Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fusebase-dev/fusebase-flow/app-sidecarnpx skills add fusebase-dev/fusebase-flow --skill app-sidecargit clone --depth 1 https://github.com/fusebase-dev/fusebase-flowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00066 | $0.03577 |
| Opus 5 | $0.00033 | $0.01788 |
| Sonnet 5 | $0.00013 | $0.00715 |
| Haiku 4.5 | $0.00007 | $0.00358 |
Grade B, and why
app-sidecar scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Sends data to an external URLmediumData exfiltration
A POST to an outside endpoint may be telemetry or may be exfiltration; either way the mod talks to somewhere, and you should know where.
const res = await fetch("http://localhost:9222/screenshot", { method: "POST", How it starts
The opening of the file, as written. The whole thing — 391 lines — stays where its author put it; the contents beside it link to each section on GitHub.
App Sidecar Containers
Sidecars are pre-built Docker images deployed alongside an app backend in the same network namespace (sharing localhost). They enable auxiliary services that the backend communicates with over HTTP or other protocols on localhost.
Prerequisites
- App must have a
backend/folder configured infusebase.json
Use Cases
| Sidecar | Image Example | Port | Purpose |
|---|---|---|---|
| Headless browser | browserless/chrome:latest |
9222 | Web scraping, PDF generation, screenshots |
| Lightweight browser | nicholasgriffintn/lightpanda:latest |
9222 | Fast page parsing |
| Redis cache | redis:7-alpine |
6379 | Caching, queues, pub/sub |
| Image processor | dpokidov/imageproxy:latest |
8080 | Image resizing/optimization |
CLI Commands
Add a Sidecar
fusebase sidecar add \
--app <appPath> \
--name <name> \
--image <dockerImage> \
[--port <port>] \
[--tier small|medium|large] \
[--env KEY=VALUE ...] \
[--secret KEY|KEY:ALIAS ...]
Example:
fusebase sidecar add \
--app my-scraper \
--name chromium \
--image browserless/chrome:latest \
--port 9222 \
--tier medium \
--env MAX_CONCURRENT_SESSIONS=5 \
--env CONNECTION_TIMEOUT=30000
Remove a Sidecar
fusebase sidecar remove --app <appPath> --name <name>
List Sidecars
fusebase sidecar list --app <appPath>
--feature (-f) is accepted as a deprecated alias for --app (-a).
Whitelisting Secrets
By default, app secrets registered via fusebase secret create are injected only into the main backend container (and into cron job containers). Sidecars receive no app secrets unless you explicitly whitelist the keys you want each sidecar to see.
Use the repeatable --secret option on fusebase sidecar add to opt in:
# Inject the secret as an env var with the same name (DB_PASSWORD)
fusebase sidecar add --app my-scraper --name redis \
--image redis:7-alpine \
--secret DB_PASSWORD
# Inject the secret under a different env var name inside the sidecar
# (sidecar sees REDIS_AUTH_TOKEN; the underlying secret remains DB_PASSWORD)
fusebase sidecar add --app my-scraper --name redis \
--image redis:7-alpine \
--secret DB_PASSWORD:REDIS_AUTH_TOKEN
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 391 lines · 66 tokens per session scan B 6412c6ee62d8
app-sidecar is a skill published in the GitHub repository fusebase-dev/fusebase-flow (9 stars, last pushed 7d ago), licensed MIT. It adds 66 tokens to every session and 3,577 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it B with 1 finding (sends data to an external url). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
adobe-express-core
Adobe Express environment essentials, two-runtime architecture, project setup, and MCP server configuration. Use when starting add-on development, understanding iframe vs sandbox boundaries, configuring MCP servers, setting up local projects, or validating manifest configuration.
adobe-express-monetization
Monetize Adobe Express add-ons with subscriptions and payments. Use when designing checkout flows, defining subscription tiers, implementing webhook verification, managing entitlements, or securing backend billing logic.
adobe-express-spectrum-ui-ux
Build or review Adobe Express add-on panel UI with Spectrum patterns, stack selection guidance (raw SWC, swc-react, React Spectrum), Express theme setup, state and navigation design, and actionable UX quality checks. Use when implementing or auditing panel layouts, interaction states, multi-screen flows, and…
adobe-express-cors-and-backend
Diagnose and fix CORS errors between Adobe Express add-on UI and backend APIs across local development, private listing, and public listing stages. Use when browser requests fail with preflight, Access-Control-Allow-Origin, Access-Control-Allow-Headers, or OPTIONS issues; when moving from localhost to hosted add-on…
adobe-express-document-manipulation
Create and modify document content in Adobe Express add-ons using Document SDK. Use when planning document operations, inserting shapes/text/media, sequencing sandbox commands, or troubleshooting document edits.
adobe-express-oauth-authentication
Implement OAuth 2.0 and authentication flows for Adobe Express add-ons. Use when connecting to cloud providers (Dropbox, OneDrive, Google Drive), managing tokens, storing credentials, or designing login surfaces.