Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Pantani/tdmcp --skill mcpb-bundlegit clone --depth 1 https://github.com/Pantani/tdmcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pantani/tdmcp/mcpb-bundle)<a href="https://agentmods.dev/skills/pantani/tdmcp/mcpb-bundle"><img src="https://agentmods.dev/badge/skills/pantani/tdmcp/mcpb-bundle.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium MCP Rug Pull · line 28 npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.Fix: Pin the version: npx @scope/[email protected]
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00102 | $0.01085 |
| Opus 5 | $0.00051 | $0.00543 |
| Sonnet 5 | $0.00020 | $0.00217 |
| Haiku 4.5 | $0.00010 | $0.00109 |
Grade A, and why
mcpb-bundle scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
2 near-identical copies found in the catalogue:
- mcpb-bundle — 100% identical, 0 lines differ
- mcpb-bundle — 91% identical, 8 lines differ
How it starts
The opening of the file, as written. The whole thing — 70 lines — stays where its author put it; the contents beside it link to each section on GitHub.
tdmcp Desktop bundle: .dxt → .mcpb
Anthropic renamed Desktop Extensions from DXT (.dxt, packer
@anthropic-ai/dxt, manifest key dxt_version) to MCPB (.mcpb, packer
@anthropic-ai/mcpb, manifest key manifest_version). Legacy .dxt still
installs in Codex Desktop, but new directory submissions should ship .mcpb.
What this repo already has
scripts/build-mcpb.mjs is already MCPB-aware: it tries @anthropic-ai/mcpb
first, falls back to legacy @anthropic-ai/dxt, then to a system zip. The
bundle stages manifest.json at the archive root + dist/, recipes/, td/,
README.md, LICENSE, package.json, and a production-only node_modules. So
the migration is mostly renaming the output + the references, not a rewrite.
dxt/manifest.json currently declares "manifest_version": "0.3" — already the
modern MCPB key (not the legacy dxt_version), so the manifest is largely correct.
The migration, concretely
- Manifest — verify, don't guess. Before touching
manifest_version, check what the installed packer accepts:npx --yes @anthropic-ai/mcpb --help(look forpack/validate). If it ships avalidatecommand, run it againstdxt/manifest.jsonand let it tell you. Only changemanifest_versionif validation demands it. A wrong value breaks install — this is why we verify rather than assume a number. - Output filename →
tdmcp.mcpb. Inscripts/build-mcpb.mjs: changeoutFiletotdmcp.mcpband update the log lines (they say.dxt). Keep the packer-preference order and the zip fallback intact — both must still work. Optionally rename the script file tobuild-mcpb.mjs(update the npm script if you do). - npm scripts (
package.json): renamebuild:dxt→build:mcpbpointing at the script. Only keep abuild:dxtalias if something external depends on the old name (grep first); otherwise replace it cleanly — no compatibility cruft. Check theversionscript too (it stagesdxt/manifest.json). - Reference sweep — change user-facing
.dxt→.mcpbin:docs/guide/{install,troubleshooting,glossary}.md+ theirdocs/pt/mirrors,docs/DEPLOYMENT.md,docs/reference/cli.md,scripts/setup.mjs,README.md. Also grep.github/for any release workflow that builds or uploadstdmcp.dxt/ runsbuild:dxt. - Release-asset URLs. Links to
releases/latest/download/tdmcp.dxtpoint at a published asset. After this change the next release shipstdmcp.mcpb; update those links to.mcpband record that a new release must be cut so the asset exists (the current v0.3.0 asset is still.dxt). Note this for the human in migration notes.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 70 lines · 102 tokens per session scan A 1f075d5b9edb
mcpb-bundle is a skill published in the GitHub repository Pantani/tdmcp (39 stars, last pushed 23d ago), licensed MIT. It adds 102 tokens to every session and 1,085 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
popx-touchdesigner
Local POPX knowledge base and workflow for TouchDesigner. Use when the user mentions POPX, popsextension, POPX examples, POPX operators, or wants to build, inspect, explain, debug, or modify POPX-based setups in TouchDesigner using the bundled POPX reference corpus and live example loader when available.
tdpilot-core
Core patching discipline for TDPilot v2.4.1 — the AI assistant inside TouchDesigner. Use for all work through the td MCP tools: routing intent, inspecting live state, making safe edits, validating results, and recalling or learning local techniques.
tdpilot-production
Production-grade TouchDesigner MCP workflow for TDPilot v2.4.1 (114 tools): show-safe routing, bounded inspection, staged transactions, rollback, performance checks, preservation assertions, and evidence-based handoff.
data-charts-tako
Search and visualize the world's data - get charts, insights, and embeddable knowledge cards for finance, economics, demographics, sports, and more.
monorepo-management
Master monorepo management with Turborepo, Nx, and pnpm workspaces to build efficient, scalable multi-package repositories with optimized builds and dependency management. Use when setting up monorepos, optimizing builds, or managing shared dependencies.
browse-and-evaluate
Use when exploring the ai-agent-skills catalog to find, compare, and evaluate skills before installing. Always use --fields to limit output size and --dry-run before committing to an install.