hono-guide

hono-guide is a skill for Claude Code from xonovex/platform. It costs 82 tokens per session (883 once invoked), scanned A, original, MIT.

A guide to building HTTP API servers with Hono 4 or newer in TypeScript. Hono is a small web framework for handling routes, requests, middleware, errors, cookies, and WebSockets.

In plain words
What is it for?
Use it when creating or editing Hono routes, API validation, middleware, WebSocket handlers, security headers, cookies, or runtime-specific code.
Why use it?
It provides consistent ways to validate requests, return standard error responses, configure middleware, and keep code portable across runtimes.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the xonovex-skill-hono plugin — 1 skill shipped together

Good fit Use it when creating or editing Hono routes, API validation, middleware, WebSocket handlers, security headers, cookies, or runtime-specific code.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/xonovex/platform/hono-guide
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add xonovex/platform --skill hono-guide
Clone the repo
git clone --depth 1 https://github.com/xonovex/platform

Made for: Claude Code.

Or install xonovex-skill-hono, the plugin that ships this one along with the rest of its 1 skill.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for hono-guide

README.md
[![agentmods](https://agentmods.dev/badge/skills/xonovex/platform/hono-guide/github.svg)](https://agentmods.dev/skills/xonovex/platform/hono-guide)
Your own site
<a href="https://agentmods.dev/skills/xonovex/platform/hono-guide"><img src="https://agentmods.dev/badge/skills/xonovex/platform/hono-guide/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for hono-guide

Your own site · 80×15
<a href="https://agentmods.dev/skills/xonovex/platform/hono-guide"><img src="https://agentmods.dev/badge/skills/xonovex/platform/hono-guide.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 82 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 883 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00082 $0.00883
Opus 5 $0.00041 $0.00441
Sonnet 5 $0.00016 $0.00177
Haiku 4.5 $0.00008 $0.00088

Measured 9d ago against content hash e0ca93c1aa3f, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-17, from the pricing page.

Security

Grade A, and why

hono-guide scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

packages/skill/skill-hono/hono-guide/SKILL.md · 56 lines

How it starts

The opening of the file, as written. The whole thing — 56 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Hono Coding Guidelines

Requirements

  • Hono ≥ 4.0, @hono/node-server, @hono/zod-validator, TypeScript ≥ 5.8

Essentials

Example

import {Hono} from "hono";
import {secureHeaders} from "hono/secure-headers";

export function createApp() {
  const app = new Hono();
  app.use("*", secureHeaders());
  app.route("/api/v1", v1Router);
  return app;
}

Gotchas

  • c.req.valid('json') is typed by inference only when zValidator is chained inline on the route; an imported base-Context controller sees any, so cast there, but that cast is unchecked and can hide schema drift
  • Middleware runs in the order it's registered: auth before routes, error handlers last; ordering bugs cause silent 200s on protected routes
  • env(c) is the portable way to read env vars across runtimes: process.env works on Node but not Workers/Deno
  • WebSocket helpers capture this from the closing object: assigning the handler to a variable loses the binding

Read the full file on GitHub · 56 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 56 lines · 82 tokens per session scan A e0ca93c1aa3f

Subscribe to this mod's changes

hono-guide is a skill published in the GitHub repository xonovex/platform (6 stars, last pushed 4d ago), licensed MIT. It adds 82 tokens to every session and 883 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-08.