Getting it into your agent
There is no command for this one: it runs only inside a plugin, and the catalogue could not identify which plugin ships it. The source is linked below.
Wrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mocchalera/xserver-files-mcp/xserver-files-setup)<a href="https://agentmods.dev/skills/mocchalera/xserver-files-mcp/xserver-files-setup"><img src="https://agentmods.dev/badge/skills/mocchalera/xserver-files-mcp/xserver-files-setup.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00063 | $0.02243 |
| Opus 5 | $0.00032 | $0.01122 |
| Sonnet 5 | $0.00013 | $0.00449 |
| Haiku 4.5 | $0.00006 | $0.00224 |
Grade A, and why
xserver-files-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 213 lines — stays where its author put it; the contents beside it link to each section on GitHub.
XServer Files セットアップスキル
いつ使うか
- このリポジトリをクローンした直後
- 新しい XServer サーバーを追加するとき
- セットアップが壊れて最初からやり直すとき
- ユーザーが「セットアップして」「設定して」「使えるようにして」と言ったとき
前提確認
セットアップを始める前に以下を確認する。満たさない場合はユーザーに伝えて中断する。
node --version # v20 以上が必要
手順
以下の Phase を上から順に実行する。各 Phase の冒頭にエージェントの行動指示がある。
Phase 1: インストール
行動: 自動実行。ユーザーへの質問なし。
npm install
成功したら動作確認を実行:
XSERVER_FILES_CONFIG=config/example.config.json node src/cli.js servers
JSON が出力されれば Phase 2 へ進む。
Phase 2: ユーザー情報の収集
行動: ユーザーに以下の情報を質問する。一度にまとめて聞くこと。
設定ファイルを作成するために、XServer の情報を教えてください。XServer サーバーパネル(https://secure.xserver.ne.jp/xapanel/login/xserver/server/ )で確認できます。
- サーバー ID — サーバーパネル上部に表示されています(例:
sv12345)- 操作対象のドメイン — ドメイン設定のドメイン一覧に表示されています(例:
example.com)- ドキュメントルート — ドメイン一覧の「ドキュメントルート」列(例:
/home/sv12345/example.com/public_html)。不明な場合は省略可(/home/<サーバーID>/<ドメイン>/public_htmlをデフォルトとして使用します)- ローカルワークスペースのパス — サイトファイルの pull 先ディレクトリ(例:
~/Dev/xserver-sites)。特に希望がなければデフォルトのままにします
複数ドメインがある場合はすべて聞く。複数サーバーがある場合はサーバーごとに聞く。
Phase 3: 設定ファイルの作成
行動: Phase 2 の回答をもとに自動生成する。ユーザーへの質問なし。
mkdir -p ~/.config/xserver-files-mcp
~/.config/xserver-files-mcp/config.json を以下の形式で作成:
{
"defaultServer": "<サーバーID>",
"localWorkspaceRoot": "<ワークスペースパス or ~/Dev/xserver-sites>",
"servers": {
"<サーバーID>": {
"host": "<サーバーID>.xsrv.jp",
"port": 10022,
"username": "<サーバーID>",
"privateKeyPath": "~/.ssh/xserver_<サーバーID>",
"roots": {
"<ドメイン1>": "<ドキュメントルート or /home/<サーバーID>/<ドメイン1>/public_html>",
"<ドメイン2>": "/home/<サーバーID>/<ドメイン2>/public_html"
}
}
}
}
作成後、設定が正しく読めるか確認:
node src/cli.js servers
エラーが出た場合は設定ファイルの JSON 構文を見直して修正する。
Phase 4: SSH 鍵の生成
行動: 既存の鍵があるか確認してから実行する。
ls ~/.ssh/xserver_<サーバーID> 2>/dev/null
鍵が既に存在する場合はユーザーに確認してから次のステップに進む:
~/.ssh/xserver_<サーバーID>に SSH 鍵が既にあります。この鍵を使いますか?新しく作り直しますか?
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 213 lines · 63 tokens per session scan A c2968da82846
xserver-files-setup is a skill published in the GitHub repository mocchalera/xserver-files-mcp (0 stars, last pushed 2mo ago), licensed MIT. It adds 63 tokens to every session and 2,243 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…
chronicle
Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…