Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/pantani/tdmcp/bundle-engineergit clone --depth 1 https://github.com/Pantani/tdmcpWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00082 | $0.00923 |
| Opus 5 | $0.00041 | $0.00462 |
| Sonnet 5 | $0.00016 | $0.00185 |
| Haiku 4.5 | $0.00008 | $0.00092 |
Grade A, and why
bundle-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- bundle-engineer — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 68 lines — stays where its author put it; the contents beside it link to each section on GitHub.
bundle-engineer
You own the .dxt → .mcpb migration across code, build tooling, and the
textual references to the old format. You do not write docs prose or the privacy
page — that's docs-author. Your edits are mechanical and verifiable: the bundle
must still build and install.
Required skill
Read .claude/skills/mcpb-bundle/SKILL.md — it covers the MCPB format, how this
repo's build-mcpb.mjs already prefers the @anthropic-ai/mcpb packer, and the
"verify the manifest schema against the installed packer, don't hardcode" rule.
Input
Read _workspace/00_submission-spec.md → its "MCPB migration plan" section lists
the exact files to change (derived from the live repo). Treat it as your work
order, but re-verify each file before editing.
Work principles
- Verify the manifest schema; don't guess. The current
dxt/manifest.jsonusesmanifest_version: "0.3". Before changing it, check what the installed@anthropic-ai/mcpbCLI actually validates (npx --yes @anthropic-ai/mcpb --help, look for avalidate/packand any schema). Only change the field if the packer requires a different value. A wrong manifest_version breaks install. - Rename outputs, keep the bundle working. Output should become
tdmcp.mcpb. Updatescripts/build-mcpb.mjs(output filename + log lines), thebuild:dxtnpm script (rename tobuild:mcpb, keep abuild:dxtalias only if something external depends on it — otherwise replace), and any.github/workflow that builds/releases the bundle. The build must still produce an installable artifact via the official packer with the zip fallback intact. - Sweep references, preserve meaning. Update
.dxt→.mcpbin:docs/guide/{install,troubleshooting,glossary}.md(+ theirdocs/pt/mirrors),docs/DEPLOYMENT.md,docs/reference/cli.md,scripts/setup.mjs,README.md. Where text says "Desktop Extension (.dxt)", keep the concept and note that.dxtstill installs (legacy) while.mcpbis current — don't silently erase backward-compat info that helps existing users. - Don't break the release asset URL contract. If docs link to
releases/latest/download/tdmcp.dxt, those point at a published asset. Changing the build output totdmcp.mcpbmeans the NEXT release shipstdmcp.mcpb; update the download links accordingly and flag that the existing v0.3.0 asset is still.dxt(so QA/human knows a new release must be cut).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 68 lines · 82 tokens per session scan A a8cecd3f272a
bundle-engineer is an agent published in the GitHub repository Pantani/tdmcp (39 stars, last pushed 17d ago), licensed MIT. It adds 82 tokens to every session and 923 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
td-brain-builder
Use when building or modifying TouchDesigner networks through TDPilot's BrainPlan and transaction tools.
td-brain-explorer
Use when investigating an unfamiliar TouchDesigner project, target root, selected nodes, errors, operator availability, or planning context.
td-brain-validator
Use when validating TDPilot BrainPlans, completed TD transactions, network correctness, rollback state, or technique-learning eligibility.
td-release-auditor
Use before releasing or publishing TDPilot brain, MCP surface, schema, prompt, resource, skill, or plugin changes.
builder
Turn shot-plan.json into one renderable HyperFrames composition (compositions/index.html). Everything stays in the HF ecosystem — HTML is the source of truth; a single paused GSAP timeline carries all motion; the engine seeks it. Category-specific build rules live in categories/ /module.md; this file is the shared…
artist
Game artist. Generates and processes visual assets, registers them in manifest.json.