xbot-dev

xbot-dev is a command for Claude Code from TidyBot-Services/Tidybot-Universe. It costs 0 tokens per session (1,313 once invoked), scanned C, original, Apache-2.0.

A command that starts development for all skills whose required services are available. It first checks the orchestrator, agent server, optional simulator, and service catalog.

In plain words
What is it for?
Use it to check prerequisites and launch development for ready skills, including projects that depend on a robot simulator or remote GPU services.
Why use it?
It shows whether the development environment is ready and points out stopped services or unavailable remote servers before work begins.

Command for Claude Code

Written for Claude Code: installed under .claude/.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/tidybot-services/tidybot-universe/xbot-dev
Clone the repo
git clone --depth 1 https://github.com/TidyBot-Services/Tidybot-Universe

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for xbot-dev

README.md
[![agentmods](https://agentmods.dev/badge/commands/tidybot-services/tidybot-universe/xbot-dev.svg)](https://agentmods.dev/commands/tidybot-services/tidybot-universe/xbot-dev)
Your own site
<a href="https://agentmods.dev/commands/tidybot-services/tidybot-universe/xbot-dev"><img src="https://agentmods.dev/badge/commands/tidybot-services/tidybot-universe/xbot-dev.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,313 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 2 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.01313
Opus 5 $0.00000 $0.00656
Sonnet 5 $0.00000 $0.00263
Haiku 4.5 $0.00000 $0.00131

Measured 6d ago against content hash 9dcd273bd126, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade C, and why

xbot-dev scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Downloads and executes remote codehighSupply chain

curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.

curl -s http://localhost:8766/entries | python3 -c "

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

curl -sf http://localhost:8766/entries # orchestrator
skill-agent-setup/claude-code/.claude/commands/xbot-dev.md · 164 lines

How it starts

The opening of the file, as written. The whole thing — 164 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/xbot-dev — Start development on ready skills

Kick off the dev pipeline for all skills whose dependencies are satisfied.

Usage

/xbot-dev

What to do

  1. Check prerequisites. All three services must be running:
curl -sf http://localhost:8766/entries  # orchestrator
curl -sf http://localhost:8080/state    # agent server

If the sim is needed (RoboCasa tasks), also check:

nc -z localhost 5500                    # sim

Also check the service catalog and remote server health:

curl -sf http://localhost:8090/health   # service catalog

If the service catalog is running, check:

  • server_reachable — is the remote GPU server accessible?
  • alert — any active alerts (server unreachable)?
  • List any services with status: "server_down" or status: "stopped" that skills may depend on

If the catalog is not running, warn the user and suggest:

Run /xbot-server to set up the service catalog first.

If the remote server is unreachable, warn the user that GPU services (GraspGen, GroundedSAM, etc.) will not be available and skills depending on them will fail.

If any local service is down, tell the user what to start and stop.

  1. Show the current tree. Fetch GET /entries and display it with statuses:
curl -s http://localhost:8766/entries | python3 -c "
import json, sys
entries = json.load(sys.stdin)
for e in entries:
    deps = ', '.join(e.get('dependencies', [])) or '(leaf)'
    status = e.get('status', 'planned')
    print(f'  [{status:>10}] {e[\"name\"]:30s} deps: {deps}')
"
  1. Generate SKILL.md for each skill. Before starting dev agents, generate a SKILL.md for every skill in the graph that doesn't have one yet. For each skill:

    • Read the graph entry (name, description, dependencies)
    • Read the graph metadata (graph.json) for task context
    • If it has dependencies, read those dependency skills' SKILL.md files to understand what inputs/outputs they provide
    • Write SKILL.md to skills/<skill-name>/SKILL.md with this structure:

Read the full file on GitHub · 164 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 164 lines · 0 tokens per session scan C 9dcd273bd126

Subscribe to this mod's changes

xbot-dev is a command published in the GitHub repository TidyBot-Services/Tidybot-Universe (56 stars, last pushed 2mo ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 1,313 tokens. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.