Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/tanstack/ai/gap-analysisnpx skills add TanStack/ai --skill gap-analysisgit clone --depth 1 https://github.com/TanStack/aiWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00065 | $0.01883 |
| Opus 5 | $0.00032 | $0.00941 |
| Sonnet 5 | $0.00013 | $0.00377 |
| Haiku 4.5 | $0.00006 | $0.00188 |
Grade A, and why
gap-analysis scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 142 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Gap Analysis — TanStack AI adapter audit
You are auditing TanStack AI's provider adapters against each provider's
upstream documentation. This is a maintainer tool. Your only output is a
markdown report under .agent/gap-analysis/. Do not edit source files.
Invocation
| Args | Scope |
|---|---|
<provider> (e.g. openai) |
One provider — all audit dimensions. |
feature <feature> (e.g. tts) |
One feature row of the matrix across all providers. |
models |
New-model diff for every provider. |
activities |
Activity-coverage diff: which of the 7 core activity |
| kinds each provider ships an adapter for, vs. what | |
| upstream supports. (Dimension 6 only, all providers.) | |
--all |
Full sweep (fan out subagents, one per provider). |
| (none) | Ask the user which scope via AskUserQuestion. |
Workflow
- Parse scope. If missing, AskUserQuestion with the four options above.
- Load the truth files, then read the per-scope inputs you need:
- Matrix:
testing/e2e/src/lib/feature-support.ts - Types:
testing/e2e/src/lib/types.ts(Provider + Feature unions, ALL_PROVIDERS, ALL_FEATURES) - Adapter index:
packages/ai-<provider>/src/index.ts - Model meta:
packages/ai-<provider>/src/model-meta.ts - Core types:
packages/ai/src/types.ts(Modality, ContentPart, ToolCall)
- Matrix:
- Research upstream. Use WebFetch against the curated URLs in
references/provider-doc-urls.md. When a
doc page has moved, fall back to WebSearch. For SDK API surface details
use the
context7MCP server (mcp__plugin_context7_context7__resolve-library-idthenmcp__plugin_context7_context7__query-docs). - Walk the audit dimensions in references/audit-checklist.md:
- New models
- Cross-adapter feature parity
- Untracked features
- Capability-flag drift
- Telemetry / observability parity (usage tokens, cache/reasoning counts, request ids, logging asymmetry)
- Activity coverage (which of the 7 core activity kinds each provider
ships an adapter for vs. what upstream supports) — this is the only
dimension for the
activitiesscope; it's also rolled into--all.
- Fan out for
--all: launch oneExploresubagent per provider, max 3 in parallel. Each subagent returns the multi-dimension findings for its provider; you synthesise into the combined report. Theactivitiesscope does not fan out — derive the provider×activity matrix centrally from the adapter files (see dimension 6), since it's a fast mechanical diff. - Write the report to
.agent/gap-analysis/YYYY-MM-DD-<scope>.mdusing references/report-template.md. Date is today's ISO date.<scope>isopenai/feature-tts/models/activities/all. - Print the report path and a 5-line summary to the user.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 142 lines · 65 tokens per session scan A c3f67ecfff47
gap-analysis is a skill published in the GitHub repository TanStack/ai (3,045 stars, last pushed 2d ago), licensed MIT. It adds 65 tokens to every session and 1,883 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
keybindings-help
Use when the user wants to customize keyboard shortcuts, rebind keys, add chord bindings, or modify /.claude/keybindings.json. Examples: "rebind ctrl+s", "add a chord shortcut", "change the submit key", "customize keybindings".
options
Present multiple design options as a vertical stack of anchored turns.
tmux
Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output.
summarize
Summarize or extract text/transcripts from URLs, podcasts, and local files (great fallback for “transcribe this YouTube/video”).
github
Interact with GitHub using the gh CLI. Use gh issue, gh pr, gh run, and gh api for issues, PRs, CI runs, and advanced queries.
workflow-authoring
Reference for writing a Workflow tool script (script API and gotchas, resume, quality patterns, worked examples). Load before authoring a script for a workflow the user already opted into; it does not itself authorize running one.