Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/xyruscode/ai-sync/blueprintnpx skills add XyrusCode/ai-sync --skill blueprintgit clone --depth 1 https://github.com/XyrusCode/ai-syncWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00030 | $0.00790 |
| Opus 5 | $0.00015 | $0.00395 |
| Sonnet 5 | $0.00006 | $0.00158 |
| Haiku 4.5 | $0.00003 | $0.00079 |
Grade A, and why
blueprint scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Blueprint
Blueprint has four assets:
Automation: executes work from manual, one-shot, scheduled, interval, condition, or Widget-event triggers.Widget: renders one responsiveindex.htmland owns display data, input state, and UI events.Binding: connects an Automation artifact toWidget.slots.mainand routesWidget.events.submitback to Automation input.Canvas: places Widgets and owns placement layout, z-order, and placement-local view state.
Rules
- Branch on
DaimonToolResponse.okbefore readingdata. - Use returned ids; never invent
automationId,widgetId,bindingId,canvasId,mountId, orviewId. - Resolve named assets with
list; usereadfor details. - Use the shortest asset chain that satisfies the request.
- Do not report completion until the matching verification below passes.
- Use platform file APIs and
FileResourceReffor uploads and generated files. - Automation limits count only enabled regular tasks. Cron jobs and widget tasks have separate limits.
- Disabled tasks are kept. A downgrade disables older tasks by
createdAt; running tasks finish.
Routing
- Executable work, schedules, conditions, runs, cancellation, or delivery: load
automation/SKILL.md. - HTML UI, data rendering, input controls, or Widget files: load
widget/SKILL.md, then readwidget/references/runtime-api.mdbefore iframe API code. - Automation-to-Widget data delivery or Widget submit routing: load
binding/SKILL.md. - Board creation, Widget placement, movement, resizing, z-order, or view state: load
canvas/SKILL.md.
Standard Chains
- Static Widget:
Widget.create-> writeworkspaceRoot/index.html->Widget.validate->Widget.showorCanvas.placeWidget. - Automation:
Automation.create-> write Python entry when using code execution ->Automation.run->Automation.readRun. - Automation-backed Widget: define matching schemas -> create Automation and Widget -> write and validate
index.html->Binding.create-> run Automation -> verify delivery andWidget.latestData.main. - File Widget: pick and submit
FileResourceRef-> Automation reads and registers outputs -> Binding -> Widget/Canvas host preview, download, reveal, and copy actions.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 57 lines · 30 tokens per session scan A a3c4c644669d
blueprint is a skill published in the GitHub repository XyrusCode/ai-sync (2 stars, last pushed yesterday), licensed MIT. It adds 30 tokens to every session and 790 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…