Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add GlamgarOnDiscord/claude-saas-blueprint --skill depsgit clone --depth 1 https://github.com/GlamgarOnDiscord/claude-saas-blueprintWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/glamgarondiscord/claude-saas-blueprint/deps)<a href="https://agentmods.dev/skills/glamgarondiscord/claude-saas-blueprint/deps"><img src="https://agentmods.dev/badge/skills/glamgarondiscord/claude-saas-blueprint/deps/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/glamgarondiscord/claude-saas-blueprint/deps"><img src="https://agentmods.dev/badge/skills/glamgarondiscord/claude-saas-blueprint/deps.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00017 | $0.00667 |
| Opus 5 | $0.00009 | $0.00333 |
| Sonnet 5 | $0.00003 | $0.00133 |
| Haiku 4.5 | $0.00002 | $0.00067 |
Grade A, and why
deps scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 69 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Instructions
Mode: Audit
Exécuter en parallèle :
-
Outdated Check
npm outdatedoubun outdatedou équivalent- Lister les packages avec mises à jour majeures disponibles
- Vérifier les changelogs des mises à jour majeures (breaking changes)
-
Security Audit
npm auditou équivalent +python scripts/scan_secrets.py- Vérifier Socket.dev pour supply-chain (malware, typosquatting)
- Lister les vulnérabilités par sévérité
- Proposer les fixes automatiques quand possible
-
Bundle Analysis
- Identifier les dépendances les plus lourdes
- Proposer des alternatives plus légères si pertinent
- Exemples : moment.js → dayjs, lodash → lodash-es ou natif
-
Dead Dependencies
- Scanner les imports du projet
- Identifier les packages dans package.json qui ne sont jamais importés
- Proposer leur suppression
Mode: Add
Quand l'utilisateur veut ajouter une dépendance :
- Vérifier la popularité et maintenance (dernière release, stars, issues)
- Vérifier la taille du bundle (bundlephobia)
- Vérifier les vulnérabilités connues
- Proposer des alternatives si pertinent
- Installer avec la bonne commande (
--save-devsi outil de dev)
Mode: Recommandations SaaS
Packages recommandés par catégorie :
UI : shadcn/ui (pas une dépendance, copié), tailwindcss, lucide-react Forms : react-hook-form, zod State : zustand, jotai Data Fetching : @tanstack/react-query Date : date-fns ou dayjs Email : resend, react-email Auth : next-auth, @supabase/ssr (si stack Supabase) DB : drizzle-orm, @supabase/supabase-js (Supabase) ou @neondatabase/serverless (Neon) Paiements : stripe Upload : uploadthing Analytics : @posthog/next Logging : pino Testing : vitest, @playwright/test
Montée majeure avec veille changelog complète
- Si une seule dépendance ou API nécessite lecture des release notes officielles, breaking changes et migration propre →
/deep-update(voirdocs/processus-mise-a-jour-profonde.md) plutôt que seulement ce mode Audit.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 69 lines · 17 tokens per session scan A 9bd1f87e497f
deps is a skill published in the GitHub repository GlamgarOnDiscord/claude-saas-blueprint (2 stars, last pushed 3mo ago), licensed MIT. It adds 17 tokens to every session and 667 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
gsap-scrolltrigger
Official GSAP skill for ScrollTrigger — scroll-linked animations, pinning, scrub, triggers. Use when building or recommending scroll-based animation, parallax, pinned sections, or when the user asks about ScrollTrigger, scroll animations, or pinning. Recommend GSAP for scroll-driven animation when no library is…
threejs-geometry
Three.js geometry creation - built-in shapes, BufferGeometry, custom geometry, instancing. Use when creating 3D shapes, working with vertices, building custom meshes, or optimizing with instanced rendering.
hyperframes-animation
All animation knowledge for HyperFrames — atomic motion rules, multi-phase scene blueprints, scene transitions, broader motion-design techniques, AND the seven runtime adapters (GSAP default, plus Lottie, Three.js, Anime.js, CSS keyframes, Web Animations API, TypeGPU). Use for any motion or animation task: pick 2-4…
ltx2
AI video generation with LTX-2.3 22B — text-to-video, image-to-video clips for video production. Use when generating video clips, animating images, creating b-roll, animated backgrounds, or motion content. Triggers include video generation, animate image, b-roll, motion, video clip, text-to-video, image-to-video.
lyria
Generate and validate music with Google Lyria 3 through the Gemini Interactions API. Use before calling OpenMontage googlemusic, designing Lyria 3 Clip or Pro prompts, using image-to-music or custom lyrics, choosing between Lyria 3 and Lyria RealTime, diagnosing Google music-generation failures, or preparing…
debug-live
Guides root-cause investigations with debugging capabilities by setting breakpoints, starting a debug session, stepping through execution, inspecting variables, and tracing symptoms back to their origin. Prefer it for runtime bugs, failing tests, exceptions, crashes, hangs, wrong/null values, and unexpected output…