Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add wangjianqi/AppStore --skill 05-project-architecturegit clone --depth 1 https://github.com/wangjianqi/AppStoreWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/wangjianqi/appstore/05-project-architecture)<a href="https://agentmods.dev/skills/wangjianqi/appstore/05-project-architecture"><img src="https://agentmods.dev/badge/skills/wangjianqi/appstore/05-project-architecture/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/wangjianqi/appstore/05-project-architecture"><img src="https://agentmods.dev/badge/skills/wangjianqi/appstore/05-project-architecture.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00038 | $0.03717 |
| Opus 5 | $0.00019 | $0.01858 |
| Sonnet 5 | $0.00008 | $0.00743 |
| Haiku 4.5 | $0.00004 | $0.00372 |
Grade A, and why
project-architecture scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 507 lines — stays where its author put it; the contents beside it link to each section on GitHub.
项目架构 DNA
目录结构
App/
├── Features/ # 功能模块(每个模块自包含)
│ ├── Camera/
│ │ ├── CameraVC.swift
│ │ ├── CameraViewModel.swift
│ │ ├── CameraService.swift
│ │ └── Views/
│ │ ├── CameraPreviewView.swift
│ │ └── CameraControlView.swift
│ ├── Settings/
│ │ ├── SettingsVC.swift
│ │ ├── SettingsViewModel.swift
│ │ └── SettingsService.swift
│ └── Paywall/
│ ├── PaywallVC.swift
│ ├── PaywallViewModel.swift
│ └── Views/
│ ├── PlanCardView.swift
│ └── FeatureListView.swift
├── Core/ # 跨模块基础设施
│ ├── Network/ # API 层
│ │ ├── NetworkService.swift
│ │ ├── APIEndpoint.swift
│ │ └── NetworkError.swift
│ ├── Storage/ # 本地持久化
│ │ ├── CoreDataStack.swift
│ │ ├── KeychainStorage.swift
│ │ └── UserDefaultsStorage.swift
│ ├── Analytics/ # 埋点
│ │ └── AnalyticsManager.swift
│ └── Extensions/ # Swift 扩展
│ ├── String+Localized.swift
│ ├── UIView+Constraints.swift
│ └── UIColor+Hex.swift
├── DesignSystem/ # UI 组件库
│ ├── AppColors.swift
│ ├── AppFonts.swift
│ ├── Layout.swift
│ └── Components/ # 可复用 UI 组件
│ ├── LoadingView.swift
│ ├── EmptyStateView.swift
│ └── PrimaryButton.swift
└── Resources/
├── Assets.xcassets
├── Localizable.strings
└── Models/ # CoreML 模型文件
架构模式:MVVM
View (VC + UIView)
↕ 绑定(closure / Combine)
ViewModel(业务逻辑 + 状态)
↕ 调用
Service / Repository(数据层)
- VC 职责: 初始化视图、绑定 ViewModel、响应用户事件
- ViewModel 职责: 处理业务逻辑、持有状态、调用 Service
- Service 职责: 网络请求、本地存储、设备能力(相机、麦克风)
- 禁止跨层直接调用(VC 不直接调 Service,ViewModel 不操作 UIView)
ViewModel 完整模板
Closure 绑定模式
import Foundation
protocol HomeViewModelProtocol {
var onItemsUpdated: (() -> Void)? { get set }
var onError: ((AppError) -> Void)? { get set }
var onLoadingStateChanged: ((Bool) -> Void)? { get set }
var items: [Item] { get }
func loadData()
func didSelectItem(at index: Int)
}
final class HomeViewModel: HomeViewModelProtocol {
var onItemsUpdated: (() -> Void)?
var onError: ((AppError) -> Void)?
var onLoadingStateChanged: ((Bool) -> Void)?
private(set) var items: [Item] = [] {
didSet { onItemsUpdated?() }
}
private let service: ItemServiceProtocol
private weak var navigation: HomeNavigation?
init(service: ItemServiceProtocol, navigation: HomeNavigation) {
self.service = service
self.navigation = navigation
}
func loadData() {
onLoadingStateChanged?(true)
service.fetchItems { [weak self] result in
self?.onLoadingStateChanged?(false)
switch result {
case .success(let items):
self?.items = items
case .failure(let error):
self?.onError?(error)
}
}
}
func didSelectItem(at index: Int) {
guard index < items.count else { return }
navigation?.showDetail(itemID: items[index].id)
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 507 lines · 38 tokens per session scan A ecc37f0a47e0
project-architecture is a skill published in the GitHub repository wangjianqi/AppStore (11 stars, last pushed 3mo ago), licensed MIT. It adds 38 tokens to every session and 3,717 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
ipaship-audit
Use when auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines or Google Play Developer Policies. Scan .ipa, .apk, or .zip files against official store policies, generate structured compliance reports, and identify violations with remediation steps.
view-specifications
Guide for writing view specification documents and a starter template for SwiftUI and cross-platform views.
project-structure
Directory layout, file responsibilities, and Xcode integration for meta-loop projects.
analyzing-ios-app-security-with-objection
Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.
argent-tv-interact
Control and inspect TV apps via argent — Apple TV (tvOS), Android TV (leanback), and Amazon Fire TV (Vega). Boot the target, read focus, navigate with the D-pad remote, type, screenshot, and on Vega debug the JS runtime (evaluate, console logs, network inspector). Use when a task targets a TV (runtimeKind "tv", or…
argent-create-flow
Create, record, edit, replay, or repair reusable Argent flow YAML files. Use when the user asks to record or replay a repeatable device path, set up profiling or an A/B comparison, or invoke the authoring engine behind argent-qa-flows. Also use before repeating three or more interactions. For one-off UI checks…