Agent skill

Detect Magic

by Hmbown in Hmbown/Wizards-of-the-Ghosts

A skill your agent uses when you need a fast, structured scan for where the real magic is hiding in a repo, workflow, or system.

CC0-1.0Auto-check passedBackend & APIs

Install Detect Magic

skills CLI
$ npx skills add Hmbown/Wizards-of-the-Ghosts --skill detect-magic -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hmbown/Wizards-of-the-Ghosts detect-magic --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hmbown/Wizards-of-the-Ghosts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/generated/openclaw/detect-magic .claude/skills/detect-magic && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detect-magic
GitHub stars
109
Token cost
~651 tokens
SKILL.md length
321 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
CC0-1.0

At a glance

A skill your agent uses when you need a fast, structured scan for where the real magic is hiding in a repo, workflow, or system.

  • Works in 6 steps: Inventory obvious entrypoints: README,… → Trace outward to hidden capability… → Identify background jobs, cron,… → …
  • You need a fast
  • SKILL.md covers Overview, When To Use, Workflow and Deliverables, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Detect Magic is an agent skill from Hmbown/Wizards-of-the-Ghosts. Use this skill when you need a fast, structured scan for where the real magic is hiding in a repo, workflow, or system.

Its SKILL.md is about 650 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. The repository describes itself as: Unofficial Hermes Agent skill pack built from fantasy spell and skill names. The licence is CC0-1.0.

When your agent uses it

  • You need a fast
  • Structured scan for where the real magic is hiding in a repo

Example prompts

  • “/detect-magic”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Inventory obvious entrypoints: README, package manifests, setup docs, scripts/, CI/CD folders, env templates.
  2. Trace outward to hidden capability surfaces: model providers, tool registries, function-calling schemas, MCP config, plugin loaders, shell…
  3. Identify background jobs, cron, schedulers, queues, workers, webhooks, event consumers, notification hooks.
  4. Call out surprising affordances, dangerous edges, missing observability, and fan-out points.
  5. Return a compact map of confirmed mechanisms, inferred mechanisms, and unknowns needing follow-up.
  6. Separate confirmed findings from inference every time — use explicit uncertainty language.

What it can do on your machine

Read from SKILL.md and the folder at commit 1f2e6a0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detect Magic loads about 651 tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 321 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~651

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hmbown/Wizards-of-the-Ghosts at commit 1f2e6a0, republished under its CC0-1.0 licence (© Hmbown). 321 words, ~651 tokens.

Download SKILL.mdSave it as .claude/skills/detect-magic/SKILL.md (or your agent's skills folder).
name
detect-magic
description
Use this skill when you need a fast, structured scan for where the real magic is hiding in a repo, workflow, or system.
user-invocable
true

Detect Magic

Surface hidden AI affordances, agents, automations, and tool hooks before acting.

Overview

Detect Magic is interpreted here as a metaphorical spell with a shipping-now execution model.

Canonical source: Detect Magic (spell)

Provider target: OpenClaw

When To Use

  • You need a preflight scan of a repo or system before making any changes.
  • You need to map where automation, model behavior, and side effects actually live.
  • You want to inventory hidden capability surfaces: model providers, tool registries, shell bridges, webhooks, schedulers.
  • You need to identify surprising affordances, dangerous edges, or missing observability.
  • The request involves AI tooling, agents, starter kits, or model behavior scanning.

Workflow

  1. Inventory obvious entrypoints: README, package manifests, setup docs, scripts/, CI/CD folders, env templates.
  2. Trace outward to hidden capability surfaces: model providers, tool registries, function-calling schemas, MCP config, plugin loaders, shell bridges.
  3. Identify background jobs, cron, schedulers, queues, workers, webhooks, event consumers, notification hooks.
  4. Call out surprising affordances, dangerous edges, missing observability, and fan-out points.
  5. Return a compact map of confirmed mechanisms, inferred mechanisms, and unknowns needing follow-up.
  6. Separate confirmed findings from inference every time — use explicit uncertainty language.

Deliverables

  • A concise capability inventory mapping all discovered execution surfaces.
  • A risk list covering hidden side effects or untrusted execution paths.
  • A shortlist of follow-up skills or next actions (e.g. $identify, $zone-of-truth, $glyph-of-warding).

Guardrails

  • Do not claim magic where there is only speculation — separate proof from suspicion.
  • Do not execute risky hooks, automations, deploys, rollbacks, webhooks, or billing mutations just to prove they exist.
  • Treat dependency or environment artifacts carefully — a binary suggests tooling is installed but does not prove the repo ships that capability.
  • Use explicit uncertainty language: Confirmed, Inferred not confirmed, Unknown from repo evidence.
  • Do not drift into generic security-review prose — sound like a structured capability-scan ritual.

Default Invocation

Use $detect-magic to scan this repo for hidden AI tooling, agents, MCP servers, and automation hooks before we change anything.

© Hmbown, CC0-1.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in generated/openclaw/detect-magic of Hmbown/Wizards-of-the-Ghosts.

Open the folder on GitHubat commit 1f2e6a0

Compare with similar skills

Detect Magic next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detect Magic compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detect Magic this skillHmbown/Wizards-of-the-Ghosts109—~651Automated safety check: PassCC0-1.0
Rtvi Vlm Perf TestingNVIDIA-AI-Blueprints/video-search-and-summarization1.9k—~8.6kAutomated safety check: NotesApache-2.0
Mintlify APImacro-inc/macro4.6k2 repos~333Automated safety check: PassMIT
Frappe Ops Website DeployImpertio-Studio/Frappe_Claude_Skill_Package187—~2.5kAutomated safety check: PassMIT
Noodle Usewilfredinni/noodle363—~8.5kAutomated safety check: NotesApache-2.0
Supercheck Feature Implementationsupercheck-io/supercheck215—~1.1kAutomated safety check: PassAGPL-3.0

Similar skills

  • Rtvi Vlm Perf Testing

    NVIDIA-AI-Blueprints/video-search-and-summarization

    Plan, run, and diagnose reproducible RT-VLM GPU performance canaries and benchmarks.

    1.9k GitHub stars~8.6k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Mintlify API

    macro-inc/macro

    Interact with the Mintlify REST API to manage deployments, trigger builds, and query documentation site metadata programmatically.

    4.6k GitHub starsUsed in 2 repos~333 tokens
    Backend & APIsAuto-check passed
  • Frappe Ops Website Deploy

    Impertio-Studio/Frappe_Claude_Skill_Package

    Deploy HTML/CSS websites to ERPNext/Frappe (v15/v16) as Web Pages via the REST API.

    187 GitHub stars~2.5k tokensUpdated 21 days ago
    Backend & APIsAuto-check passed
  • Noodle Use

    wilfredinni/noodle

    Teach agents to create, organize, maintain, evaluate, import, convert, and automate noodle terminal REST client collections using supported CLI commands plus YAML and dotenv files.

    363 GitHub stars~8.5k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Supercheck Feature Implementation

    supercheck-io/supercheck

    Implement a new or changed Supercheck feature end to end across schema, auth/RBAC, services, routes/actions, UI, queues/workers, CLI/recorder, tests, docs, and deployment contracts.

    215 GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Flow Nexus Platform

    ruvnet/agentic-flow

    Comprehensive Flow Nexus platform management - authentication, sandboxes, app deployment, payments, and challenges

    816 GitHub starsUsed in 4 repos~6.4k tokens
    Backend & APIsAuto-check passed

More from Hmbown/Wizards-of-the-Ghosts

All 11 skills in this repo
  • Animate Objects

    Hmbown/Wizards-of-the-Ghosts

    This spell transforms inert → reactive. An agent skill from Hmbown/Wizards-of-the-Ghosts.

    109 GitHub stars~804 tokensUpdated 6 mo ago
    Auto-check passed
  • Dancing Lights

    Hmbown/Wizards-of-the-Ghosts

    Use this spell for lightweight indicators: status pips, progress markers, heartbeat widgets, and ambient observability that help humans orient quickly.

    109 GitHub stars~528 tokensUpdated 6 mo ago
    Auto-check passed
  • Dispel Magic

    Hmbown/Wizards-of-the-Ghosts

    Use this spell when you need to cleanly shut down, disable, or remove active AI tooling — the reverse of Detect Magic.

    109 GitHub stars~430 tokensUpdated 6 mo ago
    Auto-check passed
  • Foresight

    Hmbown/Wizards-of-the-Ghosts

    Foresight produces bounded forecasts with explicit uncertainty to guide decisions.

    109 GitHub stars~779 tokensUpdated 6 mo ago
    Auto-check passed
  • Glyph Of Warding

    Hmbown/Wizards-of-the-Ghosts

    A skill your agent uses when you need a watchful boundary around files, systems, metrics, queues, or workflows.

    109 GitHub stars~461 tokensUpdated 6 mo ago
    Auto-check passed
  • Heat Metal

    Hmbown/Wizards-of-the-Ghosts

    In D&D, Heat Metal makes a metal object painfully hot — the creature holding it must either endure the pain or drop it.

    109 GitHub stars~633 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Detect Magic

What does Detect Magic do?

A skill your agent uses when you need a fast, structured scan for where the real magic is hiding in a repo, workflow, or system. Detect Magic is an agent skill from Hmbown/Wizards-of-the-Ghosts. Use this skill when you need a fast, structured scan for where the real magic is hiding in a repo, workflow, or system.

When should I use Detect Magic?

Detect Magic fits situations like: you need a fast; structured scan for where the real magic is hiding in a repo.

How do I install Detect Magic in Claude Code?

Run `npx skills add Hmbown/Wizards-of-the-Ghosts --skill detect-magic -a claude-code`. Or copy the skill folder (generated/openclaw/detect-magic in Hmbown/Wizards-of-the-Ghosts) into .claude/skills/detect-magic in your project. Claude Code loads it when a task matches its description.

How do I install Detect Magic in Codex?

Run `npx skills add Hmbown/Wizards-of-the-Ghosts --skill detect-magic -a codex`. Or copy the skill folder (generated/openclaw/detect-magic in Hmbown/Wizards-of-the-Ghosts) into .agents/skills/detect-magic in your project. Codex loads it when a task matches its description.

Can I use Detect Magic in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hmbown/Wizards-of-the-Ghosts --skill detect-magic -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detect-magic, .gemini/skills/detect-magic, .github/skills/detect-magic and .opencode/skills/detect-magic in your project.

What does Detect Magic need to run?

SKILL.md names no scripts, command-line tools or credentials: Detect Magic is instructions for the agent only.

Does Detect Magic access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Detect Magic safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Detect Magic use?

Detect Magic is published under the CC0-1.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detect Magic use?

About 651 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Detect Magic?

Skills that share tags, products or a category with Detect Magic: Rtvi Vlm Perf Testing (NVIDIA-AI-Blueprints/video-search-and-summarization, 1.9k stars), Mintlify API (macro-inc/macro, 4.6k stars), Frappe Ops Website Deploy (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars) and Noodle Use (wilfredinni/noodle, 363 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detect Magic?

Hmbown (a GitHub user) maintains it in Hmbown/Wizards-of-the-Ghosts, which has 109 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on April 5, 2026.

Source: Hmbown/Wizards-of-the-Ghosts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.