Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/ahmadrrrtx/xr/react_expertnpx skills add ahmadrrrtx/xr --skill react_expertgit clone --depth 1 https://github.com/ahmadrrrtx/xrWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00023 | $0.00323 |
| Opus 5 | $0.00012 | $0.00161 |
| Sonnet 5 | $0.00005 | $0.00065 |
| Haiku 4.5 | $0.00002 | $0.00032 |
Grade A, and why
React Expert scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
React Expert
Professional Identity
You are XR's React Expert Skill. You should feel like hiring a careful professional, not installing a prompt.
Mission
React Expert delivers production-grade technical work with clear architecture, tests, maintainability, and operational awareness.
Operating Rules
- Prefer simple, maintainable designs over clever abstractions.
- Preserve existing public APIs unless the user approves a breaking change.
- Run or recommend focused tests and explain unverified assumptions.
- Never run destructive shell commands without explicit approval.
Default Workflow
- Clarify the objective, user constraints, available inputs, and success criteria.
- Create a compact plan with risks and required approvals.
- Execute with domain best practices and clear artifacts.
- Validate the output against the criteria, safety constraints, and edge cases.
- Handoff with decisions, residual risks, and next steps.
Output Standard
- Use structured headings.
- Be specific and actionable.
- Call out assumptions.
- Include verification steps.
- If files, shell, network, memory, voice, providers, MCP, plugins, or computer-control actions are needed, respect XR approvals and permissions.
What ships with it
15 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- docs/operating-manual.md 1.1 KB
- docs/permissions.md 517 B
- docs/reasoning.md 178 B
- examples/basic.md 168 B
- examples/professional.md 607 B
- knowledge/checklist.md 178 B
- knowledge/playbook.md 978 B
- prompts/default.md 384 B
- prompts/diagnostic.md 590 B
- README.md 435 B
- templates/output.md 96 B
- tests/permissions.md 341 B
- tests/quality.md 391 B
- tests/selection.md 170 B
- xr-skill.json 11 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 40 lines · 23 tokens per session scan A d78c1f8e198b
React Expert is a skill published in the GitHub repository ahmadrrrtx/xr (5 stars, last pushed 8d ago), licensed MIT. It adds 23 tokens to every session and 323 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
react-core
General React fundamentals - components and JSX, props and state, the core hooks (useState/useEffect/useRef/useMemo/useCallback/useContext), composition, conditional and list rendering, and controlled inputs. The canonical "depends on React" reference.
react-vendoring
React vendoring and react-server layer boundaries. Use when editing entry-base.ts, $$compiled.internal.d.ts, compiled/react packages, or taskfile.js copyvendorreact. Covers the entry-base.ts boundary (all react-server-dom-webpack/ imports must go through it), vendored React channels, type declarations, Turbopack remap…
react-sync
Build local React changes in the bundle variants consumed by Next.js, sync them into a local Next.js checkout, and test the resulting integration. Use when working on React changes that need validation in Next.js, or when asked to run buildForNext, pnpm sync-react, or synchronize a React checkout with Next.js.
shadcn
Manages shadcn components and projects — adding, searching, fixing, debugging, styling, and composing UI, including chat interfaces. Provides project context, component docs, and usage examples. Applies when working with shadcn/ui, component registries, presets, --preset codes, or any project with a components.json…
migrate-radix-to-base
Migrates React projects and components from Radix UI to Base UI. Use when asked to migrate from radix, move to base-ui, convert radix primitives, or switch a shadcn project's base library. Handles single components ("migrate accordion") and whole projects.
flags
How to add or modify Next.js experimental feature flags end-to-end. Use when editing config-shared.ts, config-schema.ts, define-env-plugin.ts, next-server.ts, export/worker.ts, or module.compiled.js. Covers type declaration, zod schema, build-time injection, runtime env plumbing, and the decision between runtime…