Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/microsoft/ufo/server_client_architecturegit clone --depth 1 https://github.com/microsoft/UFOWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.05721 |
| Opus 5 | $0.00000 | $0.02861 |
| Sonnet 5 | $0.00000 | $0.01144 |
| Haiku 4.5 | $0.00000 | $0.00572 |
Grade A, and why
server_client_architecture scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 792 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Server-Client Architecture
Device agents in UFO are partitioned into server and client components, separating high-level orchestration from low-level execution. This architecture enables safe, scalable, and flexible task execution across heterogeneous devices through the Agent Interaction Protocol (AIP).
Overview
To support safe, scalable, and flexible execution across heterogeneous devices, each device agent is partitioned into two distinct components: a server and a client. This separation of responsibilities aligns naturally with the layered FSM architecture and leverages AIP for reliable, low-latency communication.
Architecture Benefits
| Benefit | Description |
|---|---|
| 🔒 Safe Execution | Separates reasoning (server) from system operations (client), reducing risk |
| 📈 Scalable Orchestration | Single server can manage multiple clients concurrently |
| 🔧 Independent Updates | Server logic and client tools can be updated independently |
| 🌐 Multi-Device Support | Clients can be rapidly deployed on new devices with minimal configuration |
| 🛡️ Fault Isolation | Client failures don't crash the server's reasoning logic |
| 📡 Real-Time Communication | Persistent WebSocket connections enable low-latency bidirectional messaging |
Design Philosophy:
The server-client architecture embodies the separation of concerns principle: the server focuses on what to do (strategy), while the client focuses on how to do it (execution). This clear division enhances maintainability, security, and scalability.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 792 lines · 0 tokens per session scan A ccd19236b535
server_client_architecture is an agent published in the GitHub repository microsoft/UFO (9,589 stars, last pushed 8d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 5,721 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
director
Turn a request into a shot-plan.json for a short (3–30s) design-led motion graphic. You run in two parts around the asset-sourcing step: Part 1 (plan) before sourcing, Part 2 (design) after. You do NOT write composition code — that's the Builder. Schema: references/shot-plan-ir.md.
builder
Turn shot-plan.json into one renderable HyperFrames composition (compositions/index.html). Everything stays in the HF ecosystem — HTML is the source of truth; a single paused GSAP timeline carries all motion; the engine seeks it. Category-specific build rules live in categories/ /module.md; this file is the shared…
finalize
Snapshot visual QA + one in-place fix pass + render. Dispatched only when Step 6 lint/inspect reports issues, or to do the final render.
prompt-engineer
Author and adapt prompts — discover, draft, deliver — under HITL approvals. Full subagent.
winui-dev
Builds WinUI 3 desktop applications using Windows App SDK, XAML, and C#. Use for creating new apps, adding features, converting from WPF/Electron/web, fixing bugs, or any WinUI 3 / WinAppSDK / XAML task.
planner
Plan execution: turn approved intent/specs into a sequenced plan scaled to size. Full subagent.