Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/aeonfun/aeon/deploy-prototypenpx skills add aeonfun/aeon --skill deploy-prototypegit clone --depth 1 https://github.com/aeonfun/aeonWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00020 | $0.03789 |
| Opus 5 | $0.00010 | $0.01895 |
| Sonnet 5 | $0.00004 | $0.00758 |
| Haiku 4.5 | $0.00002 | $0.00379 |
Grade C, and why
deploy-prototype scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
rm -rf .pending-deploy # clear stale state from prior runs Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
Otherwise POST the inline deployment built in step 6. Write the key as the literal `{VERCEL_TOKEN}` placeholder so `./secretcurl` substitutes it internally — a bare `$VERCEL_TOKEN` on the command line is refused by the B Copies of this mod
1 near-identical copy found in the catalogue:
- deploy-prototype — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 215 lines — stays where its author put it; the contents beside it link to each section on GitHub.
${var} — What to build and deploy.
- Empty → auto-select from recent signals (articles, logs, memory topics).
- Plain text (e.g.
market heatmap) → interpret as a build brief.- Typed form
type:slug description(e.g.tool:market-heatmap volume heatmap of top-20 tokens,viz:tx-graph,api:summarize,landing:startup-idea) → usetypeto bias shape andslugas the deployment name.
Today is ${today}. Your task is to ship a small, self-contained prototype that someone could actually use in the browser today.
Steps
-
Read context. Read
memory/MEMORY.mdand the most recent entries inmemory/logs/for active topics. If running as part of a chain, scan injected upstream outputs for a concrete artifact worth making interactive. -
Pick what to build (if
${var}is empty or vague).Scan these sources, in order, for prototype-worthy signals:
output/articles/— last 7 entries by mtime: any claim, finding, or dataset that would be more useful as an interactive page?memory/topics/*.md— running narratives; pick one with a live data source (prices, feeds, markets)memory/logs/${today}.mdand the two prior days — skill outputs flagged as interestingmemory/MEMORY.md→ "Next Priorities" and "Recent Articles"
Score each candidate 1-5 on:
- Leverage — does an interactive version beat the static write-up?
- Concreteness — is the spec obvious in one sentence? (if no, reject)
- Novelty — haven't shipped this in the last 14 days (check
output/articles/prototype-*.mdby mtime and anymemory/topics/prototypes.md)
Pick the highest-total candidate. If no candidate reaches 9/15, skip building and exit as
DEPLOY_PROTOTYPE_EMPTY(step 9).Record the chosen signal — its source file(s) and one-line rationale — you'll use it in steps 6 and 7.
-
Commit to a shape before writing code. Before touching
.pending-deploy/, write out (in your reasoning, not a file):- Slug:
aeon-prototype-<descriptor>, all lowercase,[a-z0-9-], 3–50 chars after prefix (e.g.aeon-prototype-market-heatmap). If${var}supplied a typed slug, use it; otherwise derive one. - Tagline (≤90 chars) — the one-liner that appears in the page title and OG tags.
- Primary action — what is the one thing a visitor does in the first 10 seconds? (read a number, click a filter, submit an input, compare two things). If you can't name it, go back to step 2.
- Shape: static HTML+JS / static +
api/function / Next.js. Default to static single-file HTML unless the idea genuinely needs a serverless function.
- Slug:
-
Write the files.
rm -rf .pending-deploy # clear stale state from prior runs mkdir -p .pending-deploy/filesWrite all project files into
.pending-deploy/files/. This directory is the repo root — everything here is pushed to GitHub and deployed to Vercel.Quality bar — every prototype must meet these:
- Self-contained — no external build step where avoidable. Prefer one
index.htmlwith inline<style>and<script>; fall back to amain.css/main.jsonly when size justifies it. - Loads in <1s on a cold visit. No jQuery, no CDN UI libraries for a single-page tool. Vanilla JS or a ~10KB util max. No
<link rel="stylesheet">to a CDN font unless it's one font. - Mobile-first, works on a phone. Viewport meta set, tap targets ≥40px, no horizontal scroll at 360px wide.
- Share-friendly. Include
<title>,<meta name="description">,<meta property="og:title">,<meta property="og:description">,<meta property="og:type" content="website">. Skip OG image unless you generate one. - Real content, not lorem. If the prototype shows data, fetch it from a public no-auth endpoint at load time (CoinGecko, GitHub public API, public RSS, public JSON feeds) — or hardcode a recent, realistic snapshot with the timestamp visible. Never ship placeholder
[example data]. - One visible CTA or primary surface. Clear hierarchy: what does the visitor look at first?
- Works with JS disabled to at least show the tagline (progressive enhancement — not required for interactive tools, but the title and description must render server-free).
- Light + dark via
prefers-color-scheme— 4 CSS vars is enough. - No secrets. No API keys, tokens, or env vars embedded anywhere. If the idea requires auth, redesign around a public endpoint or drop the idea.
- Include a
README.mdin.pending-deploy/files/with: what it is (1 line), how to run locally (1 line), signal source (1 line link to the article/log/topic from step 2).
- Self-contained — no external build step where avoidable. Prefer one
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 215 lines · 20 tokens per session scan C 8bb7f04ace3e
deploy-prototype is a skill published in the GitHub repository aeonfun/aeon (706 stars, last pushed 2d ago), licensed MIT. It adds 20 tokens to every session and 3,789 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it C with 2 findings (recursive force delete, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
resourceful-problem-solving
Always-on guidance for solving tasks resourcefully. Teaches agents to escalate through skills, CLI tools, and custom scripts instead of refusing. Applies to any request where the agent lacks a dedicated tool.
pretext
Use when building creative browser demos with @chenglou/pretext — DOM-free text layout for ASCII art, typographic flow around obstacles, text-as-geometry games, kinetic typography, and text-powered generative art. Produces single-file HTML demos by default.
p5js
Use when users request: p5.js sketches, creative coding, generative art, interactive visualizations, canvas animations, browser-based visual art, data viz, shader effects, or any p5.js project.
excalidraw
Hand-drawn Excalidraw JSON diagrams (arch, flow, seq).
p5js
Production pipeline for interactive and generative visual art using p5.js. Creates browser-based sketches, generative art, data visualizations, interactive experiences, 3D scenes, audio-reactive visuals, and motion graphics — exported as HTML, PNG, GIF, MP4, or SVG. Covers: 2D/3D rendering, noise and particle systems…
scrapling
Web scraping with Scrapling - HTTP fetching, stealth browser automation, Cloudflare bypass, and spider crawling via CLI and Python.