Fastapi App
ccplugins/awesome-claude-code-plugins
Bootstrap a new FastAPI backend with async SQLAlchemy 2.0, asyncpg, Alembic, Pydantic v2, and no deprecated APIs.
A skill your agent uses when building, reviewing, securing, testing or shipping a Django app — models, migrations, QuerySets/managers, FBV/CBV views, forms, the admin, settings split, and Django…
$ npx skills add ericrisco/rsc-harness --skill django -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness django --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/django .claude/skills/django && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "django" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/django into .claude/skills/django/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "django", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/djangoType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill django -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness django --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/django .agents/skills/django && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "django" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/django into .agents/skills/django/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "django", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill django -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness django --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/django .cursor/skills/django && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "django" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/django into .cursor/skills/django/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "django", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/django--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill django -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness django --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/django .gemini/skills/django && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "django" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/django into .gemini/skills/django/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "django", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness djangoInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill django -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/django .github/skills/django && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "django" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/django into .github/skills/django/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "django", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill django -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness django --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/django .opencode/skills/django && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "django" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/django into .opencode/skills/django/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "django", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
djangoA skill your agent uses when building, reviewing, securing, testing or shipping a Django app — models, migrations, QuerySets/managers, FBV/CBV views, forms, the admin, settings split, and Django…
Django is an agent skill from ericrisco/rsc-harness. Use when building, reviewing, securing, testing or shipping a Django app — models, migrations, QuerySets/managers, FBV/CBV views, forms, the admin, settings split, and Django REST Framework (serializers, ModelViewSet, permissions). NOT async FastAPI/Pydantic services (that is fastapi), NOT Postgres schema/index work (that is postgresdb).
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/drf.md`).
It sits in Backend & APIs, covering Backend development. It works with Django, FastAPI, PostgreSQL and Pydantic. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SECRET_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Django loads about 3.1k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 1,036 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,036 words, ~3,089 tokens.
.claude/skills/django/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.The single authoritative skill for building, reviewing, securing, testing and shipping a Django app — the batteries-included, ORM-first, request/response Python framework.
Mental model: a Django project is apps composed of fat-but-thin-enough models (domain + query logic on the model/manager), views that orchestrate (FBV/CBV/DRF) and never own SQL, an admin/forms layer, and a settings module split by environment. The ORM, migrations, auth, admin, CSP and the test runner are all first-party. Reach for the framework before you add a dependency.
shell,
CompositePrimaryKey, BoundField customization.ContentSecurityPolicyMiddleware, SECURE_CSP) and can take the shorter support window.
Drops Python 3.10/3.11; supports 3.12–3.14.pytest-django, factory_boy. ruff/uv and type-hint policy live in python.Version rule: default to 5.2 LTS. Pick 6.0 only for a concrete Tasks/CSP need, and say so.
| Situation | Route to |
|---|---|
Async service, fastapi/pydantic/uvicorn, async SQLAlchemy | fastapi |
| Postgres schema design, EXPLAIN ANALYZE, indexing strategy, RLS, pooling | postgresdb |
| Cross-stack OWASP/STRIDE threat modeling | secure-coding |
| Container/Compose/CI, gunicorn prod tuning, collectstatic pipeline | deployment |
| REST contract design (cursor vs offset, status codes, versioning) | api-design |
| ruff/uv/general type hints, packaging | python |
Split settings by environment; never ship one settings.py toggled by DEBUG.
src/
manage.py
config/
settings/
base.py # shared; reads secrets from os.environ
dev.py # from base import *; DEBUG=True; local hosts
prod.py # from base import *; DEBUG=False; SECURE_*; CSP
catalog/ # an app = a bounded domain
models.py managers.py views.py serializers.py urls.py admin.py
migrations/
tests/os.environ["SECRET_KEY"] (or django-environ). Never commit a
literal SECRET_KEY — a leaked key forges sessions and signed tokens.DJANGO_SETTINGS_MODULE=config.settings.prod, not an if DEBUG branch.core app that accretes everything.Put domain and query logic on the model and its manager. The view stays thin.
# managers.py
from django.db import models
class ArticleQuerySet(models.QuerySet):
def published(self):
return self.filter(status=Article.Status.PUBLISHED)
def for_reader(self): # composes; reused everywhere, tested once
return self.published().select_related("author")
# models.py
class Article(models.Model):
class Status(models.TextChoices):
DRAFT = "draft", "Draft"
PUBLISHED = "published", "Published"
tenant = models.ForeignKey("Tenant", on_delete=models.CASCADE)
slug = models.SlugField()
author = models.ForeignKey("Author", on_delete=models.PROTECT)
status = models.CharField(max_length=16, choices=Status.choices, default=Status.DRAFT)
published_at = models.DateTimeField(null=True, blank=True)
objects = ArticleQuerySet.as_manager()
class Meta:
constraints = [
models.UniqueConstraint(fields=["tenant", "slug"], name="uniq_tenant_slug"),
models.CheckConstraint(
check=models.Q(status="draft") | models.Q(published_at__isnull=False),
name="published_needs_date",
),
]
indexes = [models.Index(fields=["tenant", "status"])]UniqueConstraint/CheckConstraint is
enforced under concurrency; a clean() check is not. Validate-in-Python-only is a foot-gun.on_delete is mandatory and load-bearing: CASCADE deletes children, PROTECT blocks the
delete, SET_NULL orphans. Choosing wrong silently destroys data — pick deliberately.pk = models.CompositePrimaryKey("tenant_id", "id").# Bad: logic in the view — untested, unreusable, duplicated across endpoints
def publish(request, pk):
a = Article.objects.get(pk=pk)
a.status = "published"; a.published_at = timezone.now(); a.save()
# Good: a method on the model — one place, testable, reused by view/admin/command
class Article(models.Model):
def publish(self):
self.status = self.Status.PUBLISHED
self.published_at = timezone.now()
self.save(update_fields=["status", "published_at"])The N+1 is the single most common Django defect: one query for the list, then one more per row.
# Bad: 1 + N queries — each .author touches the DB inside the loop
for a in Article.objects.all():
print(a.author.name)
# Good: 2 queries total (FK -> JOIN; reverse/M2M -> second query)
for a in Article.objects.select_related("author").prefetch_related("tags"):
print(a.author.name, [t.name for t in a.tags.all()])| You are following | Use | Cost |
|---|---|---|
Forward ForeignKey / OneToOne | select_related(...) | SQL JOIN, 1 query |
Reverse FK, ManyToMany | prefetch_related(...) | 2nd query, joined in Python |
| Prefetch that itself needs filter/order | Prefetch("x", queryset=...) | controlled 2nd query |
qs.exists(), never len(qs) or if qs.count()..only("id", "slug") / .defer("body").annotate(...) / aggregate(...), not a Python loop.bulk_create(objs) — one round-trip, not N .save() calls.Model.objects.all() then slice/filter in Python; push it into the QuerySet.Deeper recipes (assertNumQueries, Prefetch, .explain(), ORM indexing) →
references/orm-performance.md.
Keep views thin: validate input, call a model/manager method, return a response. No SQL.
| Need | Use |
|---|---|
| One bespoke action, custom flow | function-based view (FBV) |
| Standard list/detail/create/update/delete on a model | generic CBV (ListView, DetailView, …) |
| JSON API consumed by a client/SPA | drop to DRF (do not hand-roll JsonResponse CRUD) |
For the DRF surface — serializers, ModelViewSet, routers, permissions, throttling,
pagination, filtering, nested-serializer N+1, versioning — see
references/drf.md. The thin-view rule still holds: a fat serializer that
walks relations per row is just an N+1 wearing a tie.
python manage.py makemigrations catalog # generate from model diff
python manage.py migrate # apply
python manage.py makemigrations --check # CI gate: fail if a model drifts from migrationsmigrations.RunPython(forward, reverse) with a reverse, not a
one-off script. Use the historical model from apps.get_model(...), not the imported class.postgresdb.Set these in prod.py. Then prove it: python manage.py check --deploy must come back clean.
| Setting | Value | Why |
|---|---|---|
DEBUG | False | True leaks settings + a stack-trace shell to the world |
ALLOWED_HOSTS | explicit domains | ['*'] enables Host-header attacks |
SECRET_KEY | from os.environ | a literal in source forges signed cookies/tokens |
SECURE_SSL_REDIRECT | True | force HTTPS |
SECURE_HSTS_SECONDS | 31536000 (+ include-subdomains, preload) | the check --deploy warning you saw is this being 0 |
SESSION_COOKIE_SECURE / CSRF_COOKIE_SECURE | True | stop cookie leak over HTTP |
SECURE_CSP (Django 6.0) | a real policy + nonce | native CSP; pre-6.0 use django-csp |
CsrfViewMiddleware; do not blanket-exempt views..raw(), .extra() and cursor.execute() with an
f-string/%-built string reopen SQL injection. Pass params, never interpolate.Full SECURE_* checklist, CSP nonce/report-only, upload/SSRF, ORM-injection →
references/security.md.
import pytest
from rest_framework.test import APIClient
@pytest.mark.django_db
def test_owner_only(article, owner):
client = APIClient()
assert client.get(f"/api/articles/{article.pk}/").status_code == 403 # anon
client.force_authenticate(owner)
assert client.get(f"/api/articles/{article.pk}/").status_code == 200pytest-django + @pytest.mark.django_db; run with --reuse-db to skip rebuilds locally.TestCase wraps each test in a rolled-back transaction (fast). Use TransactionTestCase
only when you test on_commit hooks or real commit behavior.assertNumQueries(2) — it fails the build when a relation regresses.factory_boy, not 30 lines of Model.objects.create(...).Setup, fixtures, transactional DB, coverage → references/testing.md.
| Need | Use |
|---|---|
| New project on Django 6.0, simple enqueue-and-forget jobs | the built-in Tasks framework |
| Pre-6.0, or you need schedules/retries/fan-out/result backends/workers at scale | Celery |
Either way: enqueue from the model/service layer, never block the request thread.
| Anti-pattern | Why it bites | Do instead |
|---|---|---|
| Business logic in the view | untested, duplicated across endpoints | method on the model/manager |
f-string SQL into .raw()/.extra()/cursor.execute | SQL injection | parameterized queries |
Looping rows touching .author | N+1 queries | select_related/prefetch_related |
DEBUG=True in prod | leaks settings + stack traces | DEBUG=False in prod.py |
SECRET_KEY literal in source | forged sessions/tokens | os.environ |
Validation only in clean() | races under concurrency | DB UniqueConstraint/CheckConstraint |
Model.objects.all() in a template loop | one query per iteration | prefetch in the view |
ModelViewSet with no permission_classes | endpoint open to the world | explicit permission class |
| Fat serializer walking relations | N+1 per response | prefetch + assertNumQueries |
| Editing an applied migration | breaks every env that ran it | new migration |
len(qs) / qs.count() to test existence | full fetch/COUNT | qs.exists() |
Swallowing Model.DoesNotExist silently | hidden bugs | get_object_or_404 or handle explicitly |
scripts/verify.sh [TARGET] greps tracked Django source for high-signal foot-guns:
FAIL on a literal SECRET_KEY, ALLOWED_HOSTS = ['*'], or f-string SQL in
.raw()/.extra()/cursor.execute; WARN on DEBUG = True outside a dev settings file and
a ModelViewSet/APIView with no permission_classes. Read-only, exit 0 on a clean or empty
target. It is a lint, not a substitute for manage.py check --deploy or the test suite.
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references) in skills/django of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
Django next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Django this skillericrisco/rsc-harness | 156 | — | ~3.1k | Automated safety check: Pass | MIT | |
| Fastapi Appccplugins/awesome-claude-code-plugins | 967 | — | ~1.1k | Automated safety check: Notes | Apache-2.0 | |
| Framework Migration AssistantArabelaTso/Skills-4-SE | 253 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Pydanticbobmatnyc/claude-mpm | 155 | — | ~8.4k | Automated safety check: Notes | Custom licence | |
| Fastcrudbenavlabs/fastcrud | 1.6k | — | ~5k | Automated safety check: Pass | MIT | |
| Silk Profilerbaserow/baserow | 6.1k | — | ~2.9k | Automated safety check: Pass | Custom licence |
ccplugins/awesome-claude-code-plugins
Bootstrap a new FastAPI backend with async SQLAlchemy 2.0, asyncpg, Alembic, Pydantic v2, and no deprecated APIs.
ArabelaTso/Skills-4-SE
Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).
bobmatnyc/claude-mpm
Python data validation using type hints and runtime type checking with Pydantic v2's Rust-powered core for high-performance validation in FastAPI, Django, and configuration management.
benavlabs/fastcrud
A skill your agent uses when building or modifying CRUD endpoints with FastCRUD (the fastcrud PyPI package) in a FastAPI project — covers FastCRUD, crudrouter, EndpointCreator, FilterConfig…
baserow/baserow
Investigate backend performance using Django Silk profiling data.
wshobson/agents
Scaffolds FastAPI projects with a layered app layout, dependency injection through Depends, async handlers and database access, middleware and pytest setup.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Works with
Categories
A skill your agent uses when building, reviewing, securing, testing or shipping a Django app — models, migrations, QuerySets/managers, FBV/CBV views, forms, the admin, settings split, and Django…. Django is an agent skill from ericrisco/rsc-harness. Use when building, reviewing, securing, testing or shipping a Django app — models, migrations, QuerySets/managers, FBV/CBV views, forms, the admin, settings split, and Django REST Framework (serializers, ModelViewSet, permissions).
Django fits situations like: shipping a Django app — models; querySets/managers; django REST Framework (serializers.
Run `npx skills add ericrisco/rsc-harness --skill django -a claude-code`. Or copy the skill folder (skills/django in ericrisco/rsc-harness) into .claude/skills/django in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill django -a codex`. Or copy the skill folder (skills/django in ericrisco/rsc-harness) into .agents/skills/django in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill django -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/django, .gemini/skills/django, .github/skills/django and .opencode/skills/django in your project.
Going by SKILL.md and its folder, Django needs a shell for the scripts in its folder, the command-line tools its instructions call (python) and credentials named SECRET_KEY. Our summary lists: Python 3; A Bash shell; A credential in SECRET_KEY.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Django is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Django: Fastapi App (ccplugins/awesome-claude-code-plugins, 967 stars), Framework Migration Assistant (ArabelaTso/Skills-4-SE, 253 stars), Pydantic (bobmatnyc/claude-mpm, 155 stars) and Fastcrud (benavlabs/fastcrud, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.