apple

A scraping guide for Apple's online product-configuration pages, such as the Mac, iPhone, iPad, and Watch buying pages. It explains how to read product, price, colour, chip, storage, and other configuration data embedded in the page's HTML.

In plain words
What is it for?
Use it to extract product options and prices from Apple's supported shop buying pages.
Why use it?
It provides a way to collect the configuration data with a normal page request instead of relying on a browser or separate network calls. The input describes Apple's page structure and extraction approach.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/agentcomputerai/torch/apple
Any agent
npx skills add AgentComputerAI/torch --skill apple
Clone the repo
git clone --depth 1 https://github.com/AgentComputerAI/torch

Made for: Claude Code, Codex.

Per session 127 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,487 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00127 $0.02487
Opus 5 $0.00063 $0.01243
Sonnet 5 $0.00025 $0.00497
Haiku 4.5 $0.00013 $0.00249

Measured yesterday against content hash ca4ff99a44b6, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

apple scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

| Status | 200 to bare `curl` with no UA tricks |
skills/sites/apple/SKILL.md · 179 lines

How it starts

The opening of the file, as written. The whole thing — 179 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Apple Store buy-flow (apple.com/shop/buy-*)

Apple's online store is a thin client over a giant SSR HTML page. The configurator state — every SKU, color, chip, price, customization option — is embedded inline as JavaScript object literals. No XHRs needed: fetch the page, find the bootstrap, extract the inner JSON. Sub-second scrape, 0 anti-bot.

Detection

Signal Value
Server Server: Apple (custom edge, not Akamai/CF)
Status 200 to bare curl with no UA tricks
Framework Custom AS (Apple Store) buyflow — not Next/Nuxt
Anti-bot None on /shop/buy-* HTML
robots.txt Allows /shop/buy-* for Googlebot etc.
Auth None required

Architecture

The buyflow page ships ~550 KB of HTML containing several window.*_BOOTSTRAP = blocks injected by the server:

  • window.PRODUCT_SELECTION_BOOTSTRAPthe one you want. Holds productSelectionData with products[], mainDisplayValues (colors, sizes, chips, prices), and configDisplayValues (memory, storage, adapter, keyboard).
  • window.PURCHASE_OPTIONS_BOOTSTRAP — checkout/financing options.
  • window.APPLECARE_BOOTSTRAP — AppleCare add-ons.
  • window.TRADEUP_BOOTSTRAP — trade-in calculator data.
  • window.LOCATION_BOOTSTRAP, window.ECHO_CONFIG, window.GLOBAL_ASSETS, window.NAMED_ASSETS, window.ACI_CONFIG_MAP, window.BUYFLOW_MESSAGES_BOOTSTRAP — UI/i18n/asset metadata.

The React-ish client just hydrates from these. There is no /api/ you need to call for the configurator — everything is server-printed.

Strategy used

  • Phase 0 (curl)curl -sL returns 200 with the full HTML. Done.
  • Phase 1/2 skipped.

Stealth config

None required. Plain fetch works. One gotcha: Node's undici occasionally hangs on Apple's edge over IPv6 (ETIMEDOUT from internalConnectMultiple). Force IPv4:

Read the full file on GitHub · 179 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 179 lines · 127 tokens per session scan A ca4ff99a44b6

Subscribe to this mod's changes

apple is a skill published in the GitHub repository AgentComputerAI/torch (5 stars, last pushed 4mo ago), licensed MIT. It adds 127 tokens to every session and 2,487 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

tiny-web-crawler

Crawl from one or more starting web pages, fetch readable content, search within pages, follow relevant links, and stop when the requested information is found or a bounded limit is reached.

leon-ai/leon · 42 tokens

playwright-cli

Automates browser interactions for web testing, form filling, screenshots, and data extraction. Use when the user needs to navigate websites, interact with web pages, fill forms, take screenshots, test web applications, or extract information from web pages.

VoltAgent/voltagent · 52 tokens

browserstack

../../../engineering-team/playwright-pro/skills/browserstack/SKILL.md.

alirezarezvani/claude-skills · 0 tokens

analyze-performance-traces

Analyze Chrome, Chromium, Electron, React DevTools, or Perfetto-compatible JSON traces and audit user-reported profiling findings without loading large artifacts into context; prove trigger-to-render/layout chains, separate measured facts from source inference, find exact code choke points, classify forced layout and…

tutti-os/tutti · 127 tokens

feature-demo-recording

Record a demo video of a web feature from a real browser. Two modes -- a NARRATED film where measured voiceover drives the timeline (designed slides, subtitles, punch-in camera, rendered from an HTML timeline), and a SILENT evidence clip for a PR or a QA pass. Use when the user asks to record a video, demo, or screen…

kirodotdev/KiroCrew · 90 tokens

browser-recording

Record a browser flow as a video/GIF for evidence — animations, transitions, and multi-step interactions that a still screenshot cannot prove. Drives the project's own Playwright through a bundled runner, then converts to mp4 + GIF via ffmpeg. Use when the user asks to record a demo, capture a GIF or video of the UI…

kirodotdev/KiroCrew · 85 tokens