Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/outlinedriven/outline-driven-development/control-uinpx skills add OutlineDriven/outline-driven-development --skill control-uigit clone --depth 1 https://github.com/OutlineDriven/outline-driven-developmentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/outlinedriven/outline-driven-development/control-ui)<a href="https://agentmods.dev/skills/outlinedriven/outline-driven-development/control-ui"><img src="https://agentmods.dev/badge/skills/outlinedriven/outline-driven-development/control-ui.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00040 | $0.00727 |
| Opus 5 | $0.00020 | $0.00364 |
| Sonnet 5 | $0.00008 | $0.00145 |
| Haiku 4.5 | $0.00004 | $0.00073 |
Grade A, and why
control-ui scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- control-ui — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 42 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Control UI
Contract
| Field | Bound contract |
|---|---|
| Trigger | Verify or reproduce browser/Electron UI behavior. |
| Authority | Write only named local evidence artifacts under the working directory and discard spawned processes on exit. Rollback: delete the evidence directory and kill any spawned process. |
| Side effect | Runs the app or a browser locally and captures screenshots, console logs, and DOM state into one named evidence directory. |
| Done | Before/after UI evidence exists in the named directory and no spawned app or browser process remains. |
Inputs
Required: a UI target that is a local app command, a local URL, or an Electron entry, and the behavior to verify or reproduce.
Optional: a viewport size, an authentication state file, and an evidence directory name (defaults to a timestamped folder under the working directory).
Procedure
- Confirm that the target is a local app command, local URL, or Electron entry supplied by the human. Refuse remote URLs or targets requiring credentials the human did not provide. Done when: the target is classified as local app, local URL, or Electron entry, and any remote or credential-bearing target is refused.
- Create or reuse the named evidence directory under the working directory. Done when: the evidence directory exists under the working directory.
- Capture the before state: launch the app or browser, navigate to the target, and record the viewport, screenshot, console log, and relevant DOM state into the evidence directory as
before.*. Done when:before.*files (viewport, screenshot, console log, DOM state) are written to the evidence directory. - Perform the behavior being verified (click, input, or navigation), or follow the reported reproduction steps. Record each step taken. Done when: every behavior step taken is recorded.
- Capture the after state: record the screenshot, console log, and DOM state into the evidence directory as
after.*. Done when:after.*files (screenshot, console log, DOM state) are written to the evidence directory. - Compare before and after evidence against the expected behavior. Record pass, fail, or mismatch with the differing evidence file names. Done when: a pass, fail, or mismatch classification is recorded citing the differing evidence file names.
- Terminate every spawned app or browser process and confirm none remain. Done when: no spawned app or browser process remains.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 42 lines · 40 tokens per session scan A ee73f15c1553
control-ui is a skill published in the GitHub repository OutlineDriven/outline-driven-development (52 stars, last pushed yesterday), licensed Apache-2.0. It adds 40 tokens to every session and 727 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
browser-testing
Test and debug browser code with Chrome DevTools MCP. Use when building or debugging browser UI, inspecting the DOM, capturing console errors, analyzing network requests, or verifying visual output.
v8-jit
V8 JIT optimization patterns for writing high-performance JavaScript in Next.js server internals. Use when writing or reviewing hot-path code in app-render, stream-utils, routing, caching, or any per-request code path. Covers hidden classes / shapes, monomorphic call sites, inline caches, megamorphic deopt, closure…
use-agent-browser-for-airi
Test AIRI display-model imports with agent-browser across stage-tamagotchi Electron, stage-web, and stage-pocket mobile web layouts. Use when uploading and verifying contributor-supplied Live2D ZIP, VRM, or MMD ZIP/PMX/PMD files through AIRI's model selector, including onboarding bypass, format-specific import…
webapp-testing
Toolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debugging UI behavior, capturing browser screenshots, and viewing browser logs.
azure-messaging-webpubsub-java
Build real-time web applications with Azure Web PubSub SDK for Java. Use when implementing WebSocket-based messaging, live updates, chat applications, or server-to-client push notifications.
web-browser
Automate and interact with web pages through Chrome or Chromium using the Chrome DevTools Protocol (CDP): navigate, click, fill forms, inspect content, take screenshots, and debug console or network activity. Use when an agent needs a real browser. Prefer headless Chrome unless visible browser interaction is required.