Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add taurgis/sfcc-dev-mcp --skill sfcc-sfra-scssgit clone --depth 1 https://github.com/taurgis/sfcc-dev-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/taurgis/sfcc-dev-mcp/sfcc-sfra-scss)<a href="https://agentmods.dev/skills/taurgis/sfcc-dev-mcp/sfcc-sfra-scss"><img src="https://agentmods.dev/badge/skills/taurgis/sfcc-dev-mcp/sfcc-sfra-scss/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/taurgis/sfcc-dev-mcp/sfcc-sfra-scss"><img src="https://agentmods.dev/badge/skills/taurgis/sfcc-dev-mcp/sfcc-sfra-scss.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Anti-Refusal · line 317 Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.Fix: Remove instructions that suppress warnings, disclaimers, or ethical commentary. Let the agent surface safety-relevant caveats to the user.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00044 | $0.04699 |
| Opus 5 | $0.00022 | $0.02350 |
| Sonnet 5 | $0.00009 | $0.00940 |
| Haiku 4.5 | $0.00004 | $0.00470 |
Grade A, and why
sfcc-sfra-scss scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 394 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SFRA SCSS Best Practices (AI-Agent Optimized)
Purpose: Provide a concise, implementation‑ready reference for styling and theming Salesforce B2C Commerce SFRA storefronts using SCSS. Optimized for automated reasoning, safe overrides, upgrade resilience, and performant output.
1. Core Principles (Never Skip)
| Principle | Rule | Why It Exists | Action Pattern |
|---|---|---|---|
| Cartridge Overlay | Never edit app_storefront_base |
Preserve upgrade path | Create mirror path in custom cartridge + import base first |
| Import First, Then Override | Always @import '~base/...'; at top |
Keeps base layout + utilities | File header snippet template |
| Single Source of Truth | Centralize tokens in abstracts/_variables.scss |
Global theming + diffable changes | Import base → redefine only changed vars |
| Shallow Specificity | Max selector depth 2–3 | Predictable cascade | Use BEM instead of nested HTML chains |
| Mobile‑First | Base = smallest viewport | Less override churn | Add enhancements with min-width media mixin |
| Immutable Generated CSS | Never hand edit /static/default/css |
Prevent drift | Recompile via build scripts only |
| Deterministic Build | Same inputs ⇒ same CSS | Debug + CI parity | Lock dependency versions |
Red flag triggers for re‑evaluation: deep nesting (>3), repeated hardcoded colors, !important, duplicated breakpoint literals, editing compiled CSS, or missing initial @import.
AI Guardrail (fast reject): If asked to "change base SCSS" directly, respond with an override strategy instead of editing base source.
2. Minimal Override Workflow (Algorithm)
- Inspect element in browser → capture compiled CSS filename (e.g.
product/detail.css) & selector(s). - Locate source in base:
app_storefront_base/cartridge/client/default/scss/<path>.scss. - Recreate identical relative path in custom cartridge under
cartridge/client/default/scss/. - Add header:
@import '~base/<path>';(must be line 1; no preceding BOM/comment). - Append scoped overrides (BEM, tokens, mixins only—no raw hex unless introducing new token).
- Run
npm run compile:scss(or project alias) → deploy → verify cascade diff. - If change is global (color, spacing, radius) prefer variable override in
_variables.scssbefore component override.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 394 lines · 44 tokens per session scan A 66582a974360
sfcc-sfra-scss is a skill published in the GitHub repository taurgis/sfcc-dev-mcp (28 stars, last pushed 5d ago), licensed MIT. It adds 44 tokens to every session and 4,699 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
shopify-theme-optimization
Theme speed and UX optimization — Core Web Vitals, Liquid code, image loading, mobile responsiveness.
shopify
Expert Shopify theme development guidelines for Liquid, Online Store 2.0, CSS, JavaScript, and UX best practices.
shopify-theme-development-guidelines
Expert Shopify theme development with Liquid, Online Store 2.0, and performance best practices.
wc-product-attribute-swatches
Build or audit WooCommerce product attribute swatch integrations around the experimental wc-visual attribute type. Covers feature gating, global pa attribute taxonomies, the WooCommerce 11 slug byte limit, color/image term meta, visual admin search results, Store API experimentalvisual / experimentalVisual, classic…
evo-nextjs-visual-stability
Fix visual stability issues (CLS, FOUC, FOIT) in Next.js e-commerce apps. Addresses theme flicker, font loading, image dimensions, and async content placeholders.
shadcn-sveltekit-design
Use when building, redesigning, beautifying, or refactoring SvelteKit pages and reusable components with shadcn-svelte, Bits UI, or the shadcn-svelte MCP. Trigger on landing pages, dashboards, marketing sites, app shells, forms, navbars, tables, dialogs, responsive layouts, theming, icon selection, and requests to…