Borrowing it
Nothing to install: this file belongs to akaghef/M3E. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/akaghef/M3E/main/.claude/skills/canvas-protocol/SKILL.mdgit clone --depth 1 https://github.com/akaghef/M3EWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/akaghef/m3e/canvas-protocol)<a href="https://agentmods.dev/skills/akaghef/m3e/canvas-protocol"><img src="https://agentmods.dev/badge/skills/akaghef/m3e/canvas-protocol/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/akaghef/m3e/canvas-protocol"><img src="https://agentmods.dev/badge/skills/akaghef/m3e/canvas-protocol.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00266 | $0.02567 |
| Opus 5.5 | $0.00106 | $0.01027 |
| Sonnet 5.5 | $0.00053 | $0.00513 |
| Haiku 4.5 | $0.00027 | $0.00257 |
Grade C, and why
canvas-protocol scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
curl -s http://localhost:4173/api/maps | node -e "..." Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -s http://localhost:4173/api/maps | node -e "..." How it starts
The opening of the file, as written. The whole thing — 169 lines — stays where its author put it; the contents beside it link to each section on GitHub.
canvas-protocol — Agent ↔ Canvas Interaction Rules
M3E マップを共有 canvas として agent と人間で使う。canvas は 任意の同期ポイントであり、 agent の主作業 (実装・テスト・PR) は canvas 不在でも完結できる設計を保つ。
1. Target server
- default: beta (port 4173)
- map discovery:
GET /api/mapsでlabel="開発"のmapIdを取得 - final (38482) は本番確認時のみ使う (m3e-map skill 参照)
2. Canvas Layout (固定パス)
M:(開発)> SYSTEM > DEV
├── strategy/ # 開発戦略・タスクボード
│ └── HOME Re-implementation/ # プロジェクト単位のサブツリー
│ ├── Visual tasks/ # ロール別タスク
│ ├── Data tasks/
│ └── Team coordination/
├── reviews/ # 人間の判断待ちキュー
│ └── {Project}/Q1, Q2, ... # 各 Q の子ノードが選択肢
│ └── (option) attributes.selected="yes" で確定
├── Agent Status/ # 各 worker の現在状態
├── tasks/ doing / ready / done # devM3E の Phase 5 同期先
├── scratch/ # アイデア・バグ報告・後回し
└── Bugs/ # 既知バグ
3. Read Protocol (agent → canvas)
着手前に必ず実施:
# reviews/{Project} を読み、status="open" の Q に未回答が無いか確認
curl -s http://localhost:4173/api/maps | node -e "..."
判断:
- 該当 Q が
attributes.selected="yes"付き選択肢を持つ → その決定で進める status="open"で未選択 → 待機 or 自己解釈せず人間に確認status="resolved"だが selected が無い → 人間に再確認 (canvas が壊れている可能性)
重要: canvas に到達できない / fetch 失敗の時、agent は作業を止めない。 ローカルで実装ドラフトを進め、PR description に「canvas 未参照、要確認」と明記する。
4. Write Protocol (agent → canvas)
4.1 タスク開始
// strategy/{Project}/{Role} tasks/{taskNode}.attributes.status = "in_progress"
node.attributes = {...node.attributes, status: "in_progress", startedAt: "2026-04-14"};
4.2 タスク完了
node.attributes = {...node.attributes, status: "done", completedAt: "2026-04-14"};
4.3 新規 Q 起票 — Ambiguity Pooling (MUST)
原則: 曖昧点に当たったら block しない / silently 決めない。プールして暫定値で進む。akaghef が batch-review する。
reviews/{Project}/Qn (text="Qn: <一文の質問>",
attributes={status:"open", raisedBy:"<role>", raisedAt:"YYYY-MM-DD"})
└── 選択肢 1 (details: Why / Trade-off)
└── 選択肢 2 (details: Why / Trade-off)
└── 選択肢 3 (attributes.tentative="yes" ← agent の暫定採用案)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 169 lines · 266 tokens per session scan C 3f51df285df3
canvas-protocol is a skill published in the GitHub repository akaghef/M3E (11 stars, last pushed 5d ago), licensed MIT. It adds 266 tokens to every session and 2,567 once invoked, about $0.0011 per session on Opus 5.5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-02.
Other skills, from other repositories
story-readiness
Is a story implementation-ready? Checks clear acceptance criteria, open questions, ADR refs. READY/NEEDS WORK/BLOCKED/NOT ASSESSED.
recipe-create-meet-space
Create a Google Meet meeting space and share the join link.
workthreads
SpecStory Workthreads - a weekly work-thread rollup across a team's repos from SpecStory coding histories (any agent - Claude Code, Codex, Cursor, Gemini, and more). It groups the window's sessions into threads of work per project and labels each new / open / recently closed, so a lead sees what shipped, what is still…
atmos-config
Atmos root configuration: atmos.yaml discovery, precedence, deep merging, basepath, imports, minimal bootstrap, and routing to narrower Atmos skills.
projects
List all managed projects with status, branch, open PRs, and open issue counts — portfolio-level view.
remove
Remove a deployed framework or addon from the current workspace.