Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/aziontech/webkit/figma-discovernpx skills add aziontech/webkit --skill figma-discovergit clone --depth 1 https://github.com/aziontech/webkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00039 | $0.01198 |
| Opus 5 | $0.00019 | $0.00599 |
| Sonnet 5 | $0.00008 | $0.00240 |
| Haiku 4.5 | $0.00004 | $0.00120 |
Grade A, and why
figma-discover scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 83 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill: figma-discover
Purpose
Convert a Figma URL or nodeId into a structured JSON blob: colors, typography, spacing, radius, shadows, states (default/hover/active/focus/disabled), and identified regions (header/body/footer/actions). The downstream token-map skill consumes that JSON; this skill never decides anything beyond what Figma reports.
When to invoke
- Step 2 (parallel discovery) of
/component-create. - During
/spec-createwhen the user provided--figma <url>.
Inputs
- A Figma frame URL or
nodeId.
Workflow
- Load prerequisite skill. Invoke
figma:figma-usebefore any MCP call (mandatory per Figma plugin instructions). - Extract variables. Call
mcp__plugin_figma_figma__get_variable_defson the target node. Capture every named Figma variable along with its resolved value. - Extract design context. Call
mcp__plugin_figma_figma__get_design_contextfor the regions, states, and component anatomy. Capture the frame's component/node name raw (do not kebab or rewrite it) forcomponent_name. - Normalize. Emit a single JSON object:
{ "figma_node": "<url>", "component_name": "...", "variables": [ { "name": "color/surface", "value": "...", "kind": "color" }, { "name": "text/heading-md", "value": "...", "kind": "typography" } ], "regions": ["header", "body", "footer", "actions"], "states": ["default", "hover", "active", "focus", "disabled"] } - Print. Emit only the JSON. No prose.
Outputs
- A single JSON blob to stdout. Nothing else.
Rules
- Do not decide anything (regions ≠ structure decision; that's
structure-decide). - Do not map Figma → DESIGN.md; that's
token-map. - Do not echo the user's request — only emit structured data.
- Do not invoke
use_figma,create_new_file, or any write-side Figma tool.
Behavioral fidelity (the part that matters)
The discovery output drives the spec, which drives the .vue. The downstream consumers depend on you to capture Figma behavior, not just colors. Capture, when present in the frame:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 83 lines · 39 tokens per session scan A 044f61d9153c
figma-discover is a skill published in the GitHub repository aziontech/webkit (2 stars, last pushed 4d ago), licensed MIT. It adds 39 tokens to every session and 1,198 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
monorepo-management
Sets up or audits a monorepo workspace: tool selection, package naming, shared tooling, inter-package dependencies, selective CI, and versioning strategy. Invoked when the user asks to set up a monorepo, add a workspace, or manage multiple packages in a single repository.
bazel-monorepo-expert
Expert knowledge for managing large-scale Bazel monorepos with multiple services, shared libraries, and cross-cutting concerns. Use for workspace structure, visibility, and dependency management.
pnpm
Skill "pnpm" from pledgeandgrow/pledge-skills, covering pnpm documentation skill, key benefits, file index, quick start and install pnpm.
fast-typescript-check
Keep www-sacred's TypeScript fast to type-check and fast to run. Use when touching the ASCII/canvas animation components (the only real per-frame code here), tightening type-check wall-clock, or auditing a change for runtime or compiler regressions. Scoped to this repo — a React 19 / Next.js 16 component library plus…
port-sacred-terminal-ui-to-react-using-same-conventions
Take a CLI screen written for Simulacrum — the sacred CLI framework (scripts/cli/templates/.ts or scripts/python/templates/.py) — and produce a React component that lives inside components/examples/ (or components/) using only sacred's existing primitives — Window, Card, SimpleTable, ActionButton, RowSpaceBetween…
tinyvue-develop-spec
在当前仓库进行组件的开发,主题开发,国际化开发,测试脚本开发时,必须遵守以下规范。.