mdcms-content-sync-workflow

A day-to-day synchronization workflow for MDCMS, a content management system that keeps Markdown files and server content in step. It covers pulling, pushing, login, publishing, and continuous-integration automation.

In plain words
What is it for?
Use it to pull fresh content, push local edits, manage API credentials, publish changes, and automate publishing in CI.
Why use it?
It clarifies the difference between drafts and published content and helps resolve authentication or synchronization problems.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/mdcms-ai/mdcms/mdcms-content-sync-workflow
Any agent
npx skills add mdcms-ai/mdcms --skill mdcms-content-sync-workflow
Clone the repo
git clone --depth 1 https://github.com/mdcms-ai/mdcms

Made for: Claude Code, Codex.

Per session 159 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,409 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00159 $0.02409
Opus 5 $0.00079 $0.01205
Sonnet 5 $0.00032 $0.00482
Haiku 4.5 $0.00016 $0.00241

Measured 2d ago against content hash acce5f271cc1, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

mdcms-content-sync-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/mdcms-content-sync-workflow/SKILL.md · 177 lines

How it starts

The opening of the file, as written. The whole thing — 177 lines — stays where its author put it; the contents beside it link to each section on GitHub.

MDCMS Content Sync Workflow

Operate the local↔server content loop day-to-day: pulling fresh content, pushing edits, logging in/rotating keys, and automating publishes in CI. Assumes mdcms-brownfield-init or mdcms-greenfield-init already ran.

When to use this skill

Anything operational: syncing content, managing credentials, automating publishing. Not for first-time setup (that's brownfield/greenfield init), not for schema changes (that's mdcms-schema-refine).

Core mental model

  • Drafts live on the server and in local working copies. Editing locally + mdcms push updates the draft on the server. Editing in Studio writes directly to the server draft. Draft reads require an explicit draft: true API/SDK request and appropriate credentials. Host apps can intentionally expose draft preview routes, but private previews should verify a Studio preview token, host session, or equivalent server-side gate first.
  • Publishing is a separate explicit action (via Studio or the CLI's publish surface when applicable). Published documents are what unauthenticated readers of the host app see.
  • Manifest — MDCMS tracks per-(project, environment) document state in .mdcms/manifests/<project>.<environment>.json. The CLI uses it for hash-based change detection. It's not committed; each developer has their own.

Step 0 — make sure the user is logged in

Always preflight authentication before any pull/push/status/publish. Every authenticated CLI command resolves credentials in this order: --api-key flag → MDCMS_API_KEY env var → stored credential keyed by (serverUrl, project, environment). The first non-empty wins. If none resolves, the CLI exits with an auth error and the user needs to log in.

Quick check:

npx mdcms status
  • Exit 0 with a normal status report → credentials are fine, proceed.
  • Exit non-zero with 401, unauthorized, Not logged in, No credential found, or a prompt for an API key → not logged in for this (serverUrl, project, environment) tuple.

Read the full file on GitHub · 177 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 177 lines · 159 tokens per session scan A acce5f271cc1

Subscribe to this mod's changes

mdcms-content-sync-workflow is a skill published in the GitHub repository mdcms-ai/mdcms (22 stars, last pushed 4d ago), licensed MIT. It adds 159 tokens to every session and 2,409 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

migrate-internal-package

Move a package from another TryGhost repository into Ghost as an internal-only workspace package while preserving its Git history. Use for package migrations from repositories such as TryGhost/SDK or TryGhost/framework, including the history import PR, exceptional merge-commit handoff, source-repository removal PR…

TryGhost/Ghost · 77 tokens

Shade dropdown surface contract

DropdownMenu, Select, and Popover share one visual recipe (bg-surface-elevated-2 + border-border/60 dark:border-border/30 + shadow-md). Change them together. Trigger when editing any of those three Shade files.

TryGhost/Ghost · 54 tokens

Shade page templates

Pick the right Shade page template (ListPage, PageHeader) for a new admin page instead of inventing chrome. Trigger when creating new admin pages or routes in apps/admin or apps/activitypub.

TryGhost/Ghost · 44 tokens

Shade use primitives

Replace bare divs that only carry flex/grid/gap utilities with Shade primitives (Stack, Inline, Box, Grid, Container, Text). Use semantic gap="md" instead of gap-4. Trigger when editing TSX in Shade-consuming apps.

TryGhost/Ghost · 54 tokens

ui4

Manually invoked skill for reskinning Payload UI components. Requires Figma URL. Usage: /ui4.

payloadcms/payload · 25 tokens

payload

Use when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.

payloadcms/payload · 43 tokens