xm-cloud

xm-cloud is a skill for Claude Code from smithdak/claude-marketplace. It costs 23 tokens per session (3,596 once invoked), scanned A, original, MIT.

A development guide for Sitecore XM Cloud, a cloud service for managing website content, with Next.js, a React framework, used to display that content.

In plain words
What is it for?
Use it when working on XM Cloud content, Next.js rendering hosts, GraphQL connections, server-rendered pages, or statically generated pages.
Why use it?
It gives developers relevant patterns when building websites that connect Sitecore content to a Next.js application.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the xm-cloud plugin — 1 skill, 1 agent shipped together

Good fit Use it when working on XM Cloud content, Next.js rendering hosts, GraphQL connections, server-rendered pages, or statically generated pages.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/smithdak/claude-marketplace/xm-cloud
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add smithdak/claude-marketplace --skill xm-cloud
Clone the repo
git clone --depth 1 https://github.com/smithdak/claude-marketplace

Made for: Claude Code.

Or install xm-cloud, the plugin that ships this one along with the rest of its 1 skill, 1 agent.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for xm-cloud

README.md
[![agentmods](https://agentmods.dev/badge/skills/smithdak/claude-marketplace/xm-cloud/github.svg)](https://agentmods.dev/skills/smithdak/claude-marketplace/xm-cloud)
Your own site
<a href="https://agentmods.dev/skills/smithdak/claude-marketplace/xm-cloud"><img src="https://agentmods.dev/badge/skills/smithdak/claude-marketplace/xm-cloud/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for xm-cloud

Your own site · 80×15
<a href="https://agentmods.dev/skills/smithdak/claude-marketplace/xm-cloud"><img src="https://agentmods.dev/badge/skills/smithdak/claude-marketplace/xm-cloud.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 23 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,596 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00023 $0.03596
Opus 5 $0.00012 $0.01798
Sonnet 5 $0.00005 $0.00719
Haiku 4.5 $0.00002 $0.00360

Measured 10d ago against content hash f041a8f9d173, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

xm-cloud scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/xm-cloud-analyzer/skills/xm-cloud/SKILL.md · 611 lines

How it starts

The opening of the file, as written. The whole thing — 611 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Bundled Skills

This plugin includes the following additional skills for comprehensive development context:

Skill Purpose
frontend-modern React/Next.js component patterns, TypeScript, modern CSS
fullstack-modern GraphQL integration, SSR/SSG patterns, API routes

These skills are automatically included when you install the XM Cloud Analyzer plugin.

XM Cloud Development Patterns

Architecture Overview

┌─────────────────────────────────────────────────────────────┐
│                        XM Cloud                              │
│  ┌─────────────┐    ┌─────────────┐    ┌─────────────┐     │
│  │   Content   │───▶│  Experience │───▶│    Edge     │     │
│  │ Management  │    │    Edge     │    │    CDN      │     │
│  └─────────────┘    └─────────────┘    └─────────────┘     │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼ GraphQL
┌─────────────────────────────────────────────────────────────┐
│                    Rendering Host                            │
│  ┌─────────────┐    ┌─────────────┐    ┌─────────────┐     │
│  │   Next.js   │───▶│    SSG/     │───▶│   Vercel/   │     │
│  │    App      │    │   ISR/SSR   │    │   Netlify   │     │
│  └─────────────┘    └─────────────┘    └─────────────┘     │
└─────────────────────────────────────────────────────────────┘

Project Structure

src/
├── rendering/
│   ├── src/
│   │   ├── components/         # JSS components
│   │   │   ├── Hero/
│   │   │   │   ├── Hero.tsx
│   │   │   │   └── Hero.module.css
│   │   │   └── Navigation/
│   │   ├── lib/                # Utilities
│   │   │   ├── graphql/
│   │   │   ├── helpers/
│   │   │   └── component-props.ts
│   │   ├── graphql/            # GraphQL queries
│   │   │   ├── queries/
│   │   │   └── fragments/
│   │   ├── hooks/              # Custom React hooks
│   │   └── types/              # TypeScript definitions
│   ├── package.json
│   └── next.config.js
└── xmcloud.build.json

Read the full file on GitHub · 611 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 611 lines · 23 tokens per session scan A f041a8f9d173

Subscribe to this mod's changes

xm-cloud is a skill published in the GitHub repository smithdak/claude-marketplace (3 stars, last pushed 7mo ago), licensed MIT. It adds 23 tokens to every session and 3,596 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

copilotkit-upgrade

Use when migrating a CopilotKit v1 application to v2 -- updating package imports, replacing deprecated hooks and components, switching from GraphQL runtime to AG-UI protocol runtime, and resolving breaking API changes.

CopilotKit/CopilotKit · 48 tokens

nextjs-app-router

Full end-to-end tRPC setup for Next.js App Router. Covers route handler with fetchRequestHandler (GET + POST exports), TRPCProvider with QueryClientProvider, createTRPCOptionsProxy for RSC prefetching, HydrateClient/HydrationBoundary for hydration, useSuspenseQuery for Suspense, and server-side callers.

trpc/trpc · 74 tokens

nextjs-pages-router

Set up tRPC in Next.js Pages Router with createNextApiHandler, createTRPCNext, withTRPC HOC, SSR via ssr option and ssrPrepass, SSG via createServerSideHelpers with getStaticProps, and server-side helpers for getServerSideProps prefetching.

trpc/trpc · 67 tokens

with-tanstack-query

Compose Angular Query with signal-owned Table filtering, sorting, and pagination state using reactive query options, manual row-model boundaries, direct query data, server counts, and valid injection context.

TanStack/table · 42 tokens

langbot-dev

Develop, build, and debug the LangBot core backend and web frontend. Use when working inside the LangBot repository — backend (Python/Quart, src/langbot/pkg), the Vite/React web UI, HTTP API controllers/services, Alembic migrations, or the MCP server. Covers the dev environment (uv, pnpm), repo layout, the API auth…

langbot-app/LangBot · 136 tokens

trigger-realtime-and-frontend

Trigger.dev client/frontend surface: subscribe to runs in realtime (runs.subscribeToRun and the @trigger.dev/react-hooks hook useRealtimeRun), consume metadata and AI/text streams in React (useRealtimeStream), trigger tasks from the browser (useTaskTrigger, useRealtimeTaskTrigger), and mint scoped frontend credentials…

triggerdotdev/trigger.dev · 148 tokens