project-match

project-match is a skill for Claude Code from Vibiz-ai/vibiz-claude-plugin. It costs 25 tokens per session (962 once invoked), scanned A, original, MIT.

A project-matching workflow that finds a local project's public brand website and matches it to an existing Vibiz, a visual brand context used by related tools. It checks common project files and links before asking for clarification.

In plain words
What is it for?
Use it before a Vibiz task that needs a target website, especially when the project's brand URL is not obvious or several possible Vibizes exist.
Why use it?
It prevents tools from being pointed at the wrong website or a code-hosting URL. This gives later Vibiz tasks the correct public identity for the project.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the vibiz plugin — 2 skills, 7 commands, 1 agent, 1 hook, 1 MCP server shipped together

Good fit Use it before a Vibiz task that needs a target website, especially when the project's brand URL is not obvious or several possible Vibizes exist.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/vibiz-ai/vibiz-claude-plugin/project-match
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add Vibiz-ai/vibiz-claude-plugin --skill project-match
Clone the repo
git clone --depth 1 https://github.com/Vibiz-ai/vibiz-claude-plugin

Made for: Claude Code.

Or install vibiz, the plugin that ships this one along with the rest of its 2 skills, 7 commands, 1 agent, 1 hook, 1 MCP server.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for project-match

README.md
[![agentmods](https://agentmods.dev/badge/skills/vibiz-ai/vibiz-claude-plugin/project-match/github.svg)](https://agentmods.dev/skills/vibiz-ai/vibiz-claude-plugin/project-match)
Your own site
<a href="https://agentmods.dev/skills/vibiz-ai/vibiz-claude-plugin/project-match"><img src="https://agentmods.dev/badge/skills/vibiz-ai/vibiz-claude-plugin/project-match/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for project-match

Your own site · 80×15
<a href="https://agentmods.dev/skills/vibiz-ai/vibiz-claude-plugin/project-match"><img src="https://agentmods.dev/badge/skills/vibiz-ai/vibiz-claude-plugin/project-match.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 25 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 962 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00025 $0.00962
Opus 5 $0.00013 $0.00481
Sonnet 5 $0.00005 $0.00192
Haiku 4.5 $0.00003 $0.00096

Measured 12d ago against content hash 29fad6d96b39, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

project-match scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/vibiz/skills/project-match/SKILL.md · 67 lines

How it starts

The opening of the file, as written. The whole thing — 67 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Project ⇄ Vibiz matching

Whenever the user asks for a Vibiz tool that needs a target.vibiz, you should match the current local project against their existing vibizes — and only ask them which one to use if matching is ambiguous. This skill describes how.

Step 1 — Detect the project's brand URL

Try in order, stop at the first one that yields a public, parseable URL:

  1. package.json — read the homepage field. (Skip repository — that's a git URL, not a brand URL.)
  2. pyproject.toml[project].urls.Homepage or [tool.poetry].homepage.
  3. Cargo.toml[package].homepage.
  4. README.md / README.mdx — first 100 lines, find the first link of the form https?://<host> that is NOT:
    • github.com / gitlab.com / bitbucket.org
    • npmjs.com / pypi.org / crates.io / rubygems.org
    • badge providers (shields.io, img.shields.io, badge.fury.io, flat.badgen.net)
    • docs hosts (readthedocs.io, gitbook.com, docs.rs)
    • any line starting with [![ (markdown badge image)
  5. git remotegit remote get-url origin. If it's a GitHub repo, do NOT use it as the brand URL; instead ask the user "what's the public website for this project?" (Enter to skip.)
  6. If everything fails — ask the user.

Refuse private/local URLs: localhost, 127.0.0.1, *.local, *.internal, *.test. Tell the user the brand kit needs a public website.

Step 2 — Normalize for matching

Both sides (the detected URL + each vibiz's websiteUrl) get the same treatment:

1. lowercase
2. strip leading 'http://' or 'https://'
3. strip leading 'www.'
4. strip trailing '/'
5. take the host + first path segment only (drop query strings, hashes, deep paths)

Examples:

  • https://www.Stripe.com/stripe.com
  • https://stripe.com/paymentsstripe.com (we keep just the host for top-level brand sites)
  • https://shop.example.comshop.example.com (subdomains DO matter — different brand)

Step 3 — Match against list_vibiz

Read the full file on GitHub · 67 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 67 lines · 25 tokens per session scan A 29fad6d96b39

Subscribe to this mod's changes

project-match is a skill published in the GitHub repository Vibiz-ai/vibiz-claude-plugin (7 stars, last pushed 4mo ago), licensed MIT. It adds 25 tokens to every session and 962 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

webgl-holographic-foil

A self-contained WebGL2 hero: thin-film interference over a crushed-foil surface whose palette shifts with the viewing angle; move the cursor to tilt the film.

nexu-io/open-design · 41 tokens

html-ppt-hermes-cyber-terminal

OpenDesign + BYOK: choosing and wiring your own model, hands-on — cost, quality, and the routing decision. Built as a decision-grade AI literacy deck for engineers, IT, applied-AI teams.

nexu-io/open-design · 53 tokens

html-ppt-taste-brutalist

16:9 HTML deck in tactical-telemetry / CRT-terminal taste. Deactivated-CRT charcoal slides, white-phosphor monospace, hazard-red accent, scanline overlay, ASCII syntax, density over decoration. Distilled from Leonxlnx/taste-skill brutalist-skill (Tactical Telemetry mode).

nexu-io/open-design · 78 tokens

visual-ralph

Visual Ralph orchestration for frontend UI from generated references, static references, or live URL targets, using $ultragoal with built-in visual verdict and pixel-diff evidence until the implementation matches and leaves a reproducible design system.

Yeachan-Heo/oh-my-codex · 52 tokens

accessibility

Consolidated accessibility skill entrypoint for WCAG 2.2, ARIA Authoring Practices, cognitive accessibility, Section 508, EN 301 549, design intent verification, and the Accessibility Planner workflow.

microsoft/hve-core · 47 tokens

make-resume

A Chinese-language tool for creating editable HTML resumes that can be changed in a browser and printed to PDF. It uses available resume templates when they are installed and otherwise provides a simpler fallback.

Hisn00w/ASu-skills · 86 tokens