Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/mdcms-ai/mdcms/mdcms-content-sync-workflownpx skills add mdcms-ai/mdcms --skill mdcms-content-sync-workflowgit clone --depth 1 https://github.com/mdcms-ai/mdcmsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00159 | $0.02409 |
| Opus 5 | $0.00079 | $0.01205 |
| Sonnet 5 | $0.00032 | $0.00482 |
| Haiku 4.5 | $0.00016 | $0.00241 |
Grade A, and why
mdcms-content-sync-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 177 lines — stays where its author put it; the contents beside it link to each section on GitHub.
MDCMS Content Sync Workflow
Operate the local↔server content loop day-to-day: pulling fresh content, pushing edits, logging in/rotating keys, and automating publishes in CI. Assumes mdcms-brownfield-init or mdcms-greenfield-init already ran.
When to use this skill
Anything operational: syncing content, managing credentials, automating publishing. Not for first-time setup (that's brownfield/greenfield init), not for schema changes (that's mdcms-schema-refine).
Core mental model
- Drafts live on the server and in local working copies. Editing locally +
mdcms pushupdates the draft on the server. Editing in Studio writes directly to the server draft. Draft reads require an explicitdraft: trueAPI/SDK request and appropriate credentials. Host apps can intentionally expose draft preview routes, but private previews should verify a Studio preview token, host session, or equivalent server-side gate first. - Publishing is a separate explicit action (via Studio or the CLI's publish surface when applicable). Published documents are what unauthenticated readers of the host app see.
- Manifest — MDCMS tracks per-
(project, environment)document state in.mdcms/manifests/<project>.<environment>.json. The CLI uses it for hash-based change detection. It's not committed; each developer has their own.
Step 0 — make sure the user is logged in
Always preflight authentication before any pull/push/status/publish. Every authenticated CLI command resolves credentials in this order: --api-key flag → MDCMS_API_KEY env var → stored credential keyed by (serverUrl, project, environment). The first non-empty wins. If none resolves, the CLI exits with an auth error and the user needs to log in.
Quick check:
npx mdcms status
- Exit 0 with a normal status report → credentials are fine, proceed.
- Exit non-zero with
401,unauthorized,Not logged in,No credential found, or a prompt for an API key → not logged in for this(serverUrl, project, environment)tuple.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 177 lines · 159 tokens per session scan A acce5f271cc1
mdcms-content-sync-workflow is a skill published in the GitHub repository mdcms-ai/mdcms (22 stars, last pushed 4d ago), licensed MIT. It adds 159 tokens to every session and 2,409 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
migrate-internal-package
Move a package from another TryGhost repository into Ghost as an internal-only workspace package while preserving its Git history. Use for package migrations from repositories such as TryGhost/SDK or TryGhost/framework, including the history import PR, exceptional merge-commit handoff, source-repository removal PR…
Shade dropdown surface contract
DropdownMenu, Select, and Popover share one visual recipe (bg-surface-elevated-2 + border-border/60 dark:border-border/30 + shadow-md). Change them together. Trigger when editing any of those three Shade files.
Shade page templates
Pick the right Shade page template (ListPage, PageHeader) for a new admin page instead of inventing chrome. Trigger when creating new admin pages or routes in apps/admin or apps/activitypub.
Shade use primitives
Replace bare divs that only carry flex/grid/gap utilities with Shade primitives (Stack, Inline, Box, Grid, Container, Text). Use semantic gap="md" instead of gap-4. Trigger when editing TSX in Shade-consuming apps.
ui4
Manually invoked skill for reskinning Payload UI components. Requires Figma URL. Usage: /ui4.
payload
Use when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.