Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add smithdak/claude-marketplace --skill xm-cloudgit clone --depth 1 https://github.com/smithdak/claude-marketplaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/smithdak/claude-marketplace/xm-cloud)<a href="https://agentmods.dev/skills/smithdak/claude-marketplace/xm-cloud"><img src="https://agentmods.dev/badge/skills/smithdak/claude-marketplace/xm-cloud/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/smithdak/claude-marketplace/xm-cloud"><img src="https://agentmods.dev/badge/skills/smithdak/claude-marketplace/xm-cloud.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00023 | $0.03596 |
| Opus 5 | $0.00012 | $0.01798 |
| Sonnet 5 | $0.00005 | $0.00719 |
| Haiku 4.5 | $0.00002 | $0.00360 |
Grade A, and why
xm-cloud scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 611 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Bundled Skills
This plugin includes the following additional skills for comprehensive development context:
| Skill | Purpose |
|---|---|
frontend-modern |
React/Next.js component patterns, TypeScript, modern CSS |
fullstack-modern |
GraphQL integration, SSR/SSG patterns, API routes |
These skills are automatically included when you install the XM Cloud Analyzer plugin.
XM Cloud Development Patterns
Architecture Overview
┌─────────────────────────────────────────────────────────────┐
│ XM Cloud │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ Content │───▶│ Experience │───▶│ Edge │ │
│ │ Management │ │ Edge │ │ CDN │ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
└─────────────────────────────────────────────────────────────┘
│
▼ GraphQL
┌─────────────────────────────────────────────────────────────┐
│ Rendering Host │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ Next.js │───▶│ SSG/ │───▶│ Vercel/ │ │
│ │ App │ │ ISR/SSR │ │ Netlify │ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
└─────────────────────────────────────────────────────────────┘
Project Structure
src/
├── rendering/
│ ├── src/
│ │ ├── components/ # JSS components
│ │ │ ├── Hero/
│ │ │ │ ├── Hero.tsx
│ │ │ │ └── Hero.module.css
│ │ │ └── Navigation/
│ │ ├── lib/ # Utilities
│ │ │ ├── graphql/
│ │ │ ├── helpers/
│ │ │ └── component-props.ts
│ │ ├── graphql/ # GraphQL queries
│ │ │ ├── queries/
│ │ │ └── fragments/
│ │ ├── hooks/ # Custom React hooks
│ │ └── types/ # TypeScript definitions
│ ├── package.json
│ └── next.config.js
└── xmcloud.build.json
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 611 lines · 23 tokens per session scan A f041a8f9d173
xm-cloud is a skill published in the GitHub repository smithdak/claude-marketplace (3 stars, last pushed 7mo ago), licensed MIT. It adds 23 tokens to every session and 3,596 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
copilotkit-upgrade
Use when migrating a CopilotKit v1 application to v2 -- updating package imports, replacing deprecated hooks and components, switching from GraphQL runtime to AG-UI protocol runtime, and resolving breaking API changes.
nextjs-app-router
Full end-to-end tRPC setup for Next.js App Router. Covers route handler with fetchRequestHandler (GET + POST exports), TRPCProvider with QueryClientProvider, createTRPCOptionsProxy for RSC prefetching, HydrateClient/HydrationBoundary for hydration, useSuspenseQuery for Suspense, and server-side callers.
nextjs-pages-router
Set up tRPC in Next.js Pages Router with createNextApiHandler, createTRPCNext, withTRPC HOC, SSR via ssr option and ssrPrepass, SSG via createServerSideHelpers with getStaticProps, and server-side helpers for getServerSideProps prefetching.
with-tanstack-query
Compose Angular Query with signal-owned Table filtering, sorting, and pagination state using reactive query options, manual row-model boundaries, direct query data, server counts, and valid injection context.
langbot-dev
Develop, build, and debug the LangBot core backend and web frontend. Use when working inside the LangBot repository — backend (Python/Quart, src/langbot/pkg), the Vite/React web UI, HTTP API controllers/services, Alembic migrations, or the MCP server. Covers the dev environment (uv, pnpm), repo layout, the API auth…
trigger-realtime-and-frontend
Trigger.dev client/frontend surface: subscribe to runs in realtime (runs.subscribeToRun and the @trigger.dev/react-hooks hook useRealtimeRun), consume metadata and AI/text streams in React (useRealtimeStream), trigger tasks from the browser (useTaskTrigger, useRealtimeTaskTrigger), and mint scoped frontend credentials…