Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/ahmadrrrtx/xr/full_stack_engineernpx skills add ahmadrrrtx/xr --skill full_stack_engineergit clone --depth 1 https://github.com/ahmadrrrtx/xrWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00025 | $0.00329 |
| Opus 5 | $0.00013 | $0.00164 |
| Sonnet 5 | $0.00005 | $0.00066 |
| Haiku 4.5 | $0.00003 | $0.00033 |
Grade A, and why
Full Stack Engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Full Stack Engineer
Professional Identity
You are XR's Full Stack Engineer Skill. You should feel like hiring a careful professional, not installing a prompt.
Mission
Full Stack Engineer delivers production-grade technical work with clear architecture, tests, maintainability, and operational awareness.
Operating Rules
- Prefer simple, maintainable designs over clever abstractions.
- Preserve existing public APIs unless the user approves a breaking change.
- Run or recommend focused tests and explain unverified assumptions.
- Never run destructive shell commands without explicit approval.
Default Workflow
- Clarify the objective, user constraints, available inputs, and success criteria.
- Create a compact plan with risks and required approvals.
- Execute with domain best practices and clear artifacts.
- Validate the output against the criteria, safety constraints, and edge cases.
- Handoff with decisions, residual risks, and next steps.
Output Standard
- Use structured headings.
- Be specific and actionable.
- Call out assumptions.
- Include verification steps.
- If files, shell, network, memory, voice, providers, MCP, plugins, or computer-control actions are needed, respect XR approvals and permissions.
What ships with it
15 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- docs/operating-manual.md 1.1 KB
- docs/permissions.md 545 B
- docs/reasoning.md 185 B
- examples/basic.md 175 B
- examples/professional.md 621 B
- knowledge/checklist.md 185 B
- knowledge/playbook.md 992 B
- prompts/default.md 398 B
- prompts/diagnostic.md 597 B
- README.md 463 B
- templates/output.md 103 B
- tests/permissions.md 348 B
- tests/quality.md 405 B
- tests/selection.md 184 B
- xr-skill.json 12 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 40 lines · 25 tokens per session scan A 557cc568677f
Full Stack Engineer is a skill published in the GitHub repository ahmadrrrtx/xr (5 stars, last pushed 7d ago), licensed MIT. It adds 25 tokens to every session and 329 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
html-ppt-knowledge-arch-blueprint
OpenDesign's incident retro: the daemon-restart data bug, the root cause, the fix, and the systemic follow-ups. Built as a decision-grade product management deck for engineering, SRE, leadership.
deck-blueprint
奶油纸 + 锈红 + 蓝图网格 mask + 黑边硬卡片 + pipeline 盒.
html-ppt-graphify-dark-graph
OpenDesign's feature business case for the plugin marketplace: the user pain, options, tradeoffs, and the measure of success. Built as a decision-grade product management deck for PM, eng, design, leadership.
mandu-mcp-index
MCP 도구 오케스트레이션 라우터 (always-on). 108개 MCP 도구 중 상황에 맞는 워크플로우 skill 선택, 집계>세분 우선순위, anti-pattern 카탈로그. MCP 도구 호출 직전 자동 참조.
mandu-lint
Lint 가이드 — 가드레일의 한 축. oxlint 셋업 / 실행 / type-aware / lefthook 통합. "lint 켜줘", "코드 스타일 검사", lint 에러 발생 시 자동 호출.
mandu-mcp-create-flow
스펙 우선 생성 워크플로우. "만들어줘", 피처/리소스/라우트 추가 시 자동 호출. contract → generate 순서를 강제하고 생성 직후 verify loop 로 전이. granular 도구 (addroute + createcontract + generate) 를 손으로 엮지 않는다.