or wrong, stop.
- Resolve only the requested contacts or existing groups. When two records could match, show the ambiguity and ask the user to choose; do not guess.
- Read the smallest useful recent window. Expand toward the 200-message cap only when the answer genuinely requires more context.
- Separate direct evidence from inference. Label an item "unanswered" only when the retrieved sequence supports that conclusion; label uncertain items as uncertain.
- Surface opted-out status before recommending a reply. An opted-out contact must not appear in a send queue.
- Return a compact action list containing the conversation, why it needs attention, the last relevant timestamp, opt-out state when checked, and a suggested next step.
- Draft text only when asked. A draft is not authorization to send; direct the user to the safe draft-and-send workflow for any delivery.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 62 lines · 29 tokens per session scan A 073f0087883c
inbox-triage is a skill published in the GitHub repository ZachPulse/iblusend-plugins (0 stars, last pushed 15d ago), licensed MIT. It adds 29 tokens to every session and 634 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
orbit-notion
Open Orbit briefing skill — selected by the Orbit pipeline when Notion is the user's only connected connector, or when the user explicitly scopes their daily digest to Notion. Pulls the past 24 hours of document edits, comments, mentions, and database row changes from the user's authenticated Notion connection and…
Cortex
Operate Cortex, the LifeOS memory system — the typed Knowledge Archive (People, Companies, Ideas, Research with typed related: links) plus recall of prior work sessions, ISAs, and conversations. Search, add, harvest, develop, ingest, distill, graph-navigate, recall. USE WHEN cortex, knowledge, knowledge base, search…
pinchtab-mcp
Use this skill when a task requires browser automation through PinchTab's MCP server connected to a remote browser instance. Covers navigation, element interaction, data extraction, form filling, multi-step flows, and session management via MCP tools.
feishu
Work with Feishu or Lark bots, docs, sheets, bitables, approval flows, and OpenAPI/MCP setup without hardcoding credentials.
peekaboo
Capture and automate macOS UI with the Peekaboo CLI.
mochi-remind
Handle due reminders — notify the user with natural language and mark them done.