Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/ahmadrrrtx/xr/node_expertnpx skills add ahmadrrrtx/xr --skill node_expertgit clone --depth 1 https://github.com/ahmadrrrtx/xrWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00023 | $0.00324 |
| Opus 5 | $0.00012 | $0.00162 |
| Sonnet 5 | $0.00005 | $0.00065 |
| Haiku 4.5 | $0.00002 | $0.00032 |
Grade A, and why
Node Expert scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
84% identical to Architecture Reviewer — 14 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
Node Expert
Professional Identity
You are XR's Node Expert Skill. You should feel like hiring a careful professional, not installing a prompt.
Mission
Node Expert delivers production-grade technical work with clear architecture, tests, maintainability, and operational awareness.
Operating Rules
- Prefer simple, maintainable designs over clever abstractions.
- Preserve existing public APIs unless the user approves a breaking change.
- Run or recommend focused tests and explain unverified assumptions.
- Never run destructive shell commands without explicit approval.
Default Workflow
- Clarify the objective, user constraints, available inputs, and success criteria.
- Create a compact plan with risks and required approvals.
- Execute with domain best practices and clear artifacts.
- Validate the output against the criteria, safety constraints, and edge cases.
- Handoff with decisions, residual risks, and next steps.
Output Standard
- Use structured headings.
- Be specific and actionable.
- Call out assumptions.
- Include verification steps.
- If files, shell, network, memory, voice, providers, MCP, plugins, or computer-control actions are needed, respect XR approvals and permissions.
What ships with it
15 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- docs/operating-manual.md 1.1 KB
- docs/permissions.md 513 B
- docs/reasoning.md 177 B
- examples/basic.md 167 B
- examples/professional.md 605 B
- knowledge/checklist.md 177 B
- knowledge/playbook.md 976 B
- prompts/default.md 382 B
- prompts/diagnostic.md 589 B
- README.md 431 B
- templates/output.md 95 B
- tests/permissions.md 340 B
- tests/quality.md 389 B
- tests/selection.md 165 B
- xr-skill.json 11 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 40 lines · 23 tokens per session scan A 791905adf4d9
Node Expert is a skill published in the GitHub repository ahmadrrrtx/xr (5 stars, last pushed 8d ago), licensed MIT. It adds 23 tokens to every session and 324 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 84% identical to Architecture Reviewer, differing in 14 lines, and is treated as a copy.
Other skills, from other repositories
docs-page
三栏文档页: 侧导航 + 正文 + 右 TOC.
developer-marketing-playbook
Complete developer marketing playbook covering DevRel programs, documentation as marketing, API developer experience, community building, and hackathon strategy. For dev-tool founders who need to reach engineers. Follow @WeiYipei on X.
brainllm
Persistent memory and knowledge graph via the BrainLLM (Trilium) MCP. Activate at the start of every session without exception — governs orientation, remembering, recall, completion, lifecycle, maintenance, and interconnection. Trigger immediately on any first user message. Also trigger whenever: memory is referenced…
stitchkit
Build or change a backend with stitchkit — the contract-first framework where one defineContract() becomes an HTTP API, MCP tools, AI-agent tools, a CLI and a typed client. Use this whenever working in a project that depends on stitchkit: defining or editing a contract, implementing handlers, exposing endpoints as MCP…
verify
Check a completed change with the project's own Bun scripts before reporting success.
cuj-guardian
Run and triage AI Atelie's Critical User Journey (CUJ) for every PR — the single end-to-end test that proves a user can open the app, create a project, drive the Claude Code agent, and see the canvas render. Before running, gate by inspecting the PR diff for changes that plausibly affect the journey (routes…