Agent skill

Kandev Canvas Authoring

by kdlbs in kdlbs/kandev

Author a Kandev task canvas as a self-contained web application.

AGPL-3.0Auto-check passedProductivity & Automation

Install Kandev Canvas Authoring

skills CLI
$ npx skills add kdlbs/kandev --skill kandev-canvas-authoring -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kdlbs/kandev kandev-canvas-authoring --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/apps/backend/internal/mcp/canvasskill/files .claude/skills/kandev-canvas-authoring && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kandev-canvas-authoring
GitHub stars
912
Token cost
~1.7k tokens
SKILL.md length
927 words
Files
11 (incl. references)
Skills in repo
45
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Author a Kandev task canvas as a self-contained web application.

  • Works in 4 steps: Call create_canvas_kandev with a short… → Use native file tools in that returned… → Keep every source path relative to the… → …
  • Productivity & Automation work in your project
  • SKILL.md covers Required workflow, Core application contract, Minimal manifest and Browser protocol summary, plus 2 more sections
  • Runs JavaScript scripts from its folder

What it does

Kandev Canvas Authoring is an agent skill from kdlbs/kandev. Author a Kandev task canvas as a self-contained web application.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including reference files (for example `references/browser-api.md`, `references/data-and-state.md` and `references/events-and-recovery.md`).

It sits in Productivity & Automation. The repository describes itself as: AI Kanban & Development Environment. Orchestrate multiple agents, review changes, open PRs. Multi-provider, self-hostable, no telemetry. The licence is AGPL-3.0.

When your agent uses it

  • Productivity & Automation work in your project

Example prompts

  • “/kandev-canvas-authoring”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Call create_canvas_kandev with a short title and an application summary.
  2. Use native file tools in that returned directory. The initial files are
  3. Keep every source path relative to the returned directory. Do not write
  4. Run local checks, then call publish_canvas_kandev with the returned canvas

What it can do on your machine

Read from SKILL.md and the folder at commit 53a00c2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kandev Canvas Authoring loads about 1.7k tokens when it runs, and up to ~7.1k if it reads all its reference files. Until then it costs about 22 tokens; SKILL.md has 927 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kdlbs/kandev at commit 53a00c2, republished under its AGPL-3.0 licence (© kdlbs). 927 words, ~1,731 tokens.

Download SKILL.mdSave it as .claude/skills/kandev-canvas-authoring/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
kandev-canvas-authoring
description
Author a Kandev task canvas as a self-contained web application.
version
1

Kandev canvas authoring

Use one read_canvas_authoring_skill_kandev call without path when you need the authoring contract. That response is the complete core bundle. It includes this workflow, the manifest and browser protocol summary, appearance rules, the minimal scaffold, and the exact supporting-file inventory. Do not read the core bundle again during the same authoring task.

Required workflow

  1. Call create_canvas_kandev with a short title and an application summary. It creates an inactive task canvas and returns its source directory, manifest scaffold, initial permission policy, and exact scaffold inventory.
  2. Use native file tools in that returned directory. The initial files are manifest.yaml, index.html, appearance.js, script.js, and styles.css. Replace or extend them in the same directory.
  3. Keep every source path relative to the returned directory. Do not write outside it. Bundle executable dependencies. Node, a package manager, and a network build step are not available at runtime.
  4. Run local checks, then call publish_canvas_kandev with the returned canvas ID and source path. Read validation diagnostics and correct rejected source before publishing again.

The first valid release of a new owner-authorized task canvas uses the returned initial permission policy. It can activate without a second approval for its declared supported permissions. Kandev data access is limited to the current workspace, while the canvas remains placed in its creating task. Imported packages and later permission increases need human review. Promotion changes workspace navigation. Do not add a trust flag to the manifest, and do not request permissions outside the policy.

Core application contract

  • Include <meta name="viewport" content="width=device-width, initial-scale=1">.
  • Use relative ./_kandev/v1 paths for Kandev data, state, actions, and events.
  • Treat Kandev domain data as the source of truth. Derive filters and summaries in memory instead of storing a second copy of domain records.
  • Store only small application-specific shared values in instance state. Keep temporary input in memory and use conditional revisions for writes.
  • The canvas runs in a trusted same-origin iframe. Treat its source as trusted user-session code: it can use same-origin browser storage and cookies and can access the host DOM. It has the viewing user's ordinary API authority.
  • Keep Kandev protocol requests relative and do not copy capability URLs or tokens into source, URLs, query strings, logs, or client state. Same-origin cookies do not replace capability validation or the grants on protocol routes.
  • Render loading, empty, error, and retry states. Keep destructive actions explicit and explain their result.
  • Use accessible labels, keyboard operation, visible focus, and touch targets.

Kandev injects a reserved startup bootstrap into the entry document before authored scripts. It reports early document errors and checks the relative context route after document load. The host reveals the frame only after a versioned acknowledgement for the current attempt. A missing acknowledgement or context failure becomes recoverable after 15 seconds. Keep the entry valid HTML and render loading, empty, error, and retry states in the app.

Minimal manifest

Use the returned manifest_scaffold as the starting point. New manifests use api_version: 2, one lowercase web-app key, a package-relative entry, and at least one task-canvas or workspace-canvas placement. Declare only the api_read, api_write, events, state, and network_origins permissions that the application needs. The owner-authorized first release can receive only its declared supported permissions, with Kandev data limited to the current workspace. The entry and all relative assets must be in the published package.

Show full SKILL.md (377 more words)Show less

Browser protocol summary

Resolve all routes from the application document with ./_kandev/v1. Use context, the paginated data routes, state/{key} with If-Match, and the bounded events stream as documented by the optional references. Events are hints that invalidate a read. Refetch authoritative data after an event, reconnect with Last-Event-ID, and perform a full refetch after runtime.resync_required.

Appearance protocol

The host may send the public presentation-only message kandev.web_app.appearance with version: 1, mode: light|dark, and exactly these color tokens: background, foreground, card, cardForeground, muted, mutedForeground, border, primary, primaryForeground, accent, accentForeground, destructive, destructiveForeground, and ring. Accept it only when event.source === window.parent, the type and version match, the keys are exact, and each serialized color is bounded. Map the tokens to the same-name kebab-case CSS variables. Keep light and dark fallbacks so the app remains usable before the first message. The message has no identity, capability, data, storage, navigation, or action fields.

The generated appearance.js implements this listener. It is optional, but copy its pattern when replacing the scaffold.

Read a supporting reference only when its topic is needed:

  • references/browser-api.md for detailed browser routes and errors.
  • references/manifest.md for the full manifest shape and validation rules.
  • references/data-and-state.md for domain data and instance state.
  • references/events-and-recovery.md for events, reconnect, and retries.
  • references/security.md for same-origin trust and source safety rules.
  • references/ui-patterns.md for responsive and accessible UI patterns.

Distribution checklist

When the user asks for a portable canvas, keep the distribution boundary separate from authoring and runtime state:

  1. Add distribution.schema_version: 1, distribution.kind: canvas, a license, and source_mode: static or source_mode: project.
  2. Keep README.md, the manifest, the application entry, and every local asset in the package. Use project mode only when the retained project is complete and bounded below distribution/source/.
  3. Publish a valid release before offering a bundle or source download. The host prepares both archives from that immutable release and does not include screenshots.
  4. Add screenshots later as ordered previews objects in a registry entry. The first preview is the cover, canvas entries require one to eight images, and plugin entries may omit images.

The authoring tools do not create repositories, releases, registry entries, or pull requests. Report those manual follow-up steps to the user. Do not claim that a local archive or build is published until the Kandev release flow confirms it.

© kdlbs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (references) in apps/backend/internal/mcp/canvasskill/files of kdlbs/kandev.

  • SKILL.md
  • references/browser-api.md
  • references/data-and-state.md
  • references/events-and-recovery.md
  • references/manifest.md
  • references/security.md
  • references/ui-patterns.md
  • scaffold/appearance.js
  • scaffold/index.html
  • scaffold/script.js
  • scaffold/styles.css

Open the folder on GitHubat commit 53a00c2

Compare with similar skills

Kandev Canvas Authoring next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kandev Canvas Authoring compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kandev Canvas Authoring this skillkdlbs/kandev912—~1.7kAutomated safety check: PassAGPL-3.0
Agent Browserquran/quran.com-frontend-next1.9k40 repos~3.3kAutomated safety check: PassNone
Dependency Watchtelegramdesktop/tdesktop33k1 repos~2.2kAutomated safety check: PassGPL-3.0
Perform Tasktelegramdesktop/tdesktop33k2 repos~3kAutomated safety check: PassGPL-3.0
Brave Searchbadlogic/pi-skills2.6k5 repos~592Automated safety check: PassMIT
Garden Inboxpaperclipai/paperclip100k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Agent Browser

    quran/quran.com-frontend-next

    Automates browser interactions for web testing, form filling, screenshots, and data extraction.

    1.9k GitHub starsUsed in 40 repos~3.3k tokens
    Productivity & AutomationAuto-check passed
  • Dependency Watch

    telegramdesktop/tdesktop

    Audit Telegram Desktop dependencies on freshly fetched origin/dev for releases and security fixes, including upstream lag and backport candidates in patched forks.

    33k GitHub starsUsed in 1 repo~2.2k tokens
    Productivity & AutomationAuto-check passed
  • Perform Task

    telegramdesktop/tdesktop

    Resolve, start or resume, implement, review, test, and publish exactly one existing ai-tdesktop task by short slug or full dated id, including rare blocked retries and split-required results.

    33k GitHub starsUsed in 2 repos~3k tokens
    Productivity & AutomationAuto-check passed
  • Brave Search

    badlogic/pi-skills

    Web search and content extraction via Brave Search API. An agent skill from badlogic/pi-skills.

    2.6k GitHub starsUsed in 5 repos~592 tokens
    Productivity & AutomationAuto-check passed
  • Garden Inbox

    paperclipai/paperclip

    Scan a Paperclip user's Mine inbox, classify reversible archive candidates, request checkbox confirmation, and archive only accepted selections.

    100k GitHub stars~1.1k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Continue

    telegramdesktop/tdesktop

    Continue autonomous Telegram Desktop development from the shared ai-tdesktop repository.

    33k GitHub starsUsed in 2 repos~9.4k tokens
    Productivity & AutomationAuto-check passed

More from kdlbs/kandev

All 45 skills in this repo
  • PR Walkthrough

    kdlbs/kandev

    Generate a single-file HTML walkthrough that explains a PR's purpose, user impact, interface changes, compatibility risks, and implementation.

    917 GitHub stars~6.3k tokensUpdated today
    Auto-check passed
  • Debug

    kdlbs/kandev

    Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior.

    917 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Improve Kandev's AI harness from session learnings or explicit requests.

    917 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Diagram Design

    kdlbs/kandev

    Create branded architecture, IT current-state, flowchart, sequence, state machine, ER/data model, timeline, swimlane, quadrant, radar/spider, polar chart (polar/radial lollipop), loop/flywheel…

    917 GitHub starsUsed in 1 repo~8k tokens
    Auto-check passed
  • TDD

    kdlbs/kandev

    Implement changes using Test-Driven Development (Red-Green-Refactor).

    917 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Verify

    kdlbs/kandev

    Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.

    917 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Questions about Kandev Canvas Authoring

What does Kandev Canvas Authoring do?

Author a Kandev task canvas as a self-contained web application. Kandev Canvas Authoring is an agent skill from kdlbs/kandev. Author a Kandev task canvas as a self-contained web application.

When should I use Kandev Canvas Authoring?

Kandev Canvas Authoring fits situations like: productivity & Automation work in your project.

How do I install Kandev Canvas Authoring in Claude Code?

Run `npx skills add kdlbs/kandev --skill kandev-canvas-authoring -a claude-code`. Or copy the skill folder (apps/backend/internal/mcp/canvasskill/files in kdlbs/kandev) into .claude/skills/kandev-canvas-authoring in your project. Claude Code loads it when a task matches its description.

How do I install Kandev Canvas Authoring in Codex?

Run `npx skills add kdlbs/kandev --skill kandev-canvas-authoring -a codex`. Or copy the skill folder (apps/backend/internal/mcp/canvasskill/files in kdlbs/kandev) into .agents/skills/kandev-canvas-authoring in your project. Codex loads it when a task matches its description.

Can I use Kandev Canvas Authoring in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kdlbs/kandev --skill kandev-canvas-authoring -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kandev-canvas-authoring, .gemini/skills/kandev-canvas-authoring, .github/skills/kandev-canvas-authoring and .opencode/skills/kandev-canvas-authoring in your project.

What does Kandev Canvas Authoring need to run?

Going by SKILL.md and its folder, Kandev Canvas Authoring needs JavaScript for the scripts in its folder. Our summary lists: Node.js.

Does Kandev Canvas Authoring access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kandev Canvas Authoring safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kandev Canvas Authoring use?

Kandev Canvas Authoring is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kandev Canvas Authoring use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.3k tokens, read only when the agent opens those files.

What are the alternatives to Kandev Canvas Authoring?

Skills that share tags, products or a category with Kandev Canvas Authoring: Agent Browser (quran/quran.com-frontend-next, 1.9k stars), Dependency Watch (telegramdesktop/tdesktop, 33k stars), Perform Task (telegramdesktop/tdesktop, 33k stars) and Brave Search (badlogic/pi-skills, 2.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kandev Canvas Authoring?

kdlbs (a GitHub organization) maintains it in kdlbs/kandev, which has 912 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 10, 2026.

Source: kdlbs/kandev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.