bundle

A command that packages a composed TypeScript API client as a publishable npm package, including built JavaScript, type declarations, package metadata, documentation, and examples. npm is the main package registry for JavaScript and TypeScript libraries.

In plain words
What is it for?
Use it to build a zero-dependency TypeScript SDK, control included modules and exports, generate its README and package files, and prepare it for npm publishing.
Why use it?
It turns a development client into a distributable package that other projects can install from a registry.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/finom/vovk/bundle
Any agent
npx skills add finom/vovk --skill bundle
Clone the repo
git clone --depth 1 https://github.com/finom/vovk

Made for: Claude Code, Codex.

Per session 250 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,587 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00250 $0.03587
Opus 5 $0.00125 $0.01793
Sonnet 5 $0.00050 $0.00717
Haiku 4.5 $0.00025 $0.00359

Measured 2d ago against content hash 571e4c77238c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

bundle scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Runs shell commandslowCapability

Expected in a hook, worth knowing in a rule or an instructions file.

Vovk is bundler-agnostic — `esbuild`, `tsup`, `tsdown`, even `child_process` shell-out work. Only **tsdown** tested by Vovk's authors; docs warn: **pin `[email protected]`** until newer versions confirmed compatible.
skills/bundle/SKILL.md · 255 lines

How it starts

The opening of the file, as written. The whole thing — 255 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Vovk.ts vovk bundle

vovk bundle packages composed TypeScript client as zero-dep npm package — pre-built JS + .d.ts, auto-gen package.json, auto-gen README.md w/ samples, ready for npm publish. Release step: vovk generate → in-project client for dev; vovk bundle → distributable SDK installed from registry.

TypeScript-only. Despite name, ships no Python/Rust clients. Those have own templates (py / pySrc / rs / rsSrc) and own publish flows — see python and rust skills.

Scope

Covers:

  • 4-step bundle workflow.
  • bundle.build async function (required) + canonical [email protected] recipe.
  • bundle.outputConfig fields (origin, package, reExports, imports, requires, readme, samples, includeSegments/excludeSegments).
  • Default directory layout (tmp_prebundledist).
  • Full CLI flag list including --openapi-* mixin family.
  • What's bundled / omitted (no openapi, no schema entry point — but schema still importable as named export).
  • npm publish dist flow + consumer-side usage.
  • deriveTools integration (bundled modules feed it identically).

Out of scope:

  • In-project vovk-client generation → rpc skill.
  • Python client publishing (PyPI) → python skill.
  • Rust client publishing (crates.io) → rust skill.
  • Mixin authoring (consumed here as bundle inputs) → mixins skill.

bundle vs generate

Command Purpose Output When
vovk generate In-project TypeScript client + OpenAPI spec node_modules/.vovk-client/, .vovk-schema/ Every build (prebuild hook), on schema changes during vovk dev.
vovk bundle Publishable npm package — pre-built JS + .d.ts + package.json + README.md dist/ ready for npm publish Ship SDK outside Next.js app.

Don't run vovk bundle in normal dev; in-project client faster. Bundle when you need registry artifact.

How bundling works

  1. Vovk gens TypeScript client into prebundleOutDir (default tmp_prebundle) via tsBase template — uncompiled .ts source.
  2. Vovk calls your bundle.build({ entry, outDir, prebundleDir }) async fn. Plugs in any bundler (tsdown only tested one) to compile entry (the tmp_prebundle/index.ts) → JS + .d.ts under outDir (default dist).
  3. Vovk emits package.json and README.md from packageJson and readme templates into outDir.
  4. Vovk deletes prebundleOutDir unless keepPrebundleDir: true (handy for debugging prebundled source).

Read the full file on GitHub · 255 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 255 lines · 250 tokens per session scan A 571e4c77238c

Subscribe to this mod's changes

bundle is a skill published in the GitHub repository finom/vovk (52 stars, last pushed 5d ago), licensed MIT. It adds 250 tokens to every session and 3,587 once invoked, about $0.0013 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

ocli-api

Turn any OpenAPI/Swagger API into CLI commands and call them. Search endpoints with BM25, check parameters, execute — no MCP server needed.

EvilFreelancer/openapi-to-cli · 34 tokens

react-performance

Optimize React/Next.js runtime performance — eliminate waterfalls, shrink bundles, cut unnecessary re-renders, and speed up rendering. Use when writing, reviewing, or refactoring components for speed, or chasing slow renders, large bundles, janky interactions, or high TTFB/LCP/INP.

clubpay/ronykit · 64 tokens

ronykit-framework

Orchestrates RonyKit service development using the ronyup MCP server (knowledge resources, prompts, scaffold tools). Use when the user mentions RonyKit, ronyup, EdgeServer, contracts, scaffolding a workspace or feature, implementing API handlers and services, frontend bootstrap, integration tests, or design documents…

clubpay/ronykit · 75 tokens

composition-patterns

Design reusable React component APIs that scale — compound components, lifted state, generic context, explicit variants. Use when a component is growing boolean props (isThread, isEditing…), when building a component library, or when reviewing component architecture. Includes React 19 API changes.

clubpay/ronykit · 58 tokens

storybook

Author and maintain Storybook stories with CSF 3.0 best practices — args, decorators, parameters, and config. Use when creating or editing .stories. files, configuring .storybook/, or ensuring every UI component ships with stories.

clubpay/ronykit · 50 tokens

webmcp

Build agent-friendly web apps with the W3C Web Model Context API (WebMCP). Use when exposing frontend features as structured tools for in-browser AI agents, adding document.modelContext tools to React/Next.js apps, designing tool schemas for dashboards or admin UIs, or making existing UI automatable without DOM…

clubpay/ronykit · 69 tokens