Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add pproenca/dot-skills --skill opinionated-nextjs-patternsgit clone --depth 1 https://github.com/pproenca/dot-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pproenca/dot-skills/opinionated-nextjs-patterns)<a href="https://agentmods.dev/skills/pproenca/dot-skills/opinionated-nextjs-patterns"><img src="https://agentmods.dev/badge/skills/pproenca/dot-skills/opinionated-nextjs-patterns/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/pproenca/dot-skills/opinionated-nextjs-patterns"><img src="https://agentmods.dev/badge/skills/pproenca/dot-skills/opinionated-nextjs-patterns.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00201 | $0.02850 |
| Opus 5 | $0.00101 | $0.01425 |
| Sonnet 5 | $0.00040 | $0.00570 |
| Haiku 4.5 | $0.00020 | $0.00285 |
Grade A, and why
opinionated-nextjs-patterns scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 132 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Opinionated Next.js 16 Patterns
Implementation-pattern reference for Next.js 16 (App Router) codebases that want a single, opinionated architecture. Contains 50 rules across 8 categories, prioritised by execution-lifecycle cascade impact — authorization and (optional) tenant modeling first, then the request boundary, server fetching, mutations, client boundaries, architecture, and UI conventions.
The rules are backend-agnostic in principle but use Supabase as the concrete example. Each rule teaches the transferable idea (e.g. "authorize at the data layer", "read through a typed repository"); where the backend genuinely matters, a *Transferable:* note explains the pattern for other stores (Drizzle, Prisma). The structure is a Turbo monorepo with @app/* packages you own — built on canonical libraries (next-safe-action, @supabase/ssr, @tanstack/react-query, react-hook-form + zod, shadcn/ui, next-intl, pino), not a vendored starter kit.
When to Apply
Reach for these rules when:
- Writing new code — pages, layouts, server actions, route handlers,
proxy.ts, feature packages, client components, hooks, the data-access package, SQL/migrations, forms. - Reviewing a PR — authorization slips (privileged client without a guard, missing
'server-only'), waterfalls (sequential awaits, client-fetching server data), drift (hand-edited generated types, deep package imports, hardcoded i18n strings). - Refactoring — moving code between
apps/webandpackages/*, splitting actions and services, lifting'use client'boundaries, replacing raw queries with a typed data-access factory, swapping a backend behind the data-access package. - Designing a feature — choosing the right client (request-scoped vs privileged vs browser), deciding action vs route handler, planning the form/server-action contract, scoping a tenant (if multi-tenant).
- Onboarding — understanding why the codebase looks the way it does, with concrete, transferable examples.
What ships with it
54 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- AGENTS.md 13 KB
- assets/templates/_template.md 4.5 KB
- metadata.json 1.8 KB
- references/_sections.md 3.9 KB
- references/arch-app-vs-packages-boundary.md 4.5 KB
- references/arch-config-driven-navigation.md 4.9 KB
- references/arch-data-access-adapter.md 2.7 KB
- references/arch-feature-package-layout.md 4.6 KB
- references/arch-import-via-package-exports.md 4.1 KB
- references/arch-policy-engine-for-business-rules.md 8.2 KB
- references/arch-provider-gateway-pattern.md 5.0 KB
- references/auth-gate-admin-client.md 3.8 KB
- references/auth-mfa-in-middleware.md 3.3 KB
- references/auth-server-only-imports.md 2.7 KB
- references/auth-trust-rls-no-duplicate-checks.md 3.2 KB
- references/auth-use-require-user.md 3.9 KB
- references/auth-use-sql-policy-helpers.md 3.3 KB
- references/auth-use-standard-server-client.md 3.0 KB
- references/client-pass-server-data-as-props.md 4.5 KB
- references/client-realtime-cleanup-subscription.md 5.1 KB
- references/client-stable-query-keys.md 4.5 KB
- references/client-use-action-hook.md 4.9 KB
- references/client-use-client-at-leaves.md 4.6 KB
- references/client-use-supabase-with-react-query.md 6.0 KB
- references/mutate-enhance-route-handler.md 6.2 KB
- references/mutate-revalidate-path-after-write.md 4.3 KB
- references/mutate-thin-action-service-holds-logic.md 5.6 KB
- references/mutate-use-getlogger-not-console.md 5.0 KB
- references/mutate-use-safe-action-clients.md 4.5 KB
- references/mutate-webhook-verify-signature.md 5.2 KB
- references/mutate-zod-schema-separate-file.md 4.8 KB
- references/proxy-redirect-auth-at-boundary.md 4.0 KB
- references/proxy-secure-headers-flagged.md 3.2 KB
- references/proxy-set-correlation-id.md 3.3 KB
- references/proxy-single-pipeline.md 3.3 KB
- references/proxy-url-pattern-matching.md 3.2 KB
- references/server-cache-workspace-loaders.md 4.4 KB
- references/server-fetch-in-server-components.md 4.4 KB
- references/server-promise-all-parallel-loads.md 4.0 KB
- references/server-redirect-on-missing-workspace.md 4.0 KB
- references/server-services-receive-client.md 4.6 KB
- references/server-use-feature-api-factories.md 4.5 KB
- references/server-use-tables-generic-for-types.md 3.9 KB
- references/tenant-account-id-on-product-tables.md 4.0 KB
- references/tenant-accounts-as-tenant-root.md 3.8 KB
- references/tenant-never-edit-generated-types.md 4.0 KB
- references/tenant-slug-in-team-urls.md 3.4 KB
- references/tenant-storage-paths-include-account-id.md 4.4 KB
- references/ui-base-ui-render-not-aschild.md 3.8 KB
- references/ui-form-message-per-field.md 3.8 KB
- references/ui-kit-ui-package-imports.md 4.1 KB
- references/ui-rhf-zod-no-generics.md 3.6 KB
- references/ui-semantic-tailwind-tokens.md 4.2 KB
- references/ui-trans-for-display-text.md 4.9 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 132 lines · 201 tokens per session scan A 5f3eead96e1e
opinionated-nextjs-patterns is a skill published in the GitHub repository pproenca/dot-skills (205 stars, last pushed 24d ago), licensed MIT. It adds 201 tokens to every session and 2,850 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
copilotkit-upgrade
Use when migrating a CopilotKit v1 application to v2 -- updating package imports, replacing deprecated hooks and components, switching from GraphQL runtime to AG-UI protocol runtime, and resolving breaking API changes.
nextjs-app-router
Full end-to-end tRPC setup for Next.js App Router. Covers route handler with fetchRequestHandler (GET + POST exports), TRPCProvider with QueryClientProvider, createTRPCOptionsProxy for RSC prefetching, HydrateClient/HydrationBoundary for hydration, useSuspenseQuery for Suspense, and server-side callers.
nextjs-pages-router
Set up tRPC in Next.js Pages Router with createNextApiHandler, createTRPCNext, withTRPC HOC, SSR via ssr option and ssrPrepass, SSG via createServerSideHelpers with getStaticProps, and server-side helpers for getServerSideProps prefetching.
langbot-dev
Develop, build, and debug the LangBot core backend and web frontend. Use when working inside the LangBot repository — backend (Python/Quart, src/langbot/pkg), the Vite/React web UI, HTTP API controllers/services, Alembic migrations, or the MCP server. Covers the dev environment (uv, pnpm), repo layout, the API auth…
trigger-realtime-and-frontend
Trigger.dev client/frontend surface: subscribe to runs in realtime (runs.subscribeToRun and the @trigger.dev/react-hooks hook useRealtimeRun), consume metadata and AI/text streams in React (useRealtimeStream), trigger tasks from the browser (useTaskTrigger, useRealtimeTaskTrigger), and mint scoped frontend credentials…
sanity-live-cache-components
Integrates Sanity Live with Next.js Cache Components in next-sanity v13+ apps. Sets up sanityFetch, a shared cachedSanity 'use cache' boundary, , Visual Editing, Presentation Tool, draft mode handling, and the three-layer (Page/Dynamic/Cached) component pattern with explicit perspective/stega prop-drilling. Sequences…