rayfin-getting-started

A getting-started guide for Rayfin, a backend service that provides features such as login, typed data access, file storage, and hosting. It helps create a new Rayfin app and then hands work over to the project's version-specific instructions.

In plain words
What is it for?
Use it when creating a Rayfin app or when a Rayfin task begins outside an existing project. It gets the project into a state where its own authoritative tools and documentation can take over.
Why use it?
It gives a new project a supported starting point without relying on possibly outdated Rayfin details. A backend service supplies the server-side parts an app needs.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/microsoft/rayfin/rayfin-getting-started
Any agent
npx skills add microsoft/rayfin --skill rayfin-getting-started
Clone the repo
git clone --depth 1 https://github.com/microsoft/rayfin

Made for: Claude Code, Codex.

Per session 134 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,134 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00134 $0.01134
Opus 5 $0.00067 $0.00567
Sonnet 5 $0.00027 $0.00227
Haiku 4.5 $0.00013 $0.00113

Measured 3d ago against content hash 171ce9d7f30e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

rayfin-getting-started scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/rayfin-getting-started/SKILL.md · 77 lines

How it starts

The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Rayfin (Getting Started)

Rayfin is a Backend-as-a-Service: define your data model with TypeScript decorators and Rayfin provides auth, a typed data API, storage, and Fabric hosting.

This skill only handles getting started — getting you from zero into a working Rayfin project, then handing off. The moment you're in a project, the authoritative, version-locked skill at .agents/skills/rayfin/SKILL.md — alongside the rayfin MCP and rayfin docs — owns everything else: schema, auth, storage, querying, deployment. Load it and stop using this one.

Route, don't improvise

Rayfin's specifics are version-locked per project — schema/decorator syntax, the typed data API and client queries, auth, storage, and deployment all live in the project's own skill, MCP, and rayfin docs. Never answer them from memory; remembered Rayfin APIs are routinely wrong against the installed version. Get into a project, read .agents/skills/rayfin/SKILL.md, then follow it for version-matched signatures. The in-project skill file and the rayfin docs CLI are available the moment a project exists — including right after you scaffold one, in the same session. The rayfin MCP is an extra convenience that may only come online once the tool reloads the new project, so don't wait on it: lean on the in-project skill file plus rayfin docs.

Being blocked does not unlock memory. Only treat yourself as blocked if you can reach none of the version-matched sources — you can't read .agents/skills/rayfin/SKILL.md and can't run rayfin docs (e.g. tool permissions denied). The rayfin MCP simply not being loaded yet is not a blocker. When genuinely blocked, say you need those sources to answer accurately and stop there — don't offer a "general approach" or example code "in the meantime"; that stopgap is exactly the fabrication this skill exists to prevent.

Already in a Rayfin project?

Check this first — before scaffolding anything, even when the user says "build" or "set up a new app". A directory is a Rayfin project if it has rayfin/rayfin.yml or a package.json depending on @microsoft/rayfin-*. Environment signals alone are enough: if the workspace context shows either — even when you can't open the files yet — treat it as an existing project and continue in place. Never stand up a nested or sibling project.

Read the full file on GitHub · 77 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 77 lines · 134 tokens per session scan A 171ce9d7f30e

Subscribe to this mod's changes

rayfin-getting-started is a skill published in the GitHub repository microsoft/rayfin (591 stars, last pushed 4d ago), licensed MIT. It adds 134 tokens to every session and 1,134 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

brainstorming

You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.

obra/superpowers · 37 tokens

auto-perf-optimize

Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.

microsoft/vscode · 62 tokens

chat-perf

Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.

microsoft/vscode · 51 tokens

chat-pet-sprite-creation

Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.

microsoft/vscode · 53 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens