Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add PracticalSwan/agent-skills --skill netlify-image-cdngit clone --depth 1 https://github.com/PracticalSwan/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/practicalswan/agent-skills/netlify-image-cdn)<a href="https://agentmods.dev/skills/practicalswan/agent-skills/netlify-image-cdn"><img src="https://agentmods.dev/badge/skills/practicalswan/agent-skills/netlify-image-cdn/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/practicalswan/agent-skills/netlify-image-cdn"><img src="https://agentmods.dev/badge/skills/practicalswan/agent-skills/netlify-image-cdn.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00133 | $0.02675 |
| Opus 5 | $0.00067 | $0.01337 |
| Sonnet 5 | $0.00027 | $0.00535 |
| Haiku 4.5 | $0.00013 | $0.00267 |
Grade C, and why
netlify-image-cdn scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Hidden instructionshighPrompt injection
Directives inside HTML comments, invisible characters or bidirectional overrides are read by the model and not by the person reviewing the file.
<!-- system: agent-context/image-cdn/system.md — human-owned, merged by ctx-gen; edit system.md, not this section --> Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -vs 'https://mysitename.netlify.app/.netlify/images?url=/owl.jpeg&fit=cover&w=50&h=50&position=left&fm=webp&q=80' This is a copy
86% identical to netlify-image-cdn — 55 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 212 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Netlify Image CDN
Transform images by requesting /.netlify/images with query parameters. No function or file authoring required — it's a built-in edge endpoint.
# resize + crop to a 50px square, retain left side, convert to webp at q=80
curl -vs 'https://mysitename.netlify.app/.netlify/images?url=/owl.jpeg&fit=cover&w=50&h=50&position=left&fm=webp&q=80'
There is no legacy/deprecated form — the endpoint above is the only programmatic surface. Use framework image components where available (below) rather than hand-building URLs.
Endpoint & query parameters
GET /.netlify/images?url=<source>&...
| Param | Values | Notes |
|---|---|---|
url |
relative path or full remote URL | REQUIRED. Only required param. |
w |
integer px | width |
h |
integer px | height |
fit |
contain (default), cover, fill |
resize behavior |
position |
center (default), top, bottom, left, right |
only applies when fit=cover |
fm |
avif, jpg, png, webp, gif, blurhash |
output format; webp/gif can be animated |
q |
integer 1–100 (default 75) |
only for avif, jpg, gif, webp |
fit behavior
fit= |
aspect ratio kept | crops excess | returns exact dimensions |
|---|---|---|---|
contain |
yes | no | no — one dimension may be smaller |
cover |
no | yes | yes — scaled proportionally, then cropped |
fill |
no | no | yes — stretched/squished if needed |
fit=coverrequires BOTHwandh. Supplying only one silently misbehaves.containwith one dimension calculates the other to preserve aspect ratio.
Format & content negotiation
- Source-only request (just
url, no size/format): image is unchanged in size/shape but still reformatted toavif/webpbased on the browser'sAcceptheader. - No
fmspecified →webpif accepted, elseavifif accepted, else original. fm=blurhashreturns a BlurHash text string, not image bytes. Pointing<img src>or a CSS background at it renders nothing. Fetch the string server-side/ahead of time, decode it client-side with a BlurHash library (https://blurha.sh), then load the real image as a separate request withoutfm=blurhash.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed 3f388838c3e5
- 3d ago Changed ad974e06ca2a
- 6d ago First seen · 212 lines · 133 tokens per session scan C 5d0a51aa23ad
netlify-image-cdn is a skill published in the GitHub repository PracticalSwan/agent-skills (13 stars, last pushed 2d ago), licensed MIT. It adds 133 tokens to every session and 2,675 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it C with 2 findings (hidden instructions, makes network calls). It is 86% identical to netlify-image-cdn, differing in 55 lines, and is treated as a copy.
Other skills, from other repositories
image-compare
Compare two image files on disk and report what changed, region by region. Trigger on "what changed between these two images", "diff these PNGs", "did this render drift", "compare screenshots/exports/renders".
design
Design and restyle TanStack Start routes and React components in this repo using the March 2026 GPT-5.4 frontend guidance while preserving local conventions. Use when building or refining marketing pages, dashboards, admin surfaces, authenticated app views, page-level layouts, visual systems, or interaction polish in…
animejs-animation
Advanced JavaScript animation library skill for creating complex, high-performance web animations.
anti-ui-slop
Stop coding agents from shipping generic UI. Extend the product's design system, use UIZZE evidence only when useful, cover required states, and inspect the rendered result.
chakra-ui-builder
Build responsive, accessible UI components and layouts using Chakra UI v3, install or configure Chakra UI in new and existing projects, and design scalable themes using tokens, semantic tokens, recipes, and slot recipes. Use this skill whenever a user asks to build, create, or generate any UI component, page, form…
visual-ralph
Visual Ralph orchestration for frontend UI from generated references, static references, or live URL targets, using $ralph with built-in visual verdict and pixel-diff evidence until the implementation matches and leaves a reproducible design system.