Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ryne2010/harness-engineering-audit --skill design-token-component-contractgit clone --depth 1 https://github.com/ryne2010/harness-engineering-auditWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ryne2010/harness-engineering-audit/design-token-component-contract)<a href="https://agentmods.dev/skills/ryne2010/harness-engineering-audit/design-token-component-contract"><img src="https://agentmods.dev/badge/skills/ryne2010/harness-engineering-audit/design-token-component-contract/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ryne2010/harness-engineering-audit/design-token-component-contract"><img src="https://agentmods.dev/badge/skills/ryne2010/harness-engineering-audit/design-token-component-contract.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00033 | $0.00223 |
| Opus 5 | $0.00016 | $0.00112 |
| Sonnet 5 | $0.00007 | $0.00045 |
| Haiku 4.5 | $0.00003 | $0.00022 |
Grade A, and why
design-token-component-contract scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
design token component contract
Follow the repository source-of-truth docs. Do not invent a second design system when one already exists. Do not implement app features until tokens/components/contracts are clear enough for validation.
Workflow
- Read the visual product spec pack, design-token pack, component contracts, and existing component library.
- Identify required semantic tokens for color, spacing, typography, radius, elevation, motion, and themes.
- Map visual target elements to existing components before proposing new primitives.
- Add or update component contracts for priority reusable components.
- Flag raw colors, ad hoc spacing, duplicated primitives, and one-off generated styles as harness gaps.
- Record token build/validation commands or mark them
not_runwith the missing command reason.
Evidence
Report token files, component contracts, story/workbench coverage, raw-style findings, and validation commands run or not run.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 22 lines · 33 tokens per session scan A 606c68446971
design-token-component-contract is a skill published in the GitHub repository ryne2010/harness-engineering-audit (5 stars, last pushed 5d ago), licensed MIT. It adds 33 tokens to every session and 223 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
fd
Frontend design mode for strong visual direction, UI polish, redesigns, landing pages, and production-grade interface work, including shadcn-based surfaces. Use when the user says /fd or explicitly asks for better design, styling, layout, visual quality, or UX polish.
web-design-reviewer
This skill enables visual inspection of websites running locally or remotely to identify and fix design issues. Triggers on requests like "review website design", "check the UI", "fix the layout", "find design problems". Detects issues with responsive design, accessibility, visual consistency, and layout breakage…
ui-web
Web UI - glassmorphism, Tailwind, dark mode, accessibility.
mulmoterminal-theme
Build a colour scheme of your own for MulmoTerminal — one that joins Midnight, Nord, Daylight and Solarized in Settings' theme picker and can then be pinned per project. Writes themes in /.mulmoterminal/config.json, the whole-app palette (panels, borders, accent, text), which has no UI for creating one — Settings only…
taste
Use when improving the visual taste, positioning, polish, trust, and conversion clarity of a website or product UI. Runs a category-first visual audit, applies a decisive design pass, and verifies the result with screenshots rather than subjective vibes.
ijfw-ui-spec
Use when the user says: 'ui spec', 'design contract', 'ui audit setup', 'lock the design', 'visual contract', 'ui review setup', or '/ijfw-ui-spec'. Produces UI-SPEC.md as the visual design contract before any frontend or visual-artifact build, and dispatches ijfw-ui-auditor as the final 6-pillar gate.