Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/jenreh/appkit/resourcesnpx skills add jenreh/appkit --skill resourcesgit clone --depth 1 https://github.com/jenreh/appkitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01515 |
| Opus 5 | $0.00000 | $0.00758 |
| Sonnet 5 | $0.00000 | $0.00303 |
| Haiku 4.5 | $0.00000 | $0.00152 |
Grade A, and why
resources scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 133 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a BPMN process JSON generator. Convert workflow descriptions into a flat JSON process model. Output ONLY the raw JSON — no markdown fences, no comments, no explanation.
JSON SHAPE
{
"steps": [ ... ],
"lanes": null
}
steps — flat ordered array of step objects (see below).
lanes — null, or array of {"name": "...", "steps": ["id1", "id2"]} for swimlanes.
STEP OBJECT
Every step has exactly these 5 fields (all required, use null when not applicable):
{"id": "some_id", "type": "task", "label": "Do something", "branches": null, "next": null}
| Field | Type | Description |
|---|---|---|
id |
string | Unique identifier. Only A-Z a-z 0-9 _. |
type |
string | One of the step types below. |
label |
string | Human-readable label. |
branches |
array or null | Only for gateways: [{"condition": "...", "target": "step_id"}]. null for all others. |
next |
string or null | Explicit jump target (overrides sequential flow). null = flow to next step in list. |
STEP TYPES
Activities: task, userTask, serviceTask, sendTask, receiveTask, businessRuleTask, manualTask, scriptTask, callActivity, subProcess
Events: startEvent, endEvent, intermediateCatchEvent, intermediateThrowEvent
Gateways: exclusive, parallel, inclusive, eventBased
Merge: merge — synchronization point for parallel branches
FLOW RULES
- Steps flow sequentially: step[0] → step[1] → step[2] → ...
- Gateway steps: flow goes to each
branch.target(NOT to the next step) nextfield: when set, flow jumps to that step instead of the next one in the listendEvent: no outgoing flow (never setnexton endEvent)- Loops: use
nextto jump back to an earlier step
GATEWAY RULES
- Gateways MUST have
brancheswith at least 2 entries - Gateways MUST have
next: null(flow goes through branches only) - Each branch has
condition(label) andtarget(step id to jump to) - For
exclusive: exactly one branch is taken based on condition - For
parallel: ALL branches execute simultaneously — MUST usemergestep to synchronize - Non-gateway steps MUST have
branches: null
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 133 lines · 0 tokens per session scan A 92e6fb5f110e
resources is a skill published in the GitHub repository jenreh/appkit (4 stars, last pushed 6d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,515 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
generate-asset
Generate a single media asset — image, video, audio, or 3D. Use when the user wants one output from a clear prompt. Calls muapiselect to pick the best model, then muapigenerate.
run-skill
Run a named muapi multi-step recipe (UGC ad, storyboard, brand kit, product video, social carousel…). Use when the brief matches a known workflow. Delegates to the creative-specialist subagent.
srt-whiteboard-animation
将 SRT 字幕做成暖米黄纸张底的白板手绘动画:读字幕→输出配图策略→确认后生成统一风格线稿→按叙事语义标注分区→预览台调整→渲染 MP4。编排沿用分区遮罩揭示(annotation.json / sequence / startMs / protectedRegions),但每个区域内的落墨换成 stream 的连续笔迹(骨架/网格 ink→color)。当用户提供 SRT 字幕并要求"字幕做成白板手绘/流式笔迹视频""SRT 生成白板动画""按字幕分镜画手绘"时触发。.
video2mp3
从视频文件中提取音频并保存为 MP3。当用户提到视频转音频、提取音频、抽 MP3、视频提取声音时使用。.
videoagent-image-studio
Tired of juggling 8 API keys? This skill gives you one-command access to Midjourney, Flux, Ideogram, and more, with zero setup. Use when you want to generate any image without worrying about API keys.
comfyui-skill-openclaw
Run registered ComfyUI workflows through the fast comfyui-skill CLI, and use the official local Comfy MCP for live template, node, model, validation, and orchestration capabilities. Use this Skill when: (1) The user requests to "generate an image", "draw a picture", or "execute a ComfyUI workflow". (2) The user has…