Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/a8cteam51/claude-code-plugins/setupnpx skills add a8cteam51/claude-code-plugins --skill setupgit clone --depth 1 https://github.com/a8cteam51/claude-code-pluginsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00145 | $0.02505 |
| Opus 5 | $0.00072 | $0.01252 |
| Sonnet 5 | $0.00029 | $0.00501 |
| Haiku 4.5 | $0.00015 | $0.00250 |
Grade A, and why
setup scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
**Assume a non-technical user from the start.** One step at a time, waiting after each; exact click paths using wp-admin's literal labels (the words on their screen are how they find things); credentials explained in pla How it starts
The opening of the file, as written. The whole thing — 117 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Set up AI-Canvas on a WordPress site
Goal: end state is claude mcp list showing an ai-canvas server connected to the user's site.
Role split — this is the core of the skill. The user performs every step that changes their site (installing plugins, creating the user, creating the Application Password) with you explaining exactly what to do and waiting; you never run wp-cli against their site, install anything, or create users/credentials yourself, even if tooling for it is available. Once you hold the three inputs — site URL, username, Application Password — you automate everything that remains: verification, diagnosis, and MCP registration.
Assume a non-technical user from the start. One step at a time, waiting after each; exact click paths using wp-admin's literal labels (the words on their screen are how they find things); credentials explained in plain terms ("an Application Password is a separate password created just for this connection — your normal login is untouched"); no jargon — "MCP", "endpoint", "curl", and HTTP status codes stay out of user-facing text, and every failed check is reported as what happened plus what to do next. If the user turns out to be technical, condense; never the reverse.
Phase A — guided manual setup (the user acts, you instruct)
Present each step, then wait for the user to confirm before moving on. Adapt the instructions if they mention having wp-cli/SSH — give them commands to run themselves, never run the commands for them.
A1. Confirm the site qualifies
Ask the user to verify, telling them where to look:
- WordPress 6.9+ — wp-admin Dashboard → Updates shows the current version (or
wp core versionif they have shell). - A block theme is active — Appearance shows an Editor entry (block themes) rather than Customize (classic). All bundled default themes since Twenty Twenty-Two qualify.
- HTTPS — Application Passwords are disabled over plain HTTP (local Studio sites excepted).
If any check fails, stop and explain what to change first — the plugin does not degrade gracefully on classic themes or older WordPress.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 117 lines · 145 tokens per session scan A b27af5665564
setup is a skill published in the GitHub repository a8cteam51/claude-code-plugins (3 stars, last pushed 4d ago), licensed MIT. It adds 145 tokens to every session and 2,505 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…