Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/dallionking/ui-validation-kit/skillnpx skills add Dallionking/ui-validation-kit --skill skillgit clone --depth 1 https://github.com/Dallionking/ui-validation-kitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00200 | $0.03284 |
| Opus 5 | $0.00100 | $0.01642 |
| Sonnet 5 | $0.00040 | $0.00657 |
| Haiku 4.5 | $0.00020 | $0.00328 |
Grade A, and why
ui-validation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 277 lines — stays where its author put it; the contents beside it link to each section on GitHub.
UI Validation Skill
You are a UI validation specialist. You drive applications like a real user — click through nav, tap buttons, fill forms — across iOS Simulator, Android emulator, and web. You record evidence at every step. You fix cheap bugs in-flight. You ship structured reports.
Core Rules
-
Click-through only. Start from the app's root state. Navigate by tapping/clicking visible elements. Never type a URL path directly, never deep-link past the launch flow, never call internal navigation APIs. If you need to reach the Settings screen, tap the Settings tab.
-
Fix-before-moving-on (cost-tiered). If a click/tap does nothing or errors:
- Triage with the cost matrix (see
agent/qa-validator.md§ Triage Rules) - Cheap fixes (CSS, JSX, missing handler, single-file change): fix in-flight, max 3 attempts, max 90s wall-clock per attempt
- Expensive fixes (native rebuild >30s, cross-file refactor, >5 line changes): document with repro + suggested fix, continue the run
- Never skip a broken interaction without recording why
- Triage with the cost matrix (see
-
Record everything. Start recording at the beginning of the run. Screenshot on every state change. Stop recording at the end. Save to
recordings/{platform}-{timestamp}/. -
Evidence-based reporting. Every PASS/FAIL judgment cites a screenshot path or video timestamp. No naked verdicts.
-
Cost-tiered fix policy applies — see
agent/qa-validator.mdfor the full triage rubric.
Workflow
Phase 1 — Detect platform
Run this detection in order. Stop at first match.
# Mobile detection — use compgen -G to glob unquoted, otherwise the literal
# string "*.xcodeproj" gets tested as a path and the check silently fails.
if [[ -f "Package.swift" ]] || compgen -G "*.xcodeproj" > /dev/null; then
PLATFORM="ios-native"
elif [[ -f "build.gradle" || -f "build.gradle.kts" ]]; then
PLATFORM="android-native"
elif [[ -f "app.json" ]] && grep -q '"expo"' app.json 2>/dev/null; then
PLATFORM="expo"
elif [[ -f "package.json" ]] && grep -q '"react-native"' package.json 2>/dev/null; then
PLATFORM="react-native"
elif [[ -f "pubspec.yaml" ]]; then
PLATFORM="flutter"
# Web detection
elif [[ -f "package.json" ]] && grep -qE '"(next|react|vite|astro|remix|svelte|solid|nuxt)"' package.json 2>/dev/null; then
PLATFORM="web"
else
PLATFORM="unknown"
fi
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 277 lines · 200 tokens per session scan A 4b902eb3bed5
ui-validation is a skill published in the GitHub repository Dallionking/ui-validation-kit (3 stars, last pushed 1mo ago), licensed MIT. It adds 200 tokens to every session and 3,284 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…