Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/bostonorange/claude-code-framework/app-blueprintnpx skills add BostonOrange/claude-code-framework --skill app-blueprintgit clone --depth 1 https://github.com/BostonOrange/claude-code-frameworkWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/bostonorange/claude-code-framework/app-blueprint)<a href="https://agentmods.dev/skills/bostonorange/claude-code-framework/app-blueprint"><img src="https://agentmods.dev/badge/skills/bostonorange/claude-code-framework/app-blueprint.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00019 | $0.00937 |
| Opus 5 | $0.00010 | $0.00468 |
| Sonnet 5 | $0.00004 | $0.00187 |
| Haiku 4.5 | $0.00002 | $0.00094 |
Grade A, and why
app-blueprint scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 140 lines — stays where its author put it; the contents beside it link to each section on GitHub.
App Blueprint
Turn business intent into a concrete internal-app blueprint. Use this before generating or materially changing an internal Next.js business app.
Usage
/app-blueprint Build an approval app for supplier invoices
/app-blueprint docs/notes/invoice-workflow.md
If the user gives only a rough idea, produce the best blueprint you can and mark uncertain fields in openQuestions. Ask only for blockers that would make generation unsafe.
Process
- Read the prompt and any referenced files.
- Identify the core business workflow, users, records, file needs, audit trail, dashboards, and AI assist points.
- Normalize names to stable identifiers:
PascalCasefor entity names.camelCasefor field names.- lower-kebab-case for workflow and view IDs.
- Keep the first pass small enough to generate:
- Prefer 2-5 core entities.
- Prefer explicit statuses over vague text fields.
- Prefer role names that map to permissions.
- Write the result to
docs/app-blueprint.jsonunless the user requested a different path. - Report the blueprint path and any open questions.
Output Contract
Write valid JSON with this shape:
{
"appName": "Supplier Invoice Desk",
"summary": "Short operational description.",
"usersAndRoles": [
{
"role": "financeManager",
"displayName": "Finance Manager",
"responsibilities": ["Approve invoices"],
"authSource": "oidc"
}
],
"entities": [
{
"name": "Invoice",
"description": "Supplier invoice awaiting review.",
"fields": [
{
"name": "supplierName",
"type": "string",
"required": true,
"unique": false,
"sensitive": false,
"notes": "Shown in lists and detail views."
}
],
"statuses": ["draft", "submitted", "approved", "rejected"],
"relationships": [
{
"name": "attachments",
"target": "FileObject",
"cardinality": "many"
}
]
}
],
"workflows": [
{
"id": "submit-invoice",
"name": "Submit Invoice",
"actorRoles": ["requester"],
"entity": "Invoice",
"fromStatuses": ["draft"],
"toStatus": "submitted",
"steps": ["Validate required fields", "Create audit event"]
}
],
"permissions": [
{
"role": "financeManager",
"entity": "Invoice",
"actions": ["read", "approve", "reject"]
}
],
"filesBlobNeeds": [
{
"entity": "Invoice",
"purpose": "Store original invoice PDF",
"allowedMimeTypes": ["application/pdf"],
"maxSizeMb": 10,
"retention": "Match finance record retention policy"
}
],
"auditEvents": [
{
"event": "invoice.approved",
"actor": "financeManager",
"entity": "Invoice",
"payloadFields": ["invoiceId", "approvedAmount"]
}
],
"dashboardsViews": [
{
"id": "finance-queue",
"name": "Finance Queue",
"role": "financeManager",
"type": "table",
"entities": ["Invoice"],
"filters": ["status", "supplierName"],
"primaryActions": ["approve", "reject"]
}
],
"aiAssistPoints": [
{
"id": "invoice-review-assist",
"name": "Invoice Review Assist",
"trigger": "detail-view",
"inputs": ["supplierName", "amount", "description"],
"output": "Risk notes and recommended review checklist",
"humanDecisionRequired": true
}
],
"openQuestions": []
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 140 lines · 19 tokens per session scan A d99920394b8a
app-blueprint is a skill published in the GitHub repository BostonOrange/claude-code-framework (2 stars, last pushed 1mo ago), licensed MIT. It adds 19 tokens to every session and 937 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…