Agent skill

Vendored Assets

by foldkit in foldkit/foldkit

Vendored assets. An agent skill from foldkit/foldkit.

MITAuto-check passedBackend & APIs

Install Vendored Assets

skills CLI
$ npx skills add foldkit/foldkit --skill vendored-assets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install foldkit/foldkit vendored-assets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/foldkit/foldkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/repos/effect/.agents/skills/vendored-assets .claude/skills/vendored-assets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendored-assets
GitHub stars
918
Token cost
~734 tokens
SKILL.md length
373 words
Files
2
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

Vendored assets. An agent skill from foldkit/foldkit.

  • Works in 7 steps: Trace ownership. Identify the artifact,… → Pin provenance. Resolve moving URLs,… → Clear the license gate. Verify release… → …
  • Updating checked-in third-party
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Externally generated JavaScript

What it does

Vendored Assets is an agent skill from foldkit/foldkit. Vendored assets. Use when importing or updating checked-in third-party or externally generated JavaScript, CSS, registries, schemas, snapshots, or Scalar, Swagger, and MIME artifacts.

Its SKILL.md is about 730 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `browser-assets.md`).

It sits in Backend & APIs, covering OpenAPI specifications. It works with JavaScript and OpenAPI. The licence is MIT.

When your agent uses it

  • Updating checked-in third-party
  • Externally generated JavaScript

Example prompts

  • “/vendored-assets”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Trace ownership. Identify the artifact, generator or exact import
  2. Pin provenance. Resolve moving URLs, tags, branches, and omitted versions
  3. Clear the license gate. Verify release metadata, license files, bundled
  4. Regenerate. Improve the generator or import reference first. Recover an
  5. Audit the complete diff. Account for behavior, URLs and runtime fetches,
  6. Clear test and size gates. Record byte sizes before and after, use
  7. Close release impact. Apply root changeset routing for consumer-visible

What it can do on your machine

Read from SKILL.md and the folder at commit d21db42. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendored Assets loads about 734 tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 373 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~734

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from foldkit/foldkit at commit d21db42, republished under its MIT licence (© foldkit). 373 words, ~734 tokens.

Download SKILL.mdSave it as .claude/skills/vendored-assets/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
vendored-assets
description
Vendored assets. Use when importing or updating checked-in third-party or externally generated JavaScript, CSS, registries, schemas, snapshots, or Scalar, Swagger, and MIME artifacts.

Treat upstream artifacts as supply-chain inputs. Change their generator or documented import source, then regenerate; generated output is review evidence, not an editing surface.

Workflow

  1. Trace ownership. Identify the artifact, generator or exact import procedure, upstream source/version, license, consumers, tests, and shipped package or bundle. Search by asset and upstream project name to find current packaging scripts, generated artifacts, consumers, and history. Continue when every input and consumer is accounted for.
  2. Pin provenance. Resolve moving URLs, tags, branches, and omitted versions to an immutable release or artifact. Record project, version, path or URL, and digest in the generator or maintenance header. Omit a digest only when another enforced immutable source is recorded. Continue when a future run cannot silently select different bytes.
  3. Clear the license gate. Verify release metadata, license files, bundled notices, and the license trail retained in the distributed form. Continue when every distributed artifact has a verified retained license trail.
  4. Regenerate. Improve the generator or import reference first. Recover an exact procedure for generatorless assets; add a deterministic script only for recurring updates. Record a one-off procedure beside the artifact. A clean rerun must produce no diff.
  5. Audit the complete diff. Account for behavior, URLs and runtime fetches, source maps, notices, encoding, format changes, and additions or removals. For browser assets, also read browser-assets.md. Continue when every change is attributable and suspicious content is resolved or reported.
  6. Clear test and size gates. Record byte sizes before and after, use focused consumer tests, and compare bundle size or composition when shipped JavaScript, CSS, or registry output changes materially. Compare that output against the pre-update revision rather than measuring only current size. Continue when focused checks pass and every non-trivial size delta is explained.
  7. Close release impact. Apply root changeset routing for consumer-visible behavior, browser support, wire data, or meaningful shipped-size changes. Generated sections owned by barrels, AI docs, or migration tooling remain with the owners named in root instructions.
Show full SKILL.md (45 more words)Show less

The task is complete when every input and consumer is accounted for, provenance and licenses are immutable and retained, regeneration is deterministic, every output change and non-trivial size delta is explained, focused checks pass or are reported as not runnable, and release impact is recorded.

© foldkit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in repos/effect/.agents/skills/vendored-assets of foldkit/foldkit.

  • SKILL.md
  • browser-assets.md

Open the folder on GitHubat commit d21db42

Compare with similar skills

Vendored Assets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendored Assets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendored Assets this skillfoldkit/foldkit918—~734Automated safety check: PassMIT
Counterfact Replcounterfact/api-simulator170—~3.2kAutomated safety check: PassMIT
Add Namespaceswagger-api/apidom100—~8.1kAutomated safety check: PassNone
Add Parser Adapterswagger-api/apidom100—~11kAutomated safety check: PassNone
Update Ls Configswagger-api/apidom100—~5.9kAutomated safety check: PassNone
Sap API Stylesecondsky/sap-skills462—~4.4kAutomated safety check: PassGPL-3.0

Similar skills

  • Counterfact Repl

    counterfact/api-simulator

    Interact with Counterfact mock API server programmatically. An agent skill from counterfact/api-simulator.

    170 GitHub stars~3.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Add Namespace

    swagger-api/apidom

    Creates a new namespace package for a new API specification version in the ApiDOM monorepo

    100 GitHub stars~8.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Add Parser Adapter

    swagger-api/apidom

    Creates parser adapter packages for existing ApiDOM namespace packages and integrates them with apidom-reference

    100 GitHub stars~11k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Update Ls Config

    swagger-api/apidom

    Updates apidom-ls configuration for a namespace package by analyzing the namespace structure and creating completion, documentation, and lint configurations

    100 GitHub stars~5.9k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Sap API Style

    secondsky/sap-skills

    This skill provides comprehensive guidance for documenting SAP APIs following the SAP API Style Guide standards.

    462 GitHub stars~4.4k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • API Breaking Change Detector

    github/awesome-copilot

    Official

    Cross-references C Web API controllers/DTOs against their TypeScript/JavaScript consumers (React, Angular, Vue, Svelte, Node.js, or hand-written/auto-generated HTTP clients like Fetch, Axios, NSwag)…

    40k GitHub stars~1.7k tokensUpdated today
    Backend & APIsAuto-check passed

More from foldkit/foldkit

All 18 skills in this repo
  • Commit Changes

    foldkit/foldkit

    Create a git commit in the Foldkit monorepo with changeset enforcement and formatting.

    918 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Foldkit

    foldkit/foldkit

    A skill your agent uses whenever working with Foldkit. An agent skill from foldkit/foldkit.

    918 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Outline, draft, or revise a Foldkit version release blog post using the repository's announcement style and editorial preferences.

    918 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Audit Program

    foldkit/foldkit

    Audit an existing Foldkit program against the architecture, conventions, and quality bar.

    918 GitHub stars~7.2k tokensUpdated today
    Auto-check passed
  • Generate Program

    foldkit/foldkit

    Generate a complete, idiomatic Foldkit program from a natural language description.

    918 GitHub stars~20k tokensUpdated today
    Auto-check passed
  • Changesets

    foldkit/foldkit

    Concise PR finalization changesets. An agent skill from foldkit/foldkit.

    918 GitHub stars~923 tokensUpdated today
    Auto-check passed

Categories

Questions about Vendored Assets

What does Vendored Assets do?

Vendored assets. An agent skill from foldkit/foldkit. Vendored Assets is an agent skill from foldkit/foldkit. Vendored assets.

When should I use Vendored Assets?

Vendored Assets fits situations like: updating checked-in third-party; externally generated JavaScript.

How do I install Vendored Assets in Claude Code?

Run `npx skills add foldkit/foldkit --skill vendored-assets -a claude-code`. Or copy the skill folder (repos/effect/.agents/skills/vendored-assets in foldkit/foldkit) into .claude/skills/vendored-assets in your project. Claude Code loads it when a task matches its description.

How do I install Vendored Assets in Codex?

Run `npx skills add foldkit/foldkit --skill vendored-assets -a codex`. Or copy the skill folder (repos/effect/.agents/skills/vendored-assets in foldkit/foldkit) into .agents/skills/vendored-assets in your project. Codex loads it when a task matches its description.

Can I use Vendored Assets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add foldkit/foldkit --skill vendored-assets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendored-assets, .gemini/skills/vendored-assets, .github/skills/vendored-assets and .opencode/skills/vendored-assets in your project.

What does Vendored Assets need to run?

SKILL.md names no scripts, command-line tools or credentials: Vendored Assets is instructions for the agent only.

Does Vendored Assets access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendored Assets safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vendored Assets use?

Vendored Assets is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendored Assets use?

About 734 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vendored Assets?

Skills that share tags, products or a category with Vendored Assets: Counterfact Repl (counterfact/api-simulator, 170 stars), Add Namespace (swagger-api/apidom, 100 stars), Add Parser Adapter (swagger-api/apidom, 100 stars) and Update Ls Config (swagger-api/apidom, 100 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendored Assets?

foldkit (a GitHub organization) maintains it in foldkit/foldkit, which has 918 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 8, 2026.

Source: foldkit/foldkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.