Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/microsoft/rayfin/rayfin-getting-startednpx skills add microsoft/rayfin --skill rayfin-getting-startedgit clone --depth 1 https://github.com/microsoft/rayfinWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00134 | $0.01134 |
| Opus 5 | $0.00067 | $0.00567 |
| Sonnet 5 | $0.00027 | $0.00227 |
| Haiku 4.5 | $0.00013 | $0.00113 |
Grade A, and why
rayfin-getting-started scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Rayfin (Getting Started)
Rayfin is a Backend-as-a-Service: define your data model with TypeScript decorators and Rayfin provides auth, a typed data API, storage, and Fabric hosting.
This skill only handles getting started — getting you from zero into a working Rayfin
project, then handing off. The moment you're in a project, the authoritative, version-locked
skill at .agents/skills/rayfin/SKILL.md — alongside the rayfin MCP and rayfin docs —
owns everything else: schema, auth, storage, querying, deployment. Load it and stop using
this one.
Route, don't improvise
Rayfin's specifics are version-locked per project — schema/decorator syntax, the typed data
API and client queries, auth, storage, and deployment all live in the project's own skill,
MCP, and rayfin docs. Never answer them from memory; remembered Rayfin APIs are routinely
wrong against the installed version. Get into a project, read .agents/skills/rayfin/SKILL.md,
then follow it for version-matched signatures. The in-project skill file and the
rayfin docs CLI are available the moment a project exists — including right after you
scaffold one, in the same session. The rayfin MCP is an extra convenience that may only
come online once the tool reloads the new project, so don't wait on it: lean on the
in-project skill file plus rayfin docs.
Being blocked does not unlock memory. Only treat yourself as blocked if you can reach none
of the version-matched sources — you can't read .agents/skills/rayfin/SKILL.md and can't
run rayfin docs (e.g. tool permissions denied). The rayfin MCP simply not being loaded yet
is not a blocker. When genuinely blocked, say you need those sources to answer accurately
and stop there — don't offer a "general approach" or example code "in the meantime"; that
stopgap is exactly the fabrication this skill exists to prevent.
Already in a Rayfin project?
Check this first — before scaffolding anything, even when the user says "build" or "set up a
new app". A directory is a Rayfin project if it has rayfin/rayfin.yml or a package.json
depending on @microsoft/rayfin-*. Environment signals alone are enough: if the workspace
context shows either — even when you can't open the files yet — treat it as an existing
project and continue in place. Never stand up a nested or sibling project.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 77 lines · 134 tokens per session scan A 171ce9d7f30e
rayfin-getting-started is a skill published in the GitHub repository microsoft/rayfin (591 stars, last pushed 4d ago), licensed MIT. It adds 134 tokens to every session and 1,134 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…