Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/launch52-ai/flutter-template/phone-authnpx skills add launch52-ai/flutter-template --skill phone-authgit clone --depth 1 https://github.com/launch52-ai/flutter-templateWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/launch52-ai/flutter-template/phone-auth)<a href="https://agentmods.dev/skills/launch52-ai/flutter-template/phone-auth"><img src="https://agentmods.dev/badge/skills/launch52-ai/flutter-template/phone-auth.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00039 | $0.00905 |
| Opus 5 | $0.00019 | $0.00452 |
| Sonnet 5 | $0.00008 | $0.00181 |
| Haiku 4.5 | $0.00004 | $0.00090 |
Grade A, and why
phone-auth scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 112 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Phone Auth - Phone OTP Authentication
Phone number OTP authentication with Clean Architecture. Backend handles security (OTP generation, rate limiting). Mobile handles UX (formatting, countdown, error display).
When to Use This Skill
- Adding phone number login/signup to a Flutter app
- Implementing OTP verification flows
- User asks to "add phone auth", "phone login", or "OTP verification"
Questions to Ask
- Backend type: Supabase or Custom API?
- Countries data: Local JSON (faster) or Backend API (dynamic)?
Responsibilities
| Mobile | Backend |
|---|---|
| Display country picker | OTP generation (cryptographic) |
| Format phone input | OTP storage (hashed) |
| Convert to E.164 | Rate limiting |
| Show countdown timer | Expiration checking |
| Display errors | Attempt counting |
| Call backend APIs | User auth/creation |
Reference Files
reference/
├── models/ # Country model (Freezed)
├── utils/ # Phone formatting, E.164 conversion
├── repositories/ # Domain interface + mock
├── providers/ # Riverpod notifier + state
└── failures/ # Sealed Failure types
See: implementation-guide.md for complete file list and copy instructions.
Workflow
- Copy
data/countries.jsontoassets/data/ - Copy reference files to project (see implementation-guide.md)
- Implement repository (Supabase or API) - see implementation-guide.md
- Register provider in
lib/core/providers.dart - Run
dart run build_runner build - Use
/designfor UI components
Core API
// Format and convert
final e164 = PhoneFormatUtils.toE164(localNumber, country);
// Send OTP
await repository.sendOtp(e164);
// Verify OTP
await repository.verifyOtp(phoneNumber, otp);
Failure Types
| Type | When | UI Action |
|---|---|---|
InvalidPhoneFailure |
Bad format | Validation error |
RateLimitFailure(retryAfter) |
Too many sends | Countdown |
InvalidOtpFailure(remaining) |
Wrong OTP | Show attempts |
OtpExpiredFailure |
OTP timed out | Resend option |
MaxAttemptsFailure |
3+ failures | Force new OTP |
PhoneAuthNetworkFailure |
Connection | Retry button |
What ships with it
16 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- best-practices-guide.md 2.3 KB
- checklist.md 6.6 KB
- data/countries.json 20 KB
- implementation-guide.md 6.6 KB
- phone-formats-guide.md 1.9 KB
- reference/exceptions/phone_auth_exceptions.dart 1.3 KB
- reference/failures/phone_auth_failures.dart 3.6 KB
- reference/models/country.dart 2.5 KB
- reference/providers/phone_auth_provider.dart 3.6 KB
- reference/providers/phone_auth_providers.dart 3.0 KB
- reference/providers/phone_auth_state.dart 1.8 KB
- reference/repositories/mock_phone_auth_repository.dart 5.7 KB
- reference/repositories/phone_auth_repository.dart 3.3 KB
- reference/utils/countries_data.dart 2.3 KB
- reference/utils/phone_format_utils.dart 2.5 KB
- reference/utils/phone_number_formatter.dart 2.1 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 112 lines · 39 tokens per session scan A 23e011599e47
phone-auth is a skill published in the GitHub repository launch52-ai/flutter-template (2 stars, last pushed 6mo ago), licensed MIT. It adds 39 tokens to every session and 905 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
merge-seed
Merge upstream React Starter Kit updates (the seed remote) into main, preserving this project's identity, scope, and behavior. Use when asked to sync, pull, or merge the seed / starter kit / upstream template.
django-celery-expert
Expert Django Celery guidance for asynchronous task processing. Use when designing background tasks, configuring Celery workers, handling task retries and errors, optimizing Celery performance, implementing periodic tasks with Celery Beat, or setting up production monitoring for Celery. Do not use for general Django…
django-expert
Expert Django backend development guidance. Use when creating Django models, views, serializers, or APIs; debugging ORM queries or migrations; optimizing database performance; implementing authentication; writing tests; or working with Django REST Framework. Follows Django best practices and modern patterns.
shadcn
Manages shadcn components and projects — adding, searching, fixing, debugging, styling, and composing UI, including chat interfaces. Provides project context, component docs, and usage examples. Applies when working with shadcn/ui, component registries, presets, --preset codes, or any project with a components.json…
setup
Interactive project setup from the ai-project-template — replaces the static SETUPGUIDE.md with a guided, multi-step workflow.
template-guide
Navigate template conventions, audit compliance, and guide upgrades for ai-project-template repos.