Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add muhkoo/builder --skill build-muhkoo-appgit clone --depth 1 https://github.com/muhkoo/builderWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/muhkoo/builder/build-muhkoo-app)<a href="https://agentmods.dev/skills/muhkoo/builder/build-muhkoo-app"><img src="https://agentmods.dev/badge/skills/muhkoo/builder/build-muhkoo-app/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/muhkoo/builder/build-muhkoo-app"><img src="https://agentmods.dev/badge/skills/muhkoo/builder/build-muhkoo-app.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00125 | $0.03882 |
| Opus 5 | $0.00063 | $0.01941 |
| Sonnet 5 | $0.00025 | $0.00776 |
| Haiku 4.5 | $0.00013 | $0.00388 |
Grade A, and why
build-muhkoo-app scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 281 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Build a Muhkoo app
Turn an app idea into a working application on Muhkoo: design
it, provision the backend, and scaffold a real client. The bundled references/,
scripts/, and templates/ in this skill's directory are your toolkit — read the
reference files as you go, don't work from memory.
Files referenced below (
references/…,scripts/…,templates/…) are relative to this skill's directory. Resolve that directory once (it's where this SKILL.md lives) and use absolute paths when running scripts.
What Muhkoo gives an app
ZK auth · a scalable database (client.db) · E2E-encrypted realtime channels
(client.space) · per-user KV + file storage · AI agents that can act on the app ·
serverless functions · hosting — every app gets a DNS subdomain
https://<slug>.apps.muhkoo.dev and can be deployed there (step 7). The SDK is
@muhkoo/connect. Full surface: references/platform.md.
Choosing a template
Before designing, pick the template that fits the idea — they share the same provisioning + hosting machinery, only the client differs:
templates/starter-app(default) — a full Vite + React +@muhkoo/connectapp with ZK auth, database, channels, agents. Use when users log in or the app has per-user data, realtime, or AI.templates/static-site— a lightweight statically-hosted website: plain HTML/CSS/JS (Vite), no auth, no SDK, no ZK. Use for landing pages, marketing sites, docs, portfolios — anything with no logged-in users. It can still call one optional serverless function (e.g. an email list —functions/subscribe.js). See the static-site scaffold.
If unsure, ask (AskUserQuestion). Most of the workflow below assumes the full app; the Static websites note under step 4 covers how the static path differs.
Workflow
1 — Understand the idea
Restate what they want in one or two sentences. Ask only what's genuinely unclear (use AskUserQuestion, ≤3 questions). Typical gaps: who logs in, what records exist, is there a chat/feed, is there an AI assistant. Don't over-ask — most ideas imply the answers.
What ships with it
60 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/decorators.md 4.7 KB
- references/design-guide.md 4.5 KB
- references/design.md 4.8 KB
- references/extracting-scaffolds.md 3.7 KB
- references/hosting.md 4.8 KB
- references/platform.md 10 KB
- references/provisioning.md 7.7 KB
- scaffolds/api-agents.md 2.9 KB
- scaffolds/api-auth-hosted.md 3.0 KB
- scaffolds/api-auth.md 7.0 KB
- scaffolds/api-client.md 1.7 KB
- scaffolds/api-db.md 3.5 KB
- scaffolds/api-functions.md 4.9 KB
- scaffolds/api-kv.md 2.9 KB
- scaffolds/api-message.md 2.5 KB
- scaffolds/api-space.md 4.1 KB
- scaffolds/api-storage.md 3.0 KB
- scaffolds/pwa.md 4.9 KB
- scaffolds/README.md 4.1 KB
- scaffolds/static-site.md 2.5 KB
- scripts/extract-scaffold.mjs 6.6 KB runs code
- templates/starter-app/.env.example 849 B
- templates/starter-app/.github/workflows/deploy.yml 1.2 KB
- templates/starter-app/.gitignore 131 B
- templates/starter-app/cypress.config.ts 759 B runs code
- templates/starter-app/cypress/e2e/01-auth.cy.ts 1.2 KB runs code
- templates/starter-app/cypress/e2e/02-records.cy.ts 1.0 KB runs code
- templates/starter-app/cypress/e2e/03-channel.cy.ts 1.1 KB runs code
- templates/starter-app/cypress/e2e/04-responsive.cy.ts 1.8 KB runs code
- templates/starter-app/cypress/support/e2e.ts 1.7 KB runs code
- templates/starter-app/cypress/tsconfig.json 245 B
- templates/starter-app/index.html 741 B
- templates/starter-app/package.json 1.4 KB
- templates/starter-app/README.md 2.3 KB
- templates/starter-app/src/agent/agentApp.ts 1.7 KB runs code
- templates/starter-app/src/agent/eject.ts 613 B runs code
- templates/starter-app/src/App.tsx 2.4 KB
- templates/starter-app/src/appConfig.ts 1.1 KB runs code
- templates/starter-app/src/auth/AuthContext.tsx 3.2 KB
- templates/starter-app/src/auth/AuthScreen.tsx 1.8 KB
- templates/starter-app/src/features/ChannelChat.tsx 5.5 KB
- templates/starter-app/src/features/RecordsBoard.tsx 5.1 KB
- templates/starter-app/src/lib/client.ts 838 B runs code
- templates/starter-app/src/lib/config.ts 914 B runs code
- templates/starter-app/src/main.tsx 381 B
- templates/starter-app/src/theme.ts 433 B runs code
- templates/starter-app/src/vite-env.d.ts 197 B runs code
- templates/starter-app/tsconfig.app.json 650 B
- templates/starter-app/tsconfig.json 119 B
- templates/starter-app/tsconfig.node.json 570 B
- templates/starter-app/vite.config.ts 1.3 KB runs code
- templates/starter-app/wrangler.jsonc 582 B
- templates/static-site/.env.example 229 B
- templates/static-site/.github/workflows/deploy.yml 1.1 KB
- templates/static-site/.gitignore 64 B
- templates/static-site/functions/subscribe.js 2.9 KB runs code
- templates/static-site/index.html 1.6 KB
- templates/static-site/package.json 463 B
- templates/static-site/README.md 1.3 KB
- templates/static-site/src/main.js 1.6 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 281 lines · 0 tokens per session scan A 5e3c0928c9ef
build-muhkoo-app is a skill published in the GitHub repository muhkoo/builder (2 stars, last pushed 2mo ago), licensed MIT. It adds 125 tokens to every session and 3,882 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
event-store-design
Design and implement event stores for event-sourced systems. Use when building event sourcing infrastructure, choosing event store technologies, or implementing event persistence patterns.
convex-explain-app
Explain an existing Convex app — data model + relationships, public vs internal functions, auth/ownership model, components, a request→data flow — read from the schema and function surface. Read-only.
platform-custom-field-generate
Use this skill when users need to create, generate, or validate Salesforce Custom Field metadata. Trigger when users mention custom fields, field types, Roll-up Summary fields, Master-Detail relationships, Lookup relationships, formula fields, picklists, dependent (controlling) picklists, referencing a value set from…
field-service-sobject-create-configure
Headless 360 REST API deployment step for creating sObject records. Handles describe-based field discovery, required-field derivation, entity-relationship ordering, and composite graph transactions. Use this skill when a designer skill (or a user directly) needs to create sObject records after design confirmation…
openloomi-api
OpenLoomi ships a local-first HTTP API served from the desktop app (port 3414, fallback 3515). All auth, Memory, AI, RAG, Loop, and Audit data live in a local SQLite database — your data stays on your machine and the OpenLoomi app is the source of truth. The only externally-routed auth path is the Composio OAuth…
nornicdb-grpc
Drive NornicDB over gRPC — the Qdrant-compatible surface (Collections, Points, Snapshots) plus the additive NornicSearch service. Use when ingesting via Qdrant SDKs, migrating from Qdrant, or running hybrid text+vector search from a non-Bolt client. Covers connection, RPC catalog, collection→database mapping…