Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add surrealdb/agent-skills --skill surrealdb-jsgit clone --depth 1 https://github.com/surrealdb/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/surrealdb/agent-skills/surrealdb-js)<a href="https://agentmods.dev/skills/surrealdb/agent-skills/surrealdb-js"><img src="https://agentmods.dev/badge/skills/surrealdb/agent-skills/surrealdb-js/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/surrealdb/agent-skills/surrealdb-js"><img src="https://agentmods.dev/badge/skills/surrealdb/agent-skills/surrealdb-js.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00117 | $0.01545 |
| Opus 5 | $0.00059 | $0.00772 |
| Sonnet 5 | $0.00023 | $0.00309 |
| Haiku 4.5 | $0.00012 | $0.00154 |
Grade A, and why
surrealdb-js scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 172 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SurrealDB JavaScript SDK
The official SDK (surrealdb on npm) works in Node.js, Deno, Bun, and the
browser. It connects to a remote SurrealDB instance over WebSocket/HTTP, or runs
an embedded engine in-process. Target the latest stable surrealdb release;
install without pinning (npm i surrealdb) unless the user requires a specific
version.
Installation
npm i surrealdb
# or: pnpm i surrealdb / yarn add surrealdb / bun add surrealdb
Connect & select namespace/database
Always connect, then use a namespace + database, then authenticate. Close
the connection when finished.
import { Surreal } from "surrealdb";
const db = new Surreal();
await db.connect("ws://127.0.0.1:8000/rpc");
await db.use({ namespace: "test", database: "test" });
await db.signin({ username: "root", password: "root" });
// ... work ...
await db.close();
Run a local server with surreal start -u root -p root rocksdb:mydb (or
in-memory with surreal start -u root -p root). To run SurrealDB in-process
with no server, see references/embedded.md.
Authentication
// Root / namespace / database users
await db.signin({ username: "root", password: "root" });
await db.signin({ namespace: "test", username: "ns_user", password: "..." });
await db.signin({ namespace: "test", database: "test", username: "db_user", password: "..." });
// Record (scope) access — sign in / sign up against a DEFINE ACCESS method
const token = await db.signin({
namespace: "test",
database: "test",
access: "user", // name of the access method
variables: { email: "[email protected]", pass: "secret" },
});
await db.signup({
namespace: "test",
database: "test",
access: "user",
variables: { email: "[email protected]", pass: "secret" },
});
await db.authenticate(token); // re-auth with a stored JWT
await db.invalidate(); // log out the current session
const me = await db.info(); // info about the authenticated record user
CRUD
Pass a table as a string ("person") or a RecordId for a specific record.
See references/data-types.md for RecordId, Table,
Duration, Decimal, and other value classes.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 172 lines · 117 tokens per session scan A ed7c61b419b9
surrealdb-js is a skill published in the GitHub repository surrealdb/agent-skills (25 stars, last pushed 2mo ago), licensed MIT. It adds 117 tokens to every session and 1,545 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
psl-ast-layers
How to use the PSL syntax tree layers (green tree, red tree, strongly-typed AST classes) correctly. Use for any PSL-related work: PSL interpreters (contract-psl), helpers inside the psl-parser package, the language server, formatters, or anything else that consumes parse() output from @internal/psl-parser.
ast-visitor-pattern
Use the frozen-class/visitor pattern for discriminated unions that have multiple dispatch sites. Use when creating a new set of variants (commands, IR nodes, factory calls) that will be switched over in 2+ places, or when refactoring an existing union type that has grown multiple switch sites.
no-bare-casts
Writing as in TypeScript or TSX production code, modifying a file that contains a bare as cast, silencing a type error with a cast, encountering as unknown as, or reviewing a cast site.
bumping-biome
Bumps biome package versions (e.g. @biomejs/biome) using pnpm, aligns biome.jsonc files with the new version/s across the repository and runs biome-related checks. Use when required to update biome to a newer version - explicitly or implicitly (e.g. after running pnpm up, pnpm update, pnpm upgrade without specific…
dynamodb-toolbox-patterns
Provides TypeScript patterns for DynamoDB-Toolbox v2 including schema/table/entity modeling, .build() command workflow, query/scan access patterns, batch and transaction operations, and single-table design with computed keys. Use when implementing type-safe DynamoDB access layers with DynamoDB-Toolbox v2 in TypeScript…
azure-cosmos-ts
Data plane SDK for Azure Cosmos DB NoSQL API operations — CRUD on documents, queries, bulk operations.