Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/othmanadi/openui-forge/openui-forge-csharpnpx skills add OthmanAdi/openui-forge --skill openui-forge-csharpgit clone --depth 1 https://github.com/OthmanAdi/openui-forgeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00037 | $0.02726 |
| Opus 5 | $0.00018 | $0.01363 |
| Sonnet 5 | $0.00007 | $0.00545 |
| Haiku 4.5 | $0.00004 | $0.00273 |
Grade A, and why
openui-forge-csharp scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 271 lines — stays where its author put it; the contents beside it link to each section on GitHub.
OpenUI Forge — C#
Build generative UI apps with a React frontend + C# backend. Streams OpenAI API responses directly via an ASP.NET Core Minimal API (.NET 10 LTS) using HttpClient.
Activation Triggers
- "openui csharp", "openui c#", "openui dotnet", "openui aspnet"
- "generative ui csharp", "c# streaming ui backend", "asp.net core openui"
Prerequisites
- Node.js >= 22 (24 LTS recommended) + React >= 18.3.1 (19+ recommended) (frontend)
- .NET SDK 10.0 (backend; .NET 10 is the current LTS, supported until Nov 2028. .NET 8 LTS also works but reaches end of support Nov 2026.)
OPENAI_API_KEYenvironment variable set
Quick Start
- Create the React frontend and install OpenUI deps:
npm install @openuidev/react-ui @openuidev/react-headless @openuidev/react-lang lucide-react zod
- Generate the system prompt:
npx @openuidev/cli generate ./src/lib/library.ts --out backend/system-prompt.txt
- Create the C# backend (see Full Code below)
- Run:
dotnet runon:5000, frontend on:3000
Full Code
Backend: backend/openui-backend.csproj
<Project Sdk="Microsoft.NET.Sdk.Web">
<PropertyGroup>
<TargetFramework>net10.0</TargetFramework>
<Nullable>enable</Nullable>
<ImplicitUsings>enable</ImplicitUsings>
</PropertyGroup>
</Project>
No NuGet packages required. ASP.NET Core,
HttpClient/IHttpClientFactory, andSystem.Text.Jsonall ship in the .NET 10 shared framework referenced byMicrosoft.NET.Sdk.Web.
Backend: backend/Program.cs
using System.Text;
using System.Text.Json;
using System.Text.Json.Serialization;
var builder = WebApplication.CreateBuilder(args);
// Pooled, correctly-disposed HttpClient instances. Infinite timeout because
// this is a long-lived streaming proxy; client disconnects cancel the request.
builder.Services.AddHttpClient("openai", client =>
{
client.Timeout = Timeout.InfiniteTimeSpan;
});
// CORS: lock to the configured frontend origin. Do NOT use AllowAnyOrigin —
// a wildcard would let any site call this backend and burn your API key.
var frontendOrigin =
Environment.GetEnvironmentVariable("FRONTEND_ORIGIN") ?? "http://localhost:3000";
builder.Services.AddCors(options =>
{
options.AddDefaultPolicy(policy =>
policy.WithOrigins(frontendOrigin)
.WithMethods("POST", "OPTIONS")
.AllowAnyHeader());
});
var app = builder.Build();
app.UseCors();
// Load the generated system prompt ONCE at startup; fail fast if missing.
var promptPath = Path.Combine(Directory.GetCurrentDirectory(), "system-prompt.txt");
if (!File.Exists(promptPath))
{
throw new FileNotFoundException(
"system-prompt.txt not found. Generate it with: " +
"npx @openuidev/cli generate ./src/lib/library.ts --out system-prompt.txt",
promptPath);
}
var systemPrompt = await File.ReadAllTextAsync(promptPath);
var apiKey = Environment.GetEnvironmentVariable("OPENAI_API_KEY");
var baseUrl = (Environment.GetEnvironmentVariable("OPENAI_BASE_URL") ?? "https://api.openai.com/v1")
.TrimEnd('/');
var model = Environment.GetEnvironmentVariable("OPENAI_MODEL") ?? "gpt-5.5";
app.MapPost("/api/chat", async (ChatRequest req, IHttpClientFactory httpClientFactory, HttpContext ctx) =>
{
if (string.IsNullOrEmpty(apiKey))
return Results.Json(new { error = "OPENAI_API_KEY not set" }, statusCode: 500);
if (req.Messages is null || req.Messages.Length == 0)
return Results.Json(new { error = "messages must be a non-empty array" }, statusCode: 400);
// Prepend the server-side system prompt; never trust the client to supply it.
var messages = new List<ChatMessage> { new("system", systemPrompt) };
messages.AddRange(req.Messages);
var payload = JsonSerializer.Serialize(new OpenAiRequest(model, true, messages));
using var upstreamRequest = new HttpRequestMessage(
HttpMethod.Post, $"{baseUrl}/chat/completions")
{
Content = new StringContent(payload, Encoding.UTF8, "application/json"),
};
upstreamRequest.Headers.Add("Authorization", $"Bearer {apiKey}");
var client = httpClientFactory.CreateClient("openai");
// ResponseHeadersRead returns as soon as headers arrive, so we read the
// body incrementally off the socket instead of buffering it into memory.
var upstream = await client.SendAsync(
upstreamRequest, HttpCompletionOption.ResponseHeadersRead, ctx.RequestAborted);
if (!upstream.IsSuccessStatusCode)
{
var errorBody = await upstream.Content.ReadAsStringAsync(ctx.RequestAborted);
upstream.Dispose();
return Results.Json(
new { error = $"OpenAI returned {(int)upstream.StatusCode}: {errorBody}" },
statusCode: (int)upstream.StatusCode);
}
return Results.Extensions.SseProxy(upstream);
});
app.Run();
// SSE passthrough: forward OpenAI's native `data: {chunk}\n\n` lines verbatim,
// flushing after each so tokens appear as they arrive. Pair with openAIAdapter().
//
// Idiomatic .NET 10 alternative: if you parse each chunk into a typed payload,
// return TypedResults.ServerSentEvents(IAsyncEnumerable<SseItem<T>>) from
// System.Net.ServerSentEvents — the framework writes the SSE framing for you.
// We keep the raw passthrough because the upstream is ALREADY valid SSE.
static class ResultExtensions
{
public static IResult SseProxy(this IResultExtensions _, HttpResponseMessage upstream)
=> new SseProxyResult(upstream);
}
sealed class SseProxyResult(HttpResponseMessage upstream) : IResult
{
public async Task ExecuteAsync(HttpContext httpContext)
{
var response = httpContext.Response;
response.StatusCode = 200;
response.ContentType = "text/event-stream";
response.Headers.CacheControl = "no-cache";
response.Headers.Connection = "keep-alive";
response.Headers["X-Accel-Buffering"] = "no"; // defeat proxy buffering
try
{
await using var upstreamStream =
await upstream.Content.ReadAsStreamAsync(httpContext.RequestAborted);
using var reader = new StreamReader(upstreamStream, Encoding.UTF8);
while (await reader.ReadLineAsync(httpContext.RequestAborted) is { } line)
{
if (line.Length == 0) continue; // re-emit our own framing below
await response.WriteAsync(line + "\n", httpContext.RequestAborted);
if (line.StartsWith("data:", StringComparison.Ordinal))
await response.WriteAsync("\n", httpContext.RequestAborted);
await response.Body.FlushAsync(httpContext.RequestAborted);
if (line == "data: [DONE]") break;
}
}
catch (OperationCanceledException)
{
// Client aborted — nothing to do.
}
finally
{
upstream.Dispose();
}
}
}
// JsonPropertyName pins wire names to lowercase: incoming binding is
// case-insensitive, but Serialize defaults to PascalCase and OpenAI needs
// lowercase role/content/model.
record ChatMessage(
[property: JsonPropertyName("role")] string Role,
[property: JsonPropertyName("content")] string Content);
record ChatRequest(
[property: JsonPropertyName("messages")] ChatMessage[] Messages);
record OpenAiRequest(
[property: JsonPropertyName("model")] string Model,
[property: JsonPropertyName("stream")] bool Stream,
[property: JsonPropertyName("messages")] List<ChatMessage> Messages);
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 271 lines · 37 tokens per session scan A 0619cf8acc73
openui-forge-csharp is a skill published in the GitHub repository OthmanAdi/openui-forge (22 stars, last pushed 29d ago), licensed MIT. It adds 37 tokens to every session and 2,726 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
openbot-data-access
Governs how the OpenBot browser app reads and writes server data — every request goes through client in app/src/lib/client.ts, every read is a queryOptions factory in app/src/lib/ /queries.ts, every write is a mutationOptions factory in app/src/lib/ /mutations.ts, and components consume them through…
openbot-screen-layout
The default layout for every OpenBot configuration screen — PageShell and its prose/wide widths, PageSection and PageRows, Item row composition, the settings-row pattern where a summary and a chevron open a dialog, and the size and variant vocabulary. This is what a new screen looks like unless an instruction says…
dd-code-generation
Use pup CLI for immediate Datadog operations or generate code for integration into applications.
release-discord-post
Create a Discord-ready Neva release announcement from a GitHub release payload. Use for official Neva Discord release posts.
redux-to-swr
Migrate React components from Redux + Saga to SWR hooks. Use when converting data fetching from Redux store (reducers, sagas, selectors, connect HOC) to SWR-based hooks in CockroachDB DB Console or cluster-ui.
go
Use for Go changes in Neva: authoring, refactoring, debugging, or review.