Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add OpenAEC-Foundation/OpenAEC-Workspace-Composer --skill vite-syntax-env-varsgit clone --depth 1 https://github.com/OpenAEC-Foundation/OpenAEC-Workspace-ComposerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/openaec-foundation/openaec-workspace-composer/vite-syntax-env-vars)<a href="https://agentmods.dev/skills/openaec-foundation/openaec-workspace-composer/vite-syntax-env-vars"><img src="https://agentmods.dev/badge/skills/openaec-foundation/openaec-workspace-composer/vite-syntax-env-vars/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/openaec-foundation/openaec-workspace-composer/vite-syntax-env-vars"><img src="https://agentmods.dev/badge/skills/openaec-foundation/openaec-workspace-composer/vite-syntax-env-vars.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00119 | $0.02097 |
| Opus 5 | $0.00060 | $0.01048 |
| Sonnet 5 | $0.00024 | $0.00419 |
| Haiku 4.5 | $0.00012 | $0.00210 |
Grade A, and why
vite-syntax-env-vars scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 233 lines — stays where its author put it; the contents beside it link to each section on GitHub.
vite-syntax-env-vars
Quick Reference
Built-in Constants (import.meta.env)
| Property | Type | Description |
|---|---|---|
import.meta.env.MODE |
string |
Current mode ("development", "production", or custom) |
import.meta.env.BASE_URL |
string |
Base URL from base config option |
import.meta.env.PROD |
boolean |
true when running in production |
import.meta.env.DEV |
boolean |
true when running in development (ALWAYS inverse of PROD) |
import.meta.env.SSR |
boolean |
true when running server-side |
.env File Loading Order (Priority: Low to High)
| Priority | File | Loaded When | Gitignored |
|---|---|---|---|
| 1 (lowest) | .env |
All modes | No |
| 2 | .env.local |
All modes | Yes |
| 3 | .env.[mode] |
Matching mode only | No |
| 4 | .env.[mode].local |
Matching mode only | Yes |
| 5 (highest) | OS environment variables | Always | N/A |
OS environment variables ALWAYS take highest priority and NEVER get overwritten by .env files.
Critical Warnings
NEVER set
envPrefixto''(empty string). This exposes ALL environment variables to client-side code, including secrets likeDB_PASSWORD,AWS_SECRET_KEY, and session tokens. This is a critical security vulnerability.
NEVER put secrets in
VITE_-prefixed variables. Any variable with theVITE_prefix is embedded in the client bundle and visible to anyone inspecting the browser source. Use server-side environment variables or a backend API for secrets.
VITE_ Prefix Rule
Only variables prefixed with VITE_ are exposed to client code via import.meta.env:
VITE_API_URL=https://api.example.com # Exposed: import.meta.env.VITE_API_URL
VITE_APP_TITLE=My App # Exposed: import.meta.env.VITE_APP_TITLE
DB_PASSWORD=secret123 # NOT exposed: import.meta.env.DB_PASSWORD === undefined
SECRET_KEY=abc # NOT exposed: import.meta.env.SECRET_KEY === undefined
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 233 lines · 119 tokens per session scan A eb2b11c1490e
vite-syntax-env-vars is a skill published in the GitHub repository OpenAEC-Foundation/OpenAEC-Workspace-Composer (5 stars, last pushed 5mo ago), licensed MIT. It adds 119 tokens to every session and 2,097 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
panel-app-creator
Create or update the Panel UI component of a complete schema v2 NextClaw Mini App or an explicitly loose local Panel. Use after nextclaw-app-creator selects Panel-only or Panel + Service, or for right-side UI, Service Actions, Agent-powered panels, React/Vite panels, and App bridge capability questions.
gemigo-cli
Use when the user wants to publish an already-built static website or front-end app through GemiGo, such as a Vite/React/Vue static build, plain HTML/CSS/JS page, landing page, demo, docs site, or small browser app, and get a hosted public URL.
impeccable
Use when the user wants distinctive, production-grade frontend design, anti-generic AI aesthetics, UX critique, technical UI audits, or final polish through bundled Impeccable references and an optional upstream detector CLI.
color-palette-generator
Create an HTML color palette from a mood, description, or image, with swatches, color codes, pairings, and contrast checks. Use for color schemes or brand colors.
ui-ux-pro-max
Use when the user wants professional UI/UX design guidance, design-system generation, UX review, or stack-specific frontend guidance through a bundled local UI/UX Pro Max dataset and Python search runtime.
panel-app-react-vite-creator
Create or update an engineering-style NextClaw Panel component with pnpm, Vite, React, TypeScript, and Tailwind CSS, then build it into a static .panel directory inside a schema v2 package or an explicitly loose workspace Panel. Use for modern, reusable, complex, Agent-powered, typed Panel interfaces.