web-app-scaffold

web-app-scaffold is a skill for Claude Code, Codex from AbdulmalekAlshugaa/claude-agents-fullstack. It costs 81 tokens per session (1,492 once invoked), scanned A, original, MIT.

A skill for starting full-stack web applications with Next.js, TypeScript, MongoDB, and other listed development tools. Full-stack means it covers both the user interface and server-side code.

In plain words
What is it for?
Use it to scaffold a new web app, including its application structure, data access, interface components, validation, and tests.
Why use it?
It removes the initial setup work needed to assemble a new application with these technologies.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: reads .claude/ paths; mentions CLAUDE.md.

Good fit Use it to scaffold a new web app, including its application structure, data access, interface components, validation, and tests.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/abdulmalekalshugaa/claude-agents-fullstack/web-app-scaffold
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add AbdulmalekAlshugaa/claude-agents-fullstack --skill web-app-scaffold
Clone the repo
git clone --depth 1 https://github.com/AbdulmalekAlshugaa/claude-agents-fullstack

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for web-app-scaffold

README.md
[![agentmods](https://agentmods.dev/badge/skills/abdulmalekalshugaa/claude-agents-fullstack/web-app-scaffold.svg)](https://agentmods.dev/skills/abdulmalekalshugaa/claude-agents-fullstack/web-app-scaffold)
Your own site
<a href="https://agentmods.dev/skills/abdulmalekalshugaa/claude-agents-fullstack/web-app-scaffold"><img src="https://agentmods.dev/badge/skills/abdulmalekalshugaa/claude-agents-fullstack/web-app-scaffold.svg" alt="Measured on agentmods" height="20"></a>
Per session 81 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,492 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00081 $0.01492
Opus 5 $0.00041 $0.00746
Sonnet 5 $0.00016 $0.00298
Haiku 4.5 $0.00008 $0.00149

Measured 3d ago against content hash e36bd6f9b685, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

web-app-scaffold scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/web-app-scaffold/SKILL.md · 125 lines

How it starts

The opening of the file, as written. The whole thing — 125 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Scaffold a fullstack Next.js app

Database default is PostgreSQL via Drizzle; use MongoDB/Mongoose when the user asks for it or the domain is genuinely document-shaped.

Steps

  1. Create the app (confirm the name first):

    pnpm create next-app@latest <name> --typescript --tailwind --eslint --app --src-dir --import-alias "@/*" --use-pnpm
    
  2. Install the stack:

    # Postgres (default)
    pnpm add drizzle-orm pg zod @tanstack/react-query
    pnpm add -D drizzle-kit @types/pg @electric-sql/pglite \
      vitest @vitejs/plugin-react @testing-library/react @testing-library/jest-dom jsdom \
      @tanstack/react-query-devtools @tanstack/eslint-plugin-query
    # Mongo variant: swap drizzle-orm/pg/drizzle-kit/@types/pg/@electric-sql/pglite
    # for: mongoose (dep) + mongodb-memory-server (dev)
    pnpm dlx shadcn@latest init            # then: pnpm dlx shadcn@latest add button card ...
    pnpm dlx shadcn@latest mcp init --client claude   # writes .mcp.json (commit it)
    

    The MCP server lets Claude browse, search, and install components from any shadcn-compatible registry (including third-party ones) by name — no API key needed. See "Registries and MCP" in the shadcn-ui skill.

  3. Folder layout under src/:

    src/
    ├── app/                  # routes, layouts, route handlers
    │   ├── providers.tsx     # 'use client': QueryClientProvider (+ devtools)
    │   └── api/<resource>/route.ts
    ├── components/           # shared UI
    │   └── ui/               # shadcn/ui components (CLI-generated)
    ├── modules/<feature>/
    │   ├── components/
    │   ├── services/         # all business logic + DB access
    │   ├── schemas/          # Zod schemas + z.infer DTO types
    │   ├── actions.ts        # 'use server' actions (auth → parse → service)
    │   ├── keys.ts           # query key factory
    │   ├── queries.ts        # queryOptions factories
    │   └── mutations.ts      # mutationOptions factories
    └── lib/
        ├── db/
        │   ├── index.ts      # drizzle() client cached on globalThis
        │   └── schema/       # pgTable definitions (+ index.ts barrel)
        │   # Mongo variant: connect.ts singleton + models/
        ├── query/
        │   └── get-query-client.ts  # server/browser-guarded QueryClient
        └── env.ts            # Zod-validated env
    

Read the full file on GitHub · 125 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago Changed · +34 lines · +9 tokens per session e36bd6f9b685
  2. 8d ago First seen · 91 lines · 72 tokens per session scan A ed6fb95389f8

Subscribe to this mod's changes

web-app-scaffold is a skill published in the GitHub repository AbdulmalekAlshugaa/claude-agents-fullstack (3 stars, last pushed 2d ago), licensed MIT. It adds 81 tokens to every session and 1,492 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

copilotkit-upgrade

Use when migrating a CopilotKit v1 application to v2 -- updating package imports, replacing deprecated hooks and components, switching from GraphQL runtime to AG-UI protocol runtime, and resolving breaking API changes.

CopilotKit/CopilotKit · 48 tokens

nextjs-app-router

Full end-to-end tRPC setup for Next.js App Router. Covers route handler with fetchRequestHandler (GET + POST exports), TRPCProvider with QueryClientProvider, createTRPCOptionsProxy for RSC prefetching, HydrateClient/HydrationBoundary for hydration, useSuspenseQuery for Suspense, and server-side callers.

trpc/trpc · 74 tokens

nextjs-pages-router

Set up tRPC in Next.js Pages Router with createNextApiHandler, createTRPCNext, withTRPC HOC, SSR via ssr option and ssrPrepass, SSG via createServerSideHelpers with getStaticProps, and server-side helpers for getServerSideProps prefetching.

trpc/trpc · 67 tokens

langbot-dev

Develop, build, and debug the LangBot core backend and web frontend. Use when working inside the LangBot repository — backend (Python/Quart, src/langbot/pkg), the Vite/React web UI, HTTP API controllers/services, Alembic migrations, or the MCP server. Covers the dev environment (uv, pnpm), repo layout, the API auth…

langbot-app/LangBot · 136 tokens

trigger-realtime-and-frontend

Trigger.dev client/frontend surface: subscribe to runs in realtime (runs.subscribeToRun and the @trigger.dev/react-hooks hook useRealtimeRun), consume metadata and AI/text streams in React (useRealtimeStream), trigger tasks from the browser (useTaskTrigger, useRealtimeTaskTrigger), and mint scoped frontend credentials…

triggerdotdev/trigger.dev · 148 tokens

sanity-live-cache-components

Integrates Sanity Live with Next.js Cache Components in next-sanity v13+ apps. Sets up sanityFetch, a shared cachedSanity 'use cache' boundary, , Visual Editing, Presentation Tool, draft mode handling, and the three-layer (Page/Dynamic/Cached) component pattern with explicit perspective/stega prop-drilling. Sequences…

sanity-io/next-sanity · 155 tokens