Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/rahmanef63/control-room/vps-pagegit clone --depth 1 https://github.com/rahmanef63/control-roomWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/rahmanef63/control-room/vps-page)<a href="https://agentmods.dev/commands/rahmanef63/control-room/vps-page"><img src="https://agentmods.dev/badge/commands/rahmanef63/control-room/vps-page.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00576 |
| Opus 5 | $0.00000 | $0.00288 |
| Sonnet 5 | $0.00000 | $0.00115 |
| Haiku 4.5 | $0.00000 | $0.00058 |
Grade A, and why
vps-page scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 80 lines — stays where its author put it; the contents beside it link to each section on GitHub.
VPS Control Room — Svelte Page Pattern
Use this pattern for a terminal-scoped frontend page or substantial page refactor. Root CLAUDE.md remains the SSOT. Do not add a new page for provider management, browser automation, scheduling, managed apps, or other non-terminal product scope.
Location
frontend/src/routes/<route>/+page.svelte
frontend/src/routes/<route>/+page.server.ts # only when server-side page loading is useful
frontend/src/routes/<route>/+error.svelte # when route-level recovery needs custom UX
frontend/src/lib/features/<feature>/ # reusable feature logic/components
Do not build large feature logic directly into +page.svelte; keep the route as orchestration and place domain logic in a vertical slice.
Svelte 5 state
<script lang="ts">
let loading = $state(true);
let error = $state<string | null>(null);
let items = $state<Item[]>([]);
let count = $derived(items.length);
async function refresh() {
loading = true;
error = null;
try {
const response = await fetch('/api/example');
if (!response.ok) throw new Error(`HTTP ${response.status}`);
items = await response.json();
} catch (cause) {
error = cause instanceof Error ? cause.message : String(cause);
} finally {
loading = false;
}
}
</script>
Use $props(), $state, $derived, $effect, and snippets. Do not introduce legacy component syntax or shared writable/readable stores.
Data boundary
Frontend pages talk to authenticated SvelteKit server routes. Those server routes may proxy to the Node agent through $lib/server/gateway. Host access never occurs in the page/component itself.
For privileged proxy routes:
const denied = await requireSession(event);
if (denied) return denied;
return proxyGatewayJson('/some-agent-path');
Terminal live output is a special case: browser SSE is bridged server-side to the agent WebSocket. Do not invent a direct browser-to-agent socket.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · -66 lines a55e73de8a5d
- 5d ago First seen · 146 lines · 0 tokens per session scan A fbacbc644465
vps-page is a command published in the GitHub repository rahmanef63/control-room (19 stars, last pushed yesterday), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 576 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
portaljs-architect
Recommend a data-portal architecture (storage, compute, catalog, access, hosting, metadata) from your needs, then hand off to the build skills. The advisory entry point.
portaljs-check-data-quality
Audit a local or remote tabular file (CSV/TSV) for common data quality issues. Read-only. Use only when the user explicitly asks to check or audit data quality.
upgrade-webkit
Upgrade Bun's WebKit fork to the latest upstream version of WebKit.
dedupe
Find duplicate GitHub issues.
memory-store
Store an insight, decision, or pattern to memory.
dev
Runs Vendure in development mode. By default it starts three processes: the GraphQL server (ts-node ./src/index.ts), the worker (ts-node ./src/index-worker.ts), and the dashboard (a Vite dev server).