Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add hybridlabor-api/bdb-dev-optimized-agent-skills --skill tdmcp-bridge-endpointgit clone --depth 1 https://github.com/hybridlabor-api/bdb-dev-optimized-agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hybridlabor-api/bdb-dev-optimized-agent-skills/tdmcp-bridge-endpoint)<a href="https://agentmods.dev/skills/hybridlabor-api/bdb-dev-optimized-agent-skills/tdmcp-bridge-endpoint"><img src="https://agentmods.dev/badge/skills/hybridlabor-api/bdb-dev-optimized-agent-skills/tdmcp-bridge-endpoint/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hybridlabor-api/bdb-dev-optimized-agent-skills/tdmcp-bridge-endpoint"><img src="https://agentmods.dev/badge/skills/hybridlabor-api/bdb-dev-optimized-agent-skills/tdmcp-bridge-endpoint.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00177 | $0.01488 |
| Opus 5 | $0.00088 | $0.00744 |
| Sonnet 5 | $0.00035 | $0.00298 |
| Haiku 4.5 | $0.00018 | $0.00149 |
Grade A, and why
tdmcp-bridge-endpoint scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to tdmcp-bridge-endpoint — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 102 lines — stays where its author put it; the contents beside it link to each section on GitHub.
tdmcp-bridge-endpoint — the bridge vertical slice
A bridge feature is correct only when four layers agree on one shape: the Python route, the TS client method, the Zod validator, and the tool that consumes it. This skill is that contract. Build the slice top-to-bottom, keep an exec fallback so it ships safely before every bridge in the wild updates, and prove it all offline.
Run bridge slices one at a time — they share
touchDesignerClient.ts,validators.ts, and the bridge route registry. Two in parallel is merge hell.
Why exec→REST at all
The bridge runs arbitrary Python on /api/exec. A security-conscious VJ runs
TDMCP_BRIDGE_ALLOW_EXEC=0 on a venue network — and ~69 tools silently die.
Promoting a well-defined op (connect, param-mode read/write, DAT text, node
flags, logs) to its own REST route makes it survive that hardened config. You are
promoting proven logic, not inventing it — start from the Python the tool
already sends through /api/exec.
The slice, in order
1. Bridge (Python, td/)
- Add a handler module (or extend the right existing one) and register the
route. Find how routes are registered (the request dispatcher in
td/) and follow that exact pattern — don't invent a second mechanism. - Keep every TD-global (
op,app,project,ui) inside the handler function so the module imports cleanly outside TD (the tests rely on this). - Return a JSON report with a stable shape: a top-level
ok/error and the data. Mirror the envelope the existing endpoints return soparsePythonReport/the validators stay uniform. - Honor
TDMCP_BRIDGE_TOKEN(bearer auth) and theALLOW_EXECgate exactly as sibling routes do — a new route must not become an auth bypass. python3 -m py_compile td/**/<changed>.pyon every changed file.
2. Client method (src/td-client/touchDesignerClient.ts)
- Add one typed method that calls the new route (GET/POST/PATCH/PUT as fits).
- Map failures to the existing typed errors:
TdApiError(4xx/5xx with a body),TdConnectionError(refused/DNS),TdTimeoutError. Never let a raw fetch error escape. - Exec fallback: if the endpoint returns 404 (older bridge without the route),
fall back to the previous
/api/execPython path. This is what lets the promotion ship before the bridge is reinstalled everywhere. Make the fallback a private helper so the test can force both paths.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 102 lines · 177 tokens per session scan A f36c07665324
tdmcp-bridge-endpoint is a skill published in the GitHub repository hybridlabor-api/bdb-dev-optimized-agent-skills (6 stars, last pushed 5d ago), licensed Apache-2.0. It adds 177 tokens to every session and 1,488 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to tdmcp-bridge-endpoint, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
moai-platform-auth
Authentication and authorization specialist covering Auth0, Clerk, and Firebase Auth. Use when implementing authentication, MFA, SSO, passkeys, WebAuthn, social login, or security features.
multi-app-orchestration
Orchestrate workflows across multiple applications and APIs — inter-app coordination, data handoff, and multi-system task completion.
api-documenter
Auto-generate API documentation from code and comments. Use when API endpoints change, or user mentions API docs. Creates OpenAPI/Swagger specs from code. Triggers on API file changes, documentation requests, endpoint additions.
backend-api-development
Comprehensive backend API development skill for building robust, scalable APIs. Use when creating new endpoints, services, or backend functionality. Keywords: API, backend, endpoint, service, REST, GraphQL, server, controller, route.
sinch-functions-node
Write Node.js/TypeScript Sinch Functions with @sinch/functions-runtime. Use when writing or editing function.ts: answering and controlling calls, IVR menus, placing or bridging calls, SMS/WhatsApp/RCS webhooks, custom HTTP endpoints, cache/storage/database, auth and setup() hooks. Also covers legacy Voice v1…
vigilante-issue-implementation-on-php
Implement a GitHub issue end-to-end when Vigilante dispatches work for a PHP repository with Composer, static analysis, and security guidance.