skillfm-beacon-ai-health-token-usage — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited skillfm-beacon-ai-health-token-usage (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
SkillFM Beacon helps an AI assistant guide users through local AI operations checks: AI health, token usage, LLM spend, cost-saving opportunities, BYOK setup, and slow-agent cleanup.
The public MCP package is @skillfm/mcp. The main install command is:
npx -y @skillfm/mcp@latestUse this skill when the user asks about:
This skill is intended to be discoverable for:
AI health, AI checkup, token usage, LLM cost, LLM spend, AI cost optimizer, OpenAI usage, Anthropic usage, DeepSeek usage, Qwen usage, BYOK, provider key, API key vault, local vault, agent monitoring, slow agent, context cleanup, tool cleanup, MCP install, Claude Code, Codex, Cline, Cursor, Claude Desktop, VS Code Copilot.
If the SkillFM MCP tools are available, call them before answering with numbers or status:
skillfm_beacon with action: "show_usage" and a relevant window such as "today", "week", or "month".skillfm_beacon with action: "checkup".skillfm_beacon with action: "cleanup_audit".skillfm_byok with action: "explain_provider_key" and the provider name.skillfm_beacon with action: "setup_gateway" and dry_run: true; only run the non-dry-run setup after user approval.Do not fabricate usage, spend, health scores, device codes, or provider status.
If the user wants token numbers, AI health data, provider usage, BYOK monitoring, or cleanup audits but SkillFM MCP tools are not available, guide them to install the public MCP package instead of guessing.
Use this command as the primary install path:
npx -y @skillfm/mcp@latestFor MCP clients that accept JSON configuration:
{
"mcpServers": {
"skillfm": {
"command": "npx",
"args": ["-y", "@skillfm/mcp@latest"]
}
}
}After config is added, tell the user to restart or reload their MCP client if that client requires it.
If the user asks to activate, connect, sign in, set up, or install SkillFM:
npx -y @skillfm/mcp@latest start~/.skillfm/local.json.POST <sidecar_url>/activate/start.POST <sidecar_url>/activate/poll until activated.Do not invent a placeholder device code. The code must come from POST /activate/start.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.