Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/vercel-labs/native/ts-servicesnpx skills add vercel-labs/native --skill ts-servicesgit clone --depth 1 https://github.com/vercel-labs/nativeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00103 | $0.02513 |
| Opus 5 | $0.00051 | $0.01256 |
| Sonnet 5 | $0.00021 | $0.00503 |
| Haiku 4.5 | $0.00010 | $0.00251 |
Grade A, and why
ts-services scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Runs shell commandslowCapability
Expected in a hook, worth knowing in a rule or an instructions file.
Use `src/services/**/*.ts` for imperative work that needs ordinary TypeScript beyond the deterministic core subset: `fs`, `path`, `process`, `os`, `child_process`, `fetch`, regexes, JSON, `Map`/`Set`, `Date`, and classes How it starts
The opening of the file, as written. The whole thing — 127 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Author TypeScript services behind the effect boundary
Use src/services/**/*.ts for imperative work that needs ordinary TypeScript beyond the deterministic core subset: fs, path, process, os, child_process, fetch, regexes, JSON, Map/Set, Date, and classes supported by the pinned scriptc static tier. Both classes compile with the exact scriptc version in packages/core/package.json; neither enables --dynamic or ships a JavaScript engine. The exact verdict for every surface the compiler currently projects — with each status and refusal code, plus the manifest's explicit coverage limits — is references/service-surface.md, generated from the pinned compiler's own manifest; consult it rather than guessing compiler capability.
The class line is hard:
src/core.tsand its imports outsidesrc/services/retain NS1001–NS1064 anddeterministic: true.- The core never imports a service file, even type-only (NS1065). It imports generated command constructors from
@native-sdk/services. - A service may import shared, subset-legal declarations from the core class. Put every boundary record, enum, or union there so one declaration is authoritative on both sides.
- A service may import compiler-supported Node built-ins and exact packages declared by app.zon. Undeclared bare imports teach NS1066.
Typed operation surface
Every directly exported, non-default named function is an operation named <module-basename>.<export>. It must be synchronous, have a body, take zero or one explicitly annotated request, and explicitly return a contract-encodable result. Boundary data may use booleans, numbers, integer-class numbers, bytes, optionals, readonly slices, and named records/enums/kind-unions. Functions and behavior-bearing classes do not cross.
// src/shared.ts — core-class file, imported by both classes
export type ParseRequest = {
readonly source: Uint8Array;
readonly caseSensitive: boolean;
};
export type ParseResult = {
readonly bytes: Uint8Array;
readonly matched: boolean;
};
// src/services/feeds.ts
import type { ParseRequest, ParseResult } from "../shared.ts";
export function parse(request: ParseRequest): ParseResult {
const text = new TextDecoder().decode(request.source);
const matched = request.caseSensitive ? /feed/.test(text) : /feed/i.test(text);
return { bytes: new TextEncoder().encode(JSON.stringify({ matched })), matched };
}
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 127 lines · 0 tokens per session scan A 8b0cc918dc8a
ts-services is a skill published in the GitHub repository vercel-labs/native (7,615 stars, last pushed 7d ago), licensed Apache-2.0. It adds 103 tokens to every session and 2,513 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
client-setup
Create a vanilla tRPC client with createTRPCClient (), configure link chain with httpBatchLink/httpLink, dynamic headers for auth, transformer on links (not client constructor). Infer types with inferRouterInputs and inferRouterOutputs. AbortController signal support. TRPCClientError typing.
custom-features
Author a TanStack Table v9 feature plugin across every FeatureMap and API installation surface: state, options, column definitions, table, column, row, cell, header, row-model functions/caches, defaults, prototypes, and table/row/column instance data lifecycles. Load for initTableInstanceData, resetTableInstanceData…
effect-and-errors
Composing Effect programs, domain errors, HttpError, repository error types, or error propagation at HTTP boundaries.
migrate-better-result-3
Migrate a TypeScript codebase from better-result 2.x to 3.0. Use when upgrading better-result across the TaggedError syntax, removed Result serialization helpers, recovery inference, matching, or retry APIs.
fast-typescript-check
Keep www-sacred's TypeScript fast to type-check and fast to run. Use when touching the ASCII/canvas animation components (the only real per-frame code here), tightening type-check wall-clock, or auditing a change for runtime or compiler regressions. Scoped to this repo — a React 19 / Next.js 16 component library plus…
typescript-magician
Designs complex generic types, refactors any types to strict alternatives, creates type guards and utility types, and resolves TypeScript compiler errors. Use when the user asks about TypeScript (TS) types, generics, type inference, type guards, removing any types, strict typing, type errors, infer, extends…