Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/khadinakbarlabs/shopify-app-builder/opencodegit clone --depth 1 https://github.com/khadinakbarlabs/shopify-app-builderWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00402 |
| Opus 5 | $0.00000 | $0.00201 |
| Sonnet 5 | $0.00000 | $0.00080 |
| Haiku 4.5 | $0.00000 | $0.00040 |
Grade A, and why
opencode scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
OpenCode guide
OpenCode can load the toolkit as a native, dependency-free package that registers the canonical Agent Skills directory. Portable copying remains available as a fallback.
Install
Add the package to opencode.json:
{
"plugin": [
"shopify-app-builder@git+https://github.com/khadinakbarlabs/shopify-app-builder.git"
]
}
Restart OpenCode after changing the configuration.
Portable fallback:
npx skills add khadinakbarlabs/shopify-app-builder --skill '*' --agent opencode --copy --yes
Copy-only npm fallback:
npx shopify-app-builder install --agent opencode --global
Best use cases
- Terminal-led Shopify CLI, extension, function, and deployment diagnostics.
- Focused repository implementation using named skills.
- GraphQL, webhook, authentication, and billing reviews that benefit from shell evidence.
- App listing and validation work where the output is a repository artifact.
Operating guidelines
- Ask OpenCode to load
using-shopify-app-builderbefore broad work, then name the selected focused skills. - Treat the skill text as domain guidance and the repository/runtime output as the evidence source.
- Require exact commands and observed output for fixes; never assume a deployment succeeded.
- Keep credentials out of prompts, logs, commits, and generated fixtures.
- Require explicit approval before deployment, submission, billing changes, or paid spend.
Example prompts
Load using-shopify-app-builder and diagnose why shopify app dev fails in this repo.
Use shopify-functions to review this discount function against runtime limits.
Use merchant-pain-prevention before we ship this uninstall flow.
Verify
Start a new OpenCode session in a test repository and ask it to read using-shopify-app-builder. Confirm a GraphQL throttling question routes to admin-graphql and dev-troubleshooting.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 57 lines · 0 tokens per session scan A 150a77626a9b
opencode is an agent published in the GitHub repository khadinakbarlabs/shopify-app-builder (1 stars, last pushed 23d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 402 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
agents-directory
Developer reference for all 11 Oh My OpenAgent agent definitions, factory patterns, tool restrictions, and model routing.
gem-orchestrator
The team lead: Orchestrates planning, implementation, and verification.
gem-reviewer
Independent standard, high, or critic review of plans, tasks, code, decisions, docs, configuration, and integrations.
gem-devops
Infrastructure deployment, CI/CD pipelines, container management.
gem-researcher
Codebase exploration: patterns, relationships, architecture discovery. Supports multiple exploration modes for cost-controlled research.
momus
Momus is a practical work plan reviewer. Its job is to answer one question.