Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/coda0hq/open-artifacts/using-open-artifactsnpx skills add coda0HQ/open-artifacts --skill using-open-artifactsgit clone --depth 1 https://github.com/coda0HQ/open-artifactsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/coda0hq/open-artifacts/using-open-artifacts)<a href="https://agentmods.dev/skills/coda0hq/open-artifacts/using-open-artifacts"><img src="https://agentmods.dev/badge/skills/coda0hq/open-artifacts/using-open-artifacts.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00147 | $0.06611 |
| Opus 5 | $0.00073 | $0.03306 |
| Sonnet 5 | $0.00029 | $0.01322 |
| Haiku 4.5 | $0.00015 | $0.00661 |
Grade A, and why
using-open-artifacts scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 495 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Open Artifacts
Publish a self-contained HTML, Markdown, or React artifact the user can share by URL. The viewer keeps the artifact body in a sandboxed iframe and owns the service chrome, theme switcher, version picker, comments, and optional Live or Handoff controls. Artifacts keep immutable versions; a channel can keep one URL across later publishes.
The publishing CLI is bundled at scripts/artifact.mjs next to this file. Skill
install locations vary by agent (for example, .claude/skills/ or another
Agent Skills directory), so resolve the directory containing this SKILL.md
as SKILL_DIR, then use a task-local ARTIFACT_CLI="$SKILL_DIR/scripts/artifact.mjs".
Run node "$ARTIFACT_CLI" ... from the project root. There is no globally
installed artifact binary, and Recipe paths are resolved relative to the
project-root working directory. The CLI requires Node.js 22 or newer.
Setup (once per project)
The CLI needs an instance URL, resolved in this order: --api flag,
OPEN_ARTIFACTS_URL, project .artifacts/config.json or
.artifacts/config.local.json, then ~/.config/open-artifacts/config.json.
If none is set, ask the user for the instance URL and write the project config.
For an instance gated by CREATE_TOKEN, use OPEN_ARTIFACTS_TOKEN or
createToken in config. For a hosted/SaaS instance such as coda0.com, run
node "$ARTIFACT_CLI" login; see auth.md for the
browser flow. A stored sk_ API key wins over the self-hosted create-token
values unless --token or OPEN_ARTIFACTS_API_KEY explicitly overrides it.
Every artifact is built from a JSON Recipe plus ordered fragments. Read
recipe.md before creating or updating one.
Shared Recipes and fragments are project sources and may be committed — place
them under .artifacts/recipes/ and .artifacts/fragments/. Local or
encrypted sources live under .artifacts/recipes.local/ and
.artifacts/fragments.local/.
State lives in .artifacts/: Manifest v2 records only publication state and
build hashes; credentials.json, local manifests, private Recipes/fragments,
and previews are gitignored. On the first create in a project, ask
whether the artifact should be local and recommend local. Record the
choice in artifact.local and place the Recipe/fragments accordingly.
What ships with it
43 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- examples/recipes/canvas/flow.recipe.json 729 B
- examples/recipes/canvas/fragments/body.html 1012 B
- examples/recipes/canvas/fragments/theme.css 356 B
- examples/recipes/document/fragments/body.html 336 B
- examples/recipes/document/fragments/report.css 329 B
- examples/recipes/document/fragments/theme.css 351 B
- examples/recipes/document/report.recipe.json 762 B
- examples/recipes/markdown/fragments/body.md 225 B
- examples/recipes/markdown/notes.recipe.json 713 B
- examples/recipes/react/counter.recipe.json 724 B
- examples/recipes/react/fragments/App.jsx 1.6 KB
- references/auth.md 3.4 KB
- references/canvas.md 68 KB
- references/deployment.md 5.7 KB
- references/design.md 53 KB
- references/fonts.md 9.5 KB
- references/icons.md 45 KB
- references/interaction.md 13 KB
- references/live.md 13 KB
- references/motion.md 18 KB
- references/quality.md 8.1 KB
- references/recipe.md 9.9 KB
- references/recipe.schema.json 2.7 KB
- references/reference-dna.md 4.4 KB
- references/reference-dna.schema.json 2.0 KB
- references/scripts.md 6.7 KB
- references/study.md 4.9 KB
- references/tokens.css 13 KB
- scripts/artifact-quality-smoke.mjs 4.7 KB runs code
- scripts/artifact.mjs 76 KB runs code
- scripts/build-artifact.mjs 4.3 KB runs code
- scripts/lib/compose.mjs 8.0 KB runs code
- scripts/lib/contrast.mjs 9.9 KB runs code
- scripts/lib/limits.mjs 1.0 KB runs code
- scripts/lib/live-ack.d.mts 1.1 KB
- scripts/lib/live-ack.mjs 2.4 KB runs code
- scripts/lib/react-build.d.mts 218 B
- scripts/lib/react-build.mjs 5.3 KB runs code
- scripts/lib/recipe.mjs 24 KB runs code
- scripts/lib/validate.mjs 75 KB runs code
- vendor/mermaid/LICENSE 392 B
- vendor/mermaid/linkedom.bundle.mjs 266 KB runs code
- vendor/mermaid/mermaid.bundle.mjs 3443 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 495 lines · 147 tokens per session scan A 1326abc46df1
using-open-artifacts is a skill published in the GitHub repository coda0HQ/open-artifacts (50 stars, last pushed 7d ago), licensed MIT. It adds 147 tokens to every session and 6,611 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…