skills/ affaan-m/everything-claude-code

token-card

Render a token-usage stat card from local Claude Code, Codex, Gemini CLI, and OpenCode session logs and commit it into the repository as a file. Use when someone wants a current usage figure in a README, or asks for a shareable card of their coding-agent activity.

0
Installs
—
Rating
—
Success rate
1
Files scanned
Scan passedmethodology
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

1 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 3fcbf3ff9117f124… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Token Card

Produce an SVG card summarising this machine's AI coding agent usage — total tokens, equivalent API cost, current streak, and the split across agents — and write it into the working tree as a file the README can reference.

The card is a committed artifact rather than a hosted image, so it renders from the repository itself and does not depend on a third-party endpoint staying up.

When to Activate

  • Someone wants a usage figure visible in a README or docs page.
  • Someone asks for a shareable summary of their agent activity across tools.

Use /cost-report instead when the question is "what did I spend this week". The two read different sources and produce different things:

/cost-reportToken Card
Source~/.claude/metrics/costs.jsonl, written by ECC's stop:cost-tracker hookThe agents' own session logs
AgentsClaude CodeClaude Code, Codex, Gemini CLI, OpenCode
OutputTerminal summary, optional CSVAn SVG file committed to the repo

The tool this runs

@tokenchit/cli, MIT licensed: https://github.com/iyashjayesh/tokenchit

Pinned to an exact version, deliberately. @latest resolves to whatever the registry currently serves, and this tool reads local session logs — so a compromised future release would be executed with access to them before anyone had reviewed it. Pin, and raise the pin knowingly:

TOKENCHIT_VERSION=0.10.0

To check the pinned artifact before running it the first time:

npm view @tokenchit/cli@0.10.0 dist.integrity dist.tarball

Workflow

  1. Ask before the first download. npx fetches the package from the npm registry and executes it. That is a remote download of code that will read local logs, so get explicit confirmation from the user before the first run on a machine. If they decline, stop here and say what would have run.

  2. Configure, unless this is a dry run. If .tokenchit.json is absent, run:

    npx -y @tokenchit/cli@0.10.0 init
    

    It detects which agents have logs on this machine and records them. The file is meant to be committed and never contains a credential.

    Skip this entirely when the user passed --dry-run, and report that .tokenchit.json would be created. A preview that writes a config file is not a preview.

  3. Render the card. The bare command writes to the configured output — tokenchit.svg unless .tokenchit.json names another path:

    npx -y @tokenchit/cli@0.10.0 sync
    

    Append only the flags the user actually asked for, each spelled exactly as below. Do not copy a placeholder into the command — sync ignores an unrecognised positional argument rather than refusing it, so a bracketed [--dry-run] reaches the CLI as junk and the card is written anyway, which is the opposite of what was asked.

    FlagEffect
    --out <path>Write somewhere other than the configured output
    --theme auto | light | darkCard theme; auto adapts to the reader's system
    --dry-runPrint what would be written and touch nothing

    sync reads local files and sends nothing: no prompts, no code, no file contents leave the machine, and it transmits nothing to any server. The npx invocation around it is a registry download — that is the network access in this workflow, and step 1 is where it is agreed.

  4. Report and offer. Print the figures it produced — tokens, equivalent cost, streak, per-agent split — and the path written. If the repository has a README that does not yet reference the card, offer to add:

    ![tokenchit](./tokenchit.svg)
    

    sync prints the path relative to the repository root. A Markdown image resolves relative to the file it sits in, so rewrite it for the README being edited: a card at docs/usage.svg is ./docs/usage.svg from the root README but ../usage.svg from docs/zh-CN/README.md. Pasting the printed path into a nested README points at docs/zh-CN/docs/usage.svg and renders broken.

    Do not edit the README without being asked.

Stop after step 4. Publishing to the public leaderboard is a separate publish command that requires explicit opt-in, and is not part of this workflow — run it only if the user asks for it by name. unpublish removes the row and the account again.

Output

The path of the SVG, the figures it contains, and the markdown snippet for referencing it. On a dry run: what would have been written, and nothing on disk changed.

Notes

  • Requires Node.js 22 or newer (the package declares engines: { node: ">=22" }). Nothing is installed globally; npx fetches the pinned version per run.
  • Reads token counts and timestamps only.

Files

1
5.0 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from affaan-m/everything-claude-code8

accessibility

Design, implement, and audit accessible UI to WCAG 2.2 Level AA across Web, iOS, and Android — semantic ARIA roles and labels, accessibility traits and hints, focus management, contrast, target size, and screen-reader support. Use when building or auditing UI for accessibility compliance, keyboard n

Scan passed 0
agent-architecture-audit

Full-stack diagnostic for agent and LLM applications. Audits the 12-layer agent stack for wrapper regression, memory pollution, tool discipline failures, hidden repair loops, and rendering corruption. Produces severity-ranked findings with code-first fixes. Essential for developers building agent ap

Scan passed 0
agent-eval

Head-to-head comparison of coding agents (Claude Code, Aider, Codex, etc.) on custom tasks with pass rate, cost, time, and consistency metrics. Use when choosing between coding agents, or when a change to an agent setup needs measured pass rate, cost, and time rather than an impression.

Scan passed 0
agent-harness-construction

Design and optimize AI agent action spaces, tool definitions, and observation formatting for higher completion rates. Use when defining or revising an agent's tool set, action space, or observation format.

Scan passed 0
agent-introspection-debugging

Structured self-debugging workflow for AI agent failures using capture, diagnosis, contained recovery, and introspection reports. Use when an agent run fails and you need a reproducible diagnosis instead of a retry.

Scan passed 0
agent-payment-x402

Add x402 payment execution to AI agents with per-task budgets, spending controls, and non-custodial wallets. Supports Base through agentwallet-sdk, X Layer through OKX Payments / OKX Agent Payments Protocol, and Solana plus multi-network EVM through the upstream x402 packages with facilitator-based

Scan passed 0
agent-runtime-gateway-smoke-test

Verify a local agent API, temporary gateway tunnel, and remote sandbox callback with a tool-free task, then restore the original app connection.

Scan passed 0
agent-security-hardening

Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials. Use when building or reviewing an agent runtime, autonomous worker, tool gateway, memory service, or multi-tenant agent deployme

Scan passed 0

Related methodology skillsscan passed