Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add AbdulmalekAlshugaa/claude-agents-fullstack --skill web-app-scaffoldgit clone --depth 1 https://github.com/AbdulmalekAlshugaa/claude-agents-fullstackWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/abdulmalekalshugaa/claude-agents-fullstack/web-app-scaffold)<a href="https://agentmods.dev/skills/abdulmalekalshugaa/claude-agents-fullstack/web-app-scaffold"><img src="https://agentmods.dev/badge/skills/abdulmalekalshugaa/claude-agents-fullstack/web-app-scaffold.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00081 | $0.01492 |
| Opus 5 | $0.00041 | $0.00746 |
| Sonnet 5 | $0.00016 | $0.00298 |
| Haiku 4.5 | $0.00008 | $0.00149 |
Grade A, and why
web-app-scaffold scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 125 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Scaffold a fullstack Next.js app
Database default is PostgreSQL via Drizzle; use MongoDB/Mongoose when the user asks for it or the domain is genuinely document-shaped.
Steps
-
Create the app (confirm the name first):
pnpm create next-app@latest <name> --typescript --tailwind --eslint --app --src-dir --import-alias "@/*" --use-pnpm -
Install the stack:
# Postgres (default) pnpm add drizzle-orm pg zod @tanstack/react-query pnpm add -D drizzle-kit @types/pg @electric-sql/pglite \ vitest @vitejs/plugin-react @testing-library/react @testing-library/jest-dom jsdom \ @tanstack/react-query-devtools @tanstack/eslint-plugin-query # Mongo variant: swap drizzle-orm/pg/drizzle-kit/@types/pg/@electric-sql/pglite # for: mongoose (dep) + mongodb-memory-server (dev) pnpm dlx shadcn@latest init # then: pnpm dlx shadcn@latest add button card ... pnpm dlx shadcn@latest mcp init --client claude # writes .mcp.json (commit it)The MCP server lets Claude browse, search, and install components from any shadcn-compatible registry (including third-party ones) by name — no API key needed. See "Registries and MCP" in the
shadcn-uiskill. -
Folder layout under
src/:src/ ├── app/ # routes, layouts, route handlers │ ├── providers.tsx # 'use client': QueryClientProvider (+ devtools) │ └── api/<resource>/route.ts ├── components/ # shared UI │ └── ui/ # shadcn/ui components (CLI-generated) ├── modules/<feature>/ │ ├── components/ │ ├── services/ # all business logic + DB access │ ├── schemas/ # Zod schemas + z.infer DTO types │ ├── actions.ts # 'use server' actions (auth → parse → service) │ ├── keys.ts # query key factory │ ├── queries.ts # queryOptions factories │ └── mutations.ts # mutationOptions factories └── lib/ ├── db/ │ ├── index.ts # drizzle() client cached on globalThis │ └── schema/ # pgTable definitions (+ index.ts barrel) │ # Mongo variant: connect.ts singleton + models/ ├── query/ │ └── get-query-client.ts # server/browser-guarded QueryClient └── env.ts # Zod-validated env
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago Changed · +34 lines · +9 tokens per session e36bd6f9b685
- 8d ago First seen · 91 lines · 72 tokens per session scan A ed6fb95389f8
web-app-scaffold is a skill published in the GitHub repository AbdulmalekAlshugaa/claude-agents-fullstack (3 stars, last pushed 2d ago), licensed MIT. It adds 81 tokens to every session and 1,492 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
copilotkit-upgrade
Use when migrating a CopilotKit v1 application to v2 -- updating package imports, replacing deprecated hooks and components, switching from GraphQL runtime to AG-UI protocol runtime, and resolving breaking API changes.
nextjs-app-router
Full end-to-end tRPC setup for Next.js App Router. Covers route handler with fetchRequestHandler (GET + POST exports), TRPCProvider with QueryClientProvider, createTRPCOptionsProxy for RSC prefetching, HydrateClient/HydrationBoundary for hydration, useSuspenseQuery for Suspense, and server-side callers.
nextjs-pages-router
Set up tRPC in Next.js Pages Router with createNextApiHandler, createTRPCNext, withTRPC HOC, SSR via ssr option and ssrPrepass, SSG via createServerSideHelpers with getStaticProps, and server-side helpers for getServerSideProps prefetching.
langbot-dev
Develop, build, and debug the LangBot core backend and web frontend. Use when working inside the LangBot repository — backend (Python/Quart, src/langbot/pkg), the Vite/React web UI, HTTP API controllers/services, Alembic migrations, or the MCP server. Covers the dev environment (uv, pnpm), repo layout, the API auth…
trigger-realtime-and-frontend
Trigger.dev client/frontend surface: subscribe to runs in realtime (runs.subscribeToRun and the @trigger.dev/react-hooks hook useRealtimeRun), consume metadata and AI/text streams in React (useRealtimeStream), trigger tasks from the browser (useTaskTrigger, useRealtimeTaskTrigger), and mint scoped frontend credentials…
sanity-live-cache-components
Integrates Sanity Live with Next.js Cache Components in next-sanity v13+ apps. Sets up sanityFetch, a shared cachedSanity 'use cache' boundary, , Visual Editing, Presentation Tool, draft mode handling, and the three-layer (Page/Dynamic/Cached) component pattern with explicit perspective/stega prop-drilling. Sequences…