Trellis is an engineering framework that stores project specifications, tasks, and working memory in a repository so coding agents can follow consistent development practices across sessions. Teams use it to organize AI-assisted planning, implementation, review, and validation across multiple coding platforms. The catalogue entries provide Trellis commands, agents, hooks, skills, instructions, and settings.
Borrowing it
Nothing to install: this file belongs to mindfold-ai/Trellis. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/mindfold-ai/Trellis/main/.agents/skills/ts-sdk-author/SKILL.mdgit clone --depth 1 https://github.com/mindfold-ai/TrellisWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mindfold-ai/trellis/ts-sdk-author)<a href="https://agentmods.dev/skills/mindfold-ai/trellis/ts-sdk-author"><img src="https://agentmods.dev/badge/skills/mindfold-ai/trellis/ts-sdk-author.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Tool Misuse · line 390 Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).Fix: Validate all tool parameters against an allowlist. Reject dangerous parameter values (shell=True, --force, -rf /) and use safe defaults.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00219 | $0.06646 |
| Opus 5 | $0.00110 | $0.03323 |
| Sonnet 5 | $0.00044 | $0.01329 |
| Haiku 4.5 | $0.00022 | $0.00665 |
Grade A, and why
ts-sdk-author scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
The source is not reproduced here
Licensed AGPL-3.0
The repository is licensed AGPL-3.0, which this catalogue does not treat as permission to reproduce the file. Read it at the source.
What ships with it
7 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/module-boundaries-and-plugins.md 37 KB
- references/package-json-exports.md 29 KB
- references/tsdown-bundling.md 23 KB
- references/turborepo-for-sdk.md 18 KB
- references/type-design-for-public-api.md 27 KB
- references/verification-and-publishing.md 47 KB
- references/workspace-and-layout.md 23 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 603 lines · 219 tokens per session scan A 7849f53f9093
ts-sdk-author is a skill published in the GitHub repository mindfold-ai/Trellis (14,527 stars, last pushed 12d ago), licensed AGPL-3.0. It adds 219 tokens to every session and 6,646 once invoked, about $0.0011 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
api-framework-nestjs
NestJS backend framework - modules, controllers, services, DI, guards, pipes, interceptors, exception filters, middleware, DTOs with class-validator.
web-forms-zod-validation
Zod schema validation patterns for TypeScript - schema definitions, type inference, refinements, transforms, discriminated unions.
api-framework-hono
Hono routes, OpenAPI, Zod validation.
web-data-fetching-trpc
Skill "web-data-fetching-trpc" from agents-inc/skills, covering trpc patterns, which path applies, before writing trpc code, philosophy and core patterns.
effect-http-api
Build typed HTTP APIs with Effect's HttpApi — endpoints with schemas, handlers, security middleware, OpenAPI docs, derived clients, and handler unit tests. Use when building HTTP servers, REST APIs, or typed HTTP clients with Effect v4.
effect-http-server
Build HTTP servers with effect/unstable/http — HttpRouter routes and middleware, HttpServerRequest schema decoding, HttpServerResponse constructors, multipart uploads, websocket upgrades, static files, NodeHttpServer/BunHttpServer layers, and in-memory web handlers. Use when serving raw HTTP routes, reading request…