OpenDesign is an open-source, local-first desktop app that lets coding agents create prototypes, dashboards, slide decks, images, video, and design systems as exportable files. It is used by people working with agent runtimes such as Claude Code, Codex, Cursor, and DeepSeek Harness. The catalogue add-ons extend the OpenDesign workflow with skills, instructions, commands, and plugins.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add nexu-io/open-design --skill hps-true-blueprintgit clone --depth 1 https://github.com/nexu-io/open-designWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/nexu-io/open-design/hps-true-blueprint)<a href="https://agentmods.dev/skills/nexu-io/open-design/hps-true-blueprint"><img src="https://agentmods.dev/badge/skills/nexu-io/open-design/hps-true-blueprint/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/nexu-io/open-design/hps-true-blueprint"><img src="https://agentmods.dev/badge/skills/nexu-io/open-design/hps-true-blueprint.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- Snyk pass
- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Tool Misuse · line 190 Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.Fix: Limit tool chaining depth and validate the output of each tool before passing it to the next. Require explicit user approval for multi-step chains.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00044 | $0.02751 |
| Opus 5 | $0.00022 | $0.01375 |
| Sonnet 5 | $0.00009 | $0.00550 |
| Haiku 4.5 | $0.00004 | $0.00275 |
Grade A, and why
hps-true-blueprint scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 192 lines — stays where its author put it; the contents beside it link to each section on GitHub.
True Blueprint(工程蓝图)
A locked single-theme deck skin ported from the blueprint theme of the
upstream MIT-licensed lewislulu/html-ppt-skill
(36 themes × 31 layouts). The whole deck reads as one engineering drawing
set: blueprint-blue paper, white drafting grid, dashed component outlines,
mono lettering, amber redline annotations.
Start from example.html. Replace content only. Never rewrite the design
system or the runtime script. The theme is LOCKED — no theme cycling, no
colors or fonts outside this spec.
Sibling note:
html-ppt-knowledge-arch-blueprintis the light blueprint variant (cream paper + rust-red ink). This plugin is the opposite-polarity scheme — dark blue field, white ink. Do not blend the two palettes.
Locked token sheet (:root — reproduce verbatim)
:root{
--bg:#0b3a6f; --bg-soft:#0a3260;
--surface:rgba(255,255,255,.06); --surface-2:rgba(255,255,255,.1);
--border:rgba(190,220,255,.3); --border-strong:rgba(190,220,255,.55);
--text-1:#e8f3ff; --text-2:#b8d4f0; --text-3:#7da8cf;
--accent:#ffffff; --accent-2:#aee1ff; --accent-3:#ffd27a;
--good:#8ef0a6; --warn:#ffd27a; --bad:#ff8a96;
--grad:linear-gradient(135deg,#ffffff,#aee1ff);
--grad-soft:linear-gradient(135deg,#0a3260,#0b3a6f);
--radius:2px; --radius-sm:2px; --radius-lg:4px;
--shadow:none; --shadow-lg:0 16px 40px rgba(0,0,0,.3);
--font-sans:'JetBrains Mono','IBM Plex Mono',Menlo,monospace;
--font-serif:'JetBrains Mono',Menlo,monospace;
--font-mono:'JetBrains Mono',SFMono-Regular,Menlo,monospace;
--font-display:'JetBrains Mono',Menlo,monospace;
--letter-tight:-.02em; --letter-normal:0;
--ease:cubic-bezier(.4,0,.2,1);
--grid-line:rgba(255,255,255,.06);
--ink:rgba(190,220,255,.45);
}
Color roles: white --accent for headline emphasis, ice-blue --accent-2
for ink lines / connectors / progress, amber --accent-3 strictly for
annotations, callouts and the single highlighted element per slide.
--good/--warn/--bad (mint/amber/coral) are redline-annotation semantics —
use them in eyebrows and ticks only, never as fills.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 192 lines · 44 tokens per session scan A d54599fab2fe
hps-true-blueprint is a skill published in the GitHub repository nexu-io/open-design (95,309 stars, last pushed today), licensed Apache-2.0. It adds 44 tokens to every session and 2,751 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
hps-true-blueprint
Open Design's engineering blueprint: how the sandbox, sidecar, and daemon fit — the system diagram and the invariants. Built as a decision-grade product management deck for engineering org.
replit-deck
For product and technical management work: turn PRDs, roadmaps, RFCs, architecture reviews, and retros into decision documents. Built around the core query "pm-feature-business-case-deck", with product strategy lead judgment, buyer-ready proof, and this outcome: approve the feature, architecture, roadmap, or incident…
html-ppt-graphify-dark-graph
Open Design's feature business case for the plugin marketplace: the user pain, options, tradeoffs, and the measure of success. Built as a decision-grade product management deck for PM, eng, design, leadership.
html-ppt-knowledge-arch-blueprint
Open Design's incident retro: the daemon-restart data bug, the root cause, the fix, and the systemic follow-ups. Built as a decision-grade product management deck for engineering, SRE, leadership.
deck-open-slide-canvas
Open Design's architecture review: the local daemon + agent-runtime design, the tradeoffs, and the decision to lock. Built as a decision-grade product management deck for staff eng, tech leads, security.
deck-blueprint
A presentation design template for explaining architecture and process pipelines on a cream-colored, blueprint-style background.