Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Pantani/tdmcp --skill tdmcp-bridge-endpointgit clone --depth 1 https://github.com/Pantani/tdmcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pantani/tdmcp/tdmcp-bridge-endpoint)<a href="https://agentmods.dev/skills/pantani/tdmcp/tdmcp-bridge-endpoint"><img src="https://agentmods.dev/badge/skills/pantani/tdmcp/tdmcp-bridge-endpoint/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/pantani/tdmcp/tdmcp-bridge-endpoint"><img src="https://agentmods.dev/badge/skills/pantani/tdmcp/tdmcp-bridge-endpoint.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00177 | $0.01488 |
| Opus 5 | $0.00088 | $0.00744 |
| Sonnet 5 | $0.00035 | $0.00298 |
| Haiku 4.5 | $0.00018 | $0.00149 |
Grade A, and why
tdmcp-bridge-endpoint scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
2 near-identical copies found in the catalogue:
- tdmcp-bridge-endpoint — 100% identical, 0 lines differ
- tdmcp-bridge-endpoint — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 102 lines — stays where its author put it; the contents beside it link to each section on GitHub.
tdmcp-bridge-endpoint — the bridge vertical slice
A bridge feature is correct only when four layers agree on one shape: the Python route, the TS client method, the Zod validator, and the tool that consumes it. This skill is that contract. Build the slice top-to-bottom, keep an exec fallback so it ships safely before every bridge in the wild updates, and prove it all offline.
Run bridge slices one at a time — they share
touchDesignerClient.ts,validators.ts, and the bridge route registry. Two in parallel is merge hell.
Why exec→REST at all
The bridge runs arbitrary Python on /api/exec. A security-conscious VJ runs
TDMCP_BRIDGE_ALLOW_EXEC=0 on a venue network — and ~69 tools silently die.
Promoting a well-defined op (connect, param-mode read/write, DAT text, node
flags, logs) to its own REST route makes it survive that hardened config. You are
promoting proven logic, not inventing it — start from the Python the tool
already sends through /api/exec.
The slice, in order
1. Bridge (Python, td/)
- Add a handler module (or extend the right existing one) and register the
route. Find how routes are registered (the request dispatcher in
td/) and follow that exact pattern — don't invent a second mechanism. - Keep every TD-global (
op,app,project,ui) inside the handler function so the module imports cleanly outside TD (the tests rely on this). - Return a JSON report with a stable shape: a top-level
ok/error and the data. Mirror the envelope the existing endpoints return soparsePythonReport/the validators stay uniform. - Honor
TDMCP_BRIDGE_TOKEN(bearer auth) and theALLOW_EXECgate exactly as sibling routes do — a new route must not become an auth bypass. python3 -m py_compile td/**/<changed>.pyon every changed file.
2. Client method (src/td-client/touchDesignerClient.ts)
- Add one typed method that calls the new route (GET/POST/PATCH/PUT as fits).
- Map failures to the existing typed errors:
TdApiError(4xx/5xx with a body),TdConnectionError(refused/DNS),TdTimeoutError. Never let a raw fetch error escape. - Exec fallback: if the endpoint returns 404 (older bridge without the route),
fall back to the previous
/api/execPython path. This is what lets the promotion ship before the bridge is reinstalled everywhere. Make the fallback a private helper so the test can force both paths.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 102 lines · 177 tokens per session scan A f36c07665324
tdmcp-bridge-endpoint is a skill published in the GitHub repository Pantani/tdmcp (39 stars, last pushed 26d ago), licensed MIT. It adds 177 tokens to every session and 1,488 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
cqrs-implementation
Implement Command Query Responsibility Segregation for scalable architectures. Use when separating read and write models, optimizing query performance, or building event-sourced systems.
microservices-patterns
Design microservices architectures with service boundaries, event-driven communication, and resilience patterns. Use when building distributed systems, decomposing monoliths, or implementing microservices.
diagnose-backend-bug
Diagnose a bounded backend or multi-service failure from GitHub Issues, Jira, Aone, user-provided exports, logs, traces, responses, stack traces, or job records. Use when a service, API, RPC, worker, queue, CLI, or scheduled job bug needs correlation through the project's existing observability route before repair; do…
durable-objects
Build, debug, or review Cloudflare Durable Objects code for persistent state and coordination.
api-doc-generator
Generate API documentation from source code, supporting REST APIs, GraphQL, and various documentation formats.
firebase-cloud-functions
Use when calling callable functions (httpsCallable), passing data to server-side logic, handling function errors/timeouts, configuring regions, or testing with the Emulator Suite.