bxc Core

A toolkit for building cross-platform agent projects with Bun, Rust, and native browser or social-network connections. It provides shared code patterns, commands, checks, and integrations for this type of project.

In plain words
What is it for?
Use it when developing bxc-based navigation engines, native X or Grok clients, web scrapers, Rust-to-Bun connections, or agent workflows that combine browsing and social-network actions.
Why use it?
It gives teams consistent rules for naming, testing, authentication, and cross-platform builds. It also avoids starting a separate browser process for many tasks.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/aphrody-code/bxc/bxc-core
Any agent
npx skills add aphrody-code/bxc --skill bxc-core
Clone the repo
git clone --depth 1 https://github.com/aphrody-code/bxc

Made for: Claude Code, Codex.

Per session 102 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 996 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00102 $0.00996
Opus 5 $0.00051 $0.00498
Sonnet 5 $0.00020 $0.00199
Haiku 4.5 $0.00010 $0.00100

Measured 2d ago against content hash 907aa558b5e7, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

bxc Core scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/bxc/skills/bxc-core/SKILL.md · 53 lines

How it starts

The opening of the file, as written. The whole thing — 53 lines — stays where its author put it; the contents beside it link to each section on GitHub.

bxc — Zero-Spawn Native Browser Engine for Agents (toolkit)

bxc is a production-grade, cross-platform (Linux/macOS/Windows) "zero-spawn" navigation engine for AI agents: Bun runtime + Rust cdylib FFI (lol_html, html5ever, V8 bindings, X GraphQL client, For-You ranking algo port) + Zig DOM history in some components. No Chromium spawn for most workloads.

The bxc plugin provides reusable skills, dedicated sub-agents, commands, hooks, and MCP integration so any project can adopt the same architecture, patterns, and quality bars (bxc* naming, scoped testing, native keyless clients, agentic Grok+X loops, monorepo scrapers, autopilot).

Core Principles (always follow)

  • Naming: Every identifier, binary, doc, crate, package must use bxc* prefix. Rebrand is final — never reintroduce old names.
  • Test scope: Always bun test test/ packages/ src/ (or more specific). Never bare bun test (it discovers vendor/mcp-sdk and produces noise/failures).
  • Zero keys where possible: Prefer SUPER_GROK_TOKEN / ~/.grok/auth.json for xai, cookie auth_token+ct0 for X (via XSession). No paid API keys for core flows.
  • Native first: Use the real @aphrody/x XClient and @aphrody/xai Chat + XTools for agentic flows instead of external APIs.
  • FFI discipline: Rust cdylibs (bxc-rust-bridge) for hot paths (DOM, ranking, lol_html). Workspace rusqlite 0.37 for sqlite links. Build with bun run build:linux or cargo --release.
  • Cross-platform: Bun works everywhere. Rust produces .so / .dylib / .dll. Provide notes/scripts for all three OS.
  • MCP exposure: The bxc-native-mcp (in src/mcp/server.ts) exposes tools; extend with registerTool + Zod. Build to dist/standalone/bxc-mcp.
  • Autonomy: The autopilot.sh + monitors + subagents pattern for continuous verify/build/docs.

Quick Project Layout (for new or ported projects)

my-bxc-project/
├── src/                  # TS API, CLI, MCP server (Elysia or standalone)
├── packages/             # Monorepo scraper workspaces (@aphrody/<name>)
├── rust-bridge/          # FFI crates (x-client, x-algorithm, bxc-rust-bridge cdylib)
├── .claude/              # skills, agents (or load via bxc plugin)
├── CLAUDE.md             # project rules (test scope, naming, etc.)
├── MEGA-PLAN.md          # high-level roadmap
└── scripts/              # bxc-control.sh, autopilot.sh, build-standalone.ts

Read the full file on GitHub · 53 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 53 lines · 102 tokens per session scan A 907aa558b5e7

Subscribe to this mod's changes

bxc Core is a skill published in the GitHub repository aphrody-code/bxc (2 stars, last pushed 2d ago), licensed Apache-2.0. It adds 102 tokens to every session and 996 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

using-claude-cli

How to drive claude (Claude Code) as a non-interactive CLI tool — headless runs, MCP servers, permissions, output formats, and piping. Use when scripting Claude, spawning a sub-agent from another process, or wiring Claude into CI/automation.

developerz-ai/ui-debugger-mcp · 61 tokens

obscura

Operate and validate Obscura for JavaScript page loading, stealth browsing, anti-fingerprinting, tracker blocking, screenshots and visual comparison, CDP automation with Puppeteer or Playwright, screencasting, PDF export, MCP browser interaction, and web extraction. Use when running Obscura against deterministic…

h4ckf0r0day/obscura · 100 tokens

pinchtab

Use this skill when a task needs browser automation through PinchTab: open a website, inspect interactive elements, click through flows, fill out forms, scrape page text, reuse a dedicated automation profile with user approval, export screenshots or PDFs, manage multiple browser instances, or fall back to the HTTP API…

pinchtab/pinchtab · 94 tokens

pinchtab-mcp

Use this skill when a task requires browser automation through PinchTab's MCP server connected to a remote browser instance. Covers navigation, element interaction, data extraction, form filling, multi-step flows, and session management via MCP tools.

pinchtab/pinchtab · 52 tokens

pinchtab-stealth-score

Run the PinchTab stealth-score sweep against 15 bot-detection / fingerprint sites (sannysoft, rebrowser, deviceandbrowserinfo, iphey, whoer, browserscan, pixelscan, fingerprint-scan, incolumitas, fvision, amiunique, browserleaks, creepjs, coveryourtracks, fingerprint-demo). Starts a Docker PinchTab container per…

pinchtab/pinchtab · 168 tokens

browser-use-terminal

Direct browser control via the Browser Use Terminal CLI. Use when the user wants to automate, scrape, test, or interact with web pages — you drive the browser yourself with Python helpers.

browser-use/terminal · 41 tokens