Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fusebase-dev/fusebase-flow/lightweight-lanenpx skills add fusebase-dev/fusebase-flow --skill lightweight-lanegit clone --depth 1 https://github.com/fusebase-dev/fusebase-flowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00130 | $0.02893 |
| Opus 5 | $0.00065 | $0.01447 |
| Sonnet 5 | $0.00026 | $0.00579 |
| Haiku 4.5 | $0.00013 | $0.00289 |
Grade A, and why
lightweight-lane scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 115 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Lightweight Lane (FR-21)
Purpose
Make ceremony proportional to risk. Fusebase Flow's full eight-phase lane is calibrated for uncertain / risky work, where spec / clarify / decisions / gate genuinely de-risk. For a change that is small, reversible, security-neutral, and has a one-sentence verifiable outcome, that uncertainty is near zero — so the planning + traceability artifacts add cost without reducing risk, and the two-agent deploy split can even add risk (redundant rebuild, more surface for mistakes than the change carries). This skill is the single source of truth for the Lightweight Lane (LL): the eligibility gate, the change-note, the one-pass procedure, and mid-flight promotion. Everything that actually controls risk is kept in both lanes.
This is not only for one-line edits. It covers the whole class of small / minor changes that need no large implementation and no real architectural decisions — small hotfixes, small bug fixes, small improvements, config/copy tweaks. The discriminator is implementation size + risk, not a hard file count.
The change-note is Tier 1 in the FR-23 documentation budget (
flow-skills/documentation-budget/SKILL.md): FR-21 scales process ceremony; FR-23 scales persistent documentation. A Lightweight ticket's documentation IS the change-note — do not also emit spec/decisions/tasks/handoff docs for it.
When to classify (every ticket, at Specify)
Classify Full or Lightweight when the ticket is opened. requirements-specification calls this gate. Record change_tier (in the change-note for LL; in spec.md for Full).
Eligibility gate — Lightweight iff ALL of these hold
| # | Condition | Concrete check |
|---|---|---|
| 1 | Small implementation, single coherent concern | Modest code, no large/multi-part build, no real architectural decision. A handful of files is fine — the test is "no large implementation AND no real decision needed," not a file count. |
| 2 | Reversible | git revert / restore-backup undoes it. No DB schema/data migration; no hard-to-remove new dependency. |
| 3 | Clear, mechanically-verifiable acceptance | A defined outcome (one or a few sentences) checkable by a gate / probe / measurement. |
| 4 | No new security surface | No authz / permission / protected-path / secret-handling change. |
| 5 | No cross-cutting / public-contract change needing a decision | No new API / route / manifest needing an architectural choice (a routine in-place SKIP-upgrade deploy is fine); no broad refactor. |
| 6 | Root cause already understood | Not a Phase-1 diagnostic. Unknown-cause investigation always uses the Full lane. |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 115 lines · 130 tokens per session scan A 95ecbfcf18db
lightweight-lane is a skill published in the GitHub repository fusebase-dev/fusebase-flow (9 stars, last pushed 7d ago), licensed MIT. It adds 130 tokens to every session and 2,893 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
adobe-express-core
Adobe Express environment essentials, two-runtime architecture, project setup, and MCP server configuration. Use when starting add-on development, understanding iframe vs sandbox boundaries, configuring MCP servers, setting up local projects, or validating manifest configuration.
adobe-express-monetization
Monetize Adobe Express add-ons with subscriptions and payments. Use when designing checkout flows, defining subscription tiers, implementing webhook verification, managing entitlements, or securing backend billing logic.
adobe-express-spectrum-ui-ux
Build or review Adobe Express add-on panel UI with Spectrum patterns, stack selection guidance (raw SWC, swc-react, React Spectrum), Express theme setup, state and navigation design, and actionable UX quality checks. Use when implementing or auditing panel layouts, interaction states, multi-screen flows, and…
adobe-express-cors-and-backend
Diagnose and fix CORS errors between Adobe Express add-on UI and backend APIs across local development, private listing, and public listing stages. Use when browser requests fail with preflight, Access-Control-Allow-Origin, Access-Control-Allow-Headers, or OPTIONS issues; when moving from localhost to hosted add-on…
adobe-express-document-manipulation
Create and modify document content in Adobe Express add-ons using Document SDK. Use when planning document operations, inserting shapes/text/media, sequencing sandbox commands, or troubleshooting document edits.
adobe-express-oauth-authentication
Implement OAuth 2.0 and authentication flows for Adobe Express add-ons. Use when connecting to cloud providers (Dropbox, OneDrive, Google Drive), managing tokens, storing credentials, or designing login surfaces.