app-sidecar

A guide for running supporting Docker containers alongside an application backend. These sidecars provide services such as browsers, caches, queues, or image processors over the shared local network.

In plain words
What is it for?
Use it to add, remove, list, or configure sidecar containers, including their Docker images, ports, environment variables, secrets, networking, and resource tiers.
Why use it?
It gives the backend access to auxiliary services without putting all of their work inside the main application container.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/fusebase-dev/fusebase-flow/app-sidecar
Any agent
npx skills add fusebase-dev/fusebase-flow --skill app-sidecar
Clone the repo
git clone --depth 1 https://github.com/fusebase-dev/fusebase-flow

Made for: Claude Code, Codex.

Per session 66 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,577 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00066 $0.03577
Opus 5 $0.00033 $0.01788
Sonnet 5 $0.00013 $0.00715
Haiku 4.5 $0.00007 $0.00358

Measured 2d ago against content hash 6412c6ee62d8, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

app-sidecar scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Sends data to an external URLmediumData exfiltration

A POST to an outside endpoint may be telemetry or may be exfiltration; either way the mod talks to somewhere, and you should know where.

const res = await fetch("http://localhost:9222/screenshot", { method: "POST",
.agents/skills/app-sidecar/SKILL.md · 391 lines

How it starts

The opening of the file, as written. The whole thing — 391 lines — stays where its author put it; the contents beside it link to each section on GitHub.

App Sidecar Containers

Sidecars are pre-built Docker images deployed alongside an app backend in the same network namespace (sharing localhost). They enable auxiliary services that the backend communicates with over HTTP or other protocols on localhost.

Prerequisites

  1. App must have a backend/ folder configured in fusebase.json

Use Cases

Sidecar Image Example Port Purpose
Headless browser browserless/chrome:latest 9222 Web scraping, PDF generation, screenshots
Lightweight browser nicholasgriffintn/lightpanda:latest 9222 Fast page parsing
Redis cache redis:7-alpine 6379 Caching, queues, pub/sub
Image processor dpokidov/imageproxy:latest 8080 Image resizing/optimization

CLI Commands

Add a Sidecar

fusebase sidecar add \
  --app <appPath> \
  --name <name> \
  --image <dockerImage> \
  [--port <port>] \
  [--tier small|medium|large] \
  [--env KEY=VALUE ...] \
  [--secret KEY|KEY:ALIAS ...]

Example:

fusebase sidecar add \
  --app my-scraper \
  --name chromium \
  --image browserless/chrome:latest \
  --port 9222 \
  --tier medium \
  --env MAX_CONCURRENT_SESSIONS=5 \
  --env CONNECTION_TIMEOUT=30000

Remove a Sidecar

fusebase sidecar remove --app <appPath> --name <name>

List Sidecars

fusebase sidecar list --app <appPath>

--feature (-f) is accepted as a deprecated alias for --app (-a).

Whitelisting Secrets

By default, app secrets registered via fusebase secret create are injected only into the main backend container (and into cron job containers). Sidecars receive no app secrets unless you explicitly whitelist the keys you want each sidecar to see.

Use the repeatable --secret option on fusebase sidecar add to opt in:

# Inject the secret as an env var with the same name (DB_PASSWORD)
fusebase sidecar add --app my-scraper --name redis \
  --image redis:7-alpine \
  --secret DB_PASSWORD

# Inject the secret under a different env var name inside the sidecar
# (sidecar sees REDIS_AUTH_TOKEN; the underlying secret remains DB_PASSWORD)
fusebase sidecar add --app my-scraper --name redis \
  --image redis:7-alpine \
  --secret DB_PASSWORD:REDIS_AUTH_TOKEN

Read the full file on GitHub · 391 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 391 lines · 66 tokens per session scan B 6412c6ee62d8

Subscribe to this mod's changes

app-sidecar is a skill published in the GitHub repository fusebase-dev/fusebase-flow (9 stars, last pushed 7d ago), licensed MIT. It adds 66 tokens to every session and 3,577 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it B with 1 finding (sends data to an external url). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

adobe-express-core

Adobe Express environment essentials, two-runtime architecture, project setup, and MCP server configuration. Use when starting add-on development, understanding iframe vs sandbox boundaries, configuring MCP servers, setting up local projects, or validating manifest configuration.

Sandgrouse/adobe-express-dev-skill · 50 tokens

adobe-express-monetization

Monetize Adobe Express add-ons with subscriptions and payments. Use when designing checkout flows, defining subscription tiers, implementing webhook verification, managing entitlements, or securing backend billing logic.

Sandgrouse/adobe-express-dev-skill · 44 tokens

adobe-express-spectrum-ui-ux

Build or review Adobe Express add-on panel UI with Spectrum patterns, stack selection guidance (raw SWC, swc-react, React Spectrum), Express theme setup, state and navigation design, and actionable UX quality checks. Use when implementing or auditing panel layouts, interaction states, multi-screen flows, and…

Sandgrouse/adobe-express-dev-skill · 70 tokens

adobe-express-cors-and-backend

Diagnose and fix CORS errors between Adobe Express add-on UI and backend APIs across local development, private listing, and public listing stages. Use when browser requests fail with preflight, Access-Control-Allow-Origin, Access-Control-Allow-Headers, or OPTIONS issues; when moving from localhost to hosted add-on…

Sandgrouse/adobe-express-dev-skill · 92 tokens

adobe-express-document-manipulation

Create and modify document content in Adobe Express add-ons using Document SDK. Use when planning document operations, inserting shapes/text/media, sequencing sandbox commands, or troubleshooting document edits.

Sandgrouse/adobe-express-dev-skill · 43 tokens

adobe-express-oauth-authentication

Implement OAuth 2.0 and authentication flows for Adobe Express add-ons. Use when connecting to cloud providers (Dropbox, OneDrive, Google Drive), managing tokens, storing credentials, or designing login surfaces.

Sandgrouse/adobe-express-dev-skill · 50 tokens