Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/marve10s/better-fullstack/add-to-projectnpx skills add Marve10s/Better-Fullstack --skill add-to-projectgit clone --depth 1 https://github.com/Marve10s/Better-FullstackWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/marve10s/better-fullstack/add-to-project)<a href="https://agentmods.dev/skills/marve10s/better-fullstack/add-to-project"><img src="https://agentmods.dev/badge/skills/marve10s/better-fullstack/add-to-project.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00071 | $0.00451 |
| Opus 5 | $0.00036 | $0.00226 |
| Sonnet 5 | $0.00014 | $0.00090 |
| Haiku 4.5 | $0.00007 | $0.00045 |
Grade A, and why
add-to-project scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Add to an Existing Better Fullstack Project
Use the Better Fullstack MCP server for existing-project updates. Do not hand-edit generated stack metadata or guess which template files belong to a capability.
Workflow
- Confirm the project directory and ensure it contains
bts.jsonc. - Call
bfs_get_guidanceandbfs_get_schema. - For capability changes, call
bfs_plan_stack_updatewith the targetprojectDirand requested stack fields. - Review the preview, including blockers, file changes, dependency changes, env changes, and compatibility adjustments.
- Call
bfs_apply_stack_updateonly when the plan is acceptable. - For legacy addon/deploy-only changes, call
bfs_plan_additionbeforebfs_add_feature. - Report changed files and the exact install/test commands.
Rules
- Keep update semantics preview-first.
- Prefer additive updates first: generated CI, docs, observability, email, search, vector DB, file storage, rate limiting, and mobile capabilities.
- Treat database, ORM, auth, API, and payment-provider swaps as risky and make compatibility changes explicit.
- Set installs disabled unless the user asks for dependency installation.
- Do not start a dev server.
CLI-only fallback
If the Better Fullstack MCP tools are unavailable, inspect the current flags with
npx -y create-better-fullstack@latest add --help, then run the explicit add command with
--project-dir <path> --dry-run --no-install. Review that preview before rerunning without
--dry-run. Do not guess option names or hand-edit generated stack metadata.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago Changed · +7 lines 8dda945ce63b
- 6d ago First seen · 36 lines · 71 tokens per session scan A 4ee12c69b53b
add-to-project is a skill published in the GitHub repository Marve10s/Better-Fullstack (729 stars, last pushed yesterday), licensed MIT. It adds 71 tokens to every session and 451 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
review-pr
Review a Deno runtime pull request for correctness, tests, security, and conventions. Use when asked to review a PR or when a PR number/URL is provided for review.
node-compat
Run a Node.js compatibility test, diagnose failures, and either fix the implementation, skip, or ignore the test. Use when asked to work on node compat tests.
fmt
Format all code in the repository. Run before opening a PR or committing changes.
lint-all
Lint all code (Rust + JS/TS). Use before opening a PR when Rust code was changed.
lint-js
Lint JS/TS code only. Use before opening a PR when only JavaScript or TypeScript files were changed (no Rust).
go-rust-reverse
Use for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.