Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/pr-pm/prpm/creating-windsurf-packagesnpx skills add pr-pm/prpm --skill creating-windsurf-packagesgit clone --depth 1 https://github.com/pr-pm/prpmWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pr-pm/prpm/creating-windsurf-packages)<a href="https://agentmods.dev/skills/pr-pm/prpm/creating-windsurf-packages"><img src="https://agentmods.dev/badge/skills/pr-pm/prpm/creating-windsurf-packages.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00035 | $0.01657 |
| Opus 5 | $0.00017 | $0.00829 |
| Sonnet 5 | $0.00007 | $0.00331 |
| Haiku 4.5 | $0.00003 | $0.00166 |
Grade A, and why
creating-windsurf-packages scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 274 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Creating Windsurf Packages
Overview
Windsurf uses a single .windsurf/rules file containing plain markdown instructions with NO frontmatter.
CRITICAL CONSTRAINTS:
- No frontmatter - Pure markdown only
- 12,000 character limit - Hard limit enforced by Windsurf
- Single file - All rules in one
.windsurf/rulesfile
Quick Reference
| Aspect | Requirement |
|---|---|
| Format | Plain markdown |
| Frontmatter | None (forbidden) |
| Character limit | 12,000 max |
| File location | .windsurf/rules (single file) |
Creating Rules
Plain markdown with optional H1 title and organized sections:
# React Development Guidelines
Guidelines for building React applications in this project.
## Component Structure
- Use functional components with hooks
- Keep components under 200 lines
- Extract logic into custom hooks when appropriate
- Co-locate styles with components
## State Management
We use Zustand for global state:
- Create stores in `src/stores/`
- Use selectors to prevent unnecessary re-renders
- Keep stores focused on single concerns
\`\`\`typescript
// Good: Focused store
const useAuthStore = create((set) => ({
user: null,
login: (user) => set({ user }),
logout: () => set({ user: null }),
}));
\`\`\`
## Testing
- Write tests alongside components (`.test.tsx`)
- Use React Testing Library
- Test user behavior, not implementation details
- Aim for 80% coverage on new code
Character Budget Tips
To stay under 12,000 characters:
- Focus on project-specific patterns - AI already knows general best practices
- Use concise language - Every word counts
- Limit code examples - Only essential patterns
- Skip obvious practices - Don't repeat what AI knows
- Reference external docs - Link instead of repeating
Example: Project-Specific Context
# Project Architecture
## Tech Stack
- **Frontend**: React 18 + TypeScript + Vite
- **Styling**: Tailwind CSS
- **State**: Zustand
- **Routing**: React Router v6
- **API**: REST with axios
## Directory Structure
\`\`\`
src/
components/ # Reusable UI components
features/ # Feature-specific code
hooks/ # Custom React hooks
stores/ # Zustand stores
utils/ # Helper functions
types/ # TypeScript types
\`\`\`
## Coding Conventions
- Use PascalCase for components
- Use camelCase for functions/variables
- Use kebab-case for file names
- Export components as named exports
## API Integration
All API calls go through `src/api/client.ts`:
\`\`\`typescript
import { apiClient } from '@/api/client';
// Use the client
const users = await apiClient.get('/users');
\`\`\`
## Environment Variables
Access via `import.meta.env`:
- `VITE_API_URL` - Backend API URL
- `VITE_APP_ENV` - Environment (dev/staging/prod)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 274 lines · 35 tokens per session scan A 91c763b5f425
creating-windsurf-packages is a skill published in the GitHub repository pr-pm/prpm (120 stars, last pushed 2mo ago), licensed MIT. It adds 35 tokens to every session and 1,657 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
dependency-analysis
This rule automatically analyzes dependencies before they're installed to provide insights about maintenance frequency, security vulnerabilities, and popularity in the developer ecosystem.
biome
Biome JavaScript/TypeScript linter and formatter.
laravel
Laravel PHP framework best practices.
nextjs-react19
Next.js with React 19 App Router patterns.
android-new-project
Workflow for turning a fresh copy of this Android template into a new app — renaming the package/namespace/applicationId, branding (icons, splash, palette, fonts), Firebase setup, signing config, stripping unused sample screens, and verifying the foundation. Use when the user says they are starting a new app…
template-helpers
Catalog of the reusable building blocks shipped with this Android template — BaseActivity/BaseFragment, the helpers/ extension files (navigation, lifecycle, toast, snackbar, dialogs, images, permissions, theme, locale, settings intents, date, delay), common/ (Firebase, network, observers), and…