Agent skill

Spiceflow

by remorses in remorses/spiceflow

Spiceflow is a super simple, fast, and type-safe API and React Server Components framework for TypeScript.

MITAuto-check passedBackend & APIs

Install Spiceflow

skills CLI
$ npx skills add remorses/spiceflow --skill spiceflow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install remorses/spiceflow spiceflow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/remorses/spiceflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/spiceflow .claude/skills/spiceflow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spiceflow
GitHub stars
167
Token cost
~1.9k tokens
SKILL.md length
710 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Spiceflow is a super simple, fast, and type-safe API and React Server Components framework for TypeScript.

  • Tasks that involve OpenAPI specifications
  • SKILL.md covers How the docs work, ALWAYS read the feature doc…, Testing spiceflow apps and Non-negotiable rules
  • Calls curl, pnpm and npm; reaches getspiceflow.com
  • Tasks that involve Type safety

What it does

Spiceflow is an agent skill from remorses/spiceflow. Spiceflow is a super simple, fast, and type-safe API and React Server Components framework for TypeScript. Works on Node.js, Bun, and Cloudflare Workers. ALWAYS load this skill BEFORE writing or editing ANY spiceflow code, including one-line changes: routes, pages, layouts, loaders, server actions, forms, ErrorBoundary, redirects, cookies, navigation, Link, router, ProgressBar, the typed fetch client, middleware, and OpenAPI. A project uses spiceflow if anything imports from "spiceflow" or "spiceflow/react", or…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OpenAPI specifications and Type safety. It works with React, Next.js, OpenAPI and Cloudflare Workers. The repository describes itself as: Minimal API & React framework, fully type safe, OpenAPI, RSC, MCP, type safe client, streaming with SSE. The licence is MIT.

When your agent uses it

  • Tasks that involve OpenAPI specifications
  • Tasks that involve Type safety

Example prompts

  • “spiceflow”
  • “spiceflow/react”
  • “/spiceflow”

Requirements

  • Node.js
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 24643b8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • pnpm
    • npm
    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • getspiceflow.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spiceflow loads about 1.9k tokens when it runs. Until then it costs about 182 tokens; SKILL.md has 710 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~182
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from remorses/spiceflow at commit 24643b8, republished under its MIT licence (© remorses). 710 words, ~1,943 tokens.

Download SKILL.mdSave it as .claude/skills/spiceflow/SKILL.md (or your agent's skills folder).
name
spiceflow
description
Spiceflow is a super simple, fast, and type-safe API and React Server Components framework for TypeScript. Works on Node.js, Bun, and Cloudflare Workers. ALWAYS load this skill BEFORE writing or editing ANY spiceflow code, including one-line changes: routes, pages, layouts, loaders, server actions, forms, ErrorBoundary, redirects, cookies, navigation, Link, router, ProgressBar, the typed fetch client, middleware, and OpenAPI. A project uses spiceflow if anything imports from "spiceflow" or "spiceflow/react", or constructs new Spiceflow(). The API is small but very opinionated and the opinions are NOT guessable; writing spiceflow code from memory or from what looks like Next.js produces wrong code every time.

Spiceflow

A project uses spiceflow if anything imports from spiceflow or spiceflow/react, or constructs new Spiceflow(). The API surface is small but very opinionated, and the opinions are NOT guessable. Every framework has its own answer for forms, pending state, error display, and redirects; spiceflow's answers are frequently different from Next.js and from React defaults. Writing spiceflow code from memory, or from what "looks like Next.js", produces wrong code every time.

How the docs work

Documentation lives at https://getspiceflow.com. Append .md to any page URL to get raw markdown. Fetch the docs index first if you have not read it this session:

bash
curl -s https://getspiceflow.com/llms.txt

https://getspiceflow.com/llms-full.txt contains every doc in one file, and https://getspiceflow.com/docs.zip downloads all markdown files for local grepping.

Read every fetched doc completely, with no truncation. Never pipe to head, tail, or sed. Source code and runnable examples (example-* folders) live in the repo: https://github.com/remorses/spiceflow — read the code there when the docs are not enough.

ALWAYS read the feature doc before writing code

Before touching code for a feature, fetch its doc in full. One page per branch:

TaskFetch
API routes, Zod validation, json(), typed errors, middleware, serveStatic, CORS, streaming/SSE, .onError(), listen(), Node adapters, Next.js mount, waitUntil, base path, class instanceshttps://getspiceflow.com/api.md
Typed fetch client (createSpiceflowFetch), WebMCPhttps://getspiceflow.com/fetch-client.md
OpenAPI generationhttps://getspiceflow.com/openapi.md
MCP toolshttps://getspiceflow.com/mcp.md
Tracing / OpenTelemetryhttps://getspiceflow.com/tracing.md (Strada projects: https://getspiceflow.com/strada.md)
Custom serialization (Date, Map, Set, BigInt)https://getspiceflow.com/custom-serialization.md
RSC setup, Tailwind, shadcn, app entry, layouts, <Head> SEO, query params, "use client" components, code splitting, router, Link, redirects, ProgressBar, 404 pageshttps://getspiceflow.com/react.md
Loaders, useLoaderData, streaming with use(), forms, server actions, parseFormData, useActionState, ErrorBoundaryhttps://getspiceflow.com/react-data.md
SpiceflowRegister, knownPaths, multi-app workspaces, circular TS7022 errorshttps://getspiceflow.com/type-safety.md
Federation / remote componentshttps://getspiceflow.com/federation.md
Auth middleware, proxying, cookies, graceful shutdownhttps://getspiceflow.com/middleware-patterns.md
Securing actions and routeshttps://getspiceflow.com/security.md
Migrating from Remix / React Routerhttps://getspiceflow.com/migrate-from-remix.md
Cloudflare Workers (setup, bindings, KV caching, edge cache)https://getspiceflow.com/cloudflare.md
Deploy skew, cross-deployment behaviorhttps://getspiceflow.com/deployment-skew.md
Service bindingshttps://getspiceflow.com/service-bindings.md
Dockerhttps://getspiceflow.com/docker.md
Dependency crashes with useState is undefined at startuphttps://github.com/remorses/spiceflow/blob/main/docs/use-client-trap.md

Testing spiceflow apps

Before writing any vitest tests for a spiceflow app, ALWAYS read the testing guide first:

bash
curl -s https://getspiceflow.com/testing.md

Reference examples: example-vitest (API routes, pages, actions, DI, tracing spans) and example-vitest-cloudflare (tests inside workerd with D1 and KV).

Show full SKILL.md (352 more words)Show less

Non-negotiable rules

These are the landmines that break apps when guessed. Each links to its full doc.

  • Always use Link from spiceflow/react, never raw <a>, for links. Link auto-prepends the Vite base path; never prepend it manually. Raw fetch() and Response.redirect() still need manual base handling. → navigation
  • <Head> is server-only. It records children during the RSC render; a 'use client' module never runs there, so a <Head> inside one contributes nothing (and importing it fails the build). Put <Head> in .page() / .layout() handlers. Use document.title in an effect for client-side title changes. → pages & layouts
  • Always throw redirect(...), never return redirect(...). Applies to .page(), .layout(), .loader(), .get(), .post(), server actions, and middleware. → navigation
  • Never call router.refresh() after a server action. Successful actions already re-run loaders and reconcile the page. All navigation and refresh methods are fire-and-forget; never await a navigation commit inside a React form action (it can deadlock). → forms & actions
  • Server actions and API routes are public endpoints. CSRF Origin checks do not authenticate the caller; every mutating action must read and verify a session or token itself via getActionRequest(). → security
  • Typed fetch client: use :param paths with a params object (never interpolate IDs), return plain objects or json(...) from handlers (never return new Response(...)), pass body as a plain object, and check results with instanceof Error. → fetch client
  • Pass an OTel tracer in production apps (new Spiceflow({ tracer })) so handlers get span and tracer on the context. → tracing
  • One spiceflow copy per monorepo. Mismatched or duplicated versions cause Types have separate declarations of a private property. Fix with pnpm update -r spiceflow then pnpm dedupe (or npm update spiceflow --workspaces / bun update -r spiceflow). → fetch client
  • Circular TS7022 errors happen when a SpiceflowRegister-typed API (router.href(), createSpiceflowFetch(), useLoaderData()) appears in a handler return value in the app entry. JSX, throw, event handlers, and separate files are always safe. → type safety
  • Always 301 www to the apex in one hop on new custom-domain sites. Point www.example.com at the same Cloudflare worker (custom_domain). Redirect www → https://example.com + path + query with status 301. Never leave www on Vercel/Pages. Never use 307. Never chain http://www → https://www → apex.
ts
.use(({ request }, next) => {
  const url = new URL(request.url)
  if (!url.hostname.startsWith('www.')) return next()
  url.hostname = url.hostname.slice('www.'.length)
  url.protocol = 'https:'
  throw redirect(url.toString(), { status: 301 })
})

© remorses, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/spiceflow of remorses/spiceflow.

Open the folder on GitHubat commit 24643b8

Compare with similar skills

Spiceflow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spiceflow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spiceflow this skillremorses/spiceflow167—~1.9kAutomated safety check: PassMIT
Posthog SDK Patternsjeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: PassMIT
Typescriptericrisco/rsc-harness167—~2.8kAutomated safety check: PassMIT
Api2clialexknowshtml/api2cli455—~2.9kAutomated safety check: PassMIT
Javascript SDKaiskillstore/marketplace4301 repos~3.3kAutomated safety check: PassNone
Workos Widgetsusenotra/notra256—~2kAutomated safety check: PassAGPL-3.0

Similar skills

  • Posthog SDK Patterns

    jeremylongshore/tons-of-skills-marketplace

    Implement typed, lifecycle-safe PostHog SDK adapters for browser, Node.js, React, Next.js, or Python.

    2.8k GitHub stars~2.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Typescript

    ericrisco/rsc-harness

    A skill your agent uses when writing or fixing TypeScript type code (.ts/.tsx/.d.ts), modeling data with generics/unions/branded types, diagnosing narrowing failures, or configuring tsconfig and the…

    167 GitHub stars~2.8k tokensUpdated today
    DatabasesAuto-check passed
  • Api2cli

    alexknowshtml/api2cli

    Generate a working CLI from any API, then wrap it in a Claude Code skill.

    455 GitHub stars~2.9k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Javascript SDK

    aiskillstore/marketplace

    JavaScript/TypeScript SDK for inference.sh - run AI apps, build agents, integrate with all models.

    430 GitHub starsUsed in 1 repo~3.3k tokens
    Backend & APIsAuto-check passed
  • Workos Widgets

    usenotra/notra

    A skill your agent uses when the user is implementing, embedding, or debugging a WorkOS Widget — specifically the User Management, User Profile, Admin Portal SSO Connection, or Admin Portal Domain…

    256 GitHub stars~2k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Type Safety

    idavidov13/agentic-playwright

    TypeScript type safety conventions for the Playwright scaffold — the "no any" rule, Zod 4 schema patterns (z.strictObject, top-level validators like z.uuid / z.email / z.url / z.int / z.enum)…

    223 GitHub stars~3.5k tokensUpdated 7 days ago
    Testing & QAAuto-check passed

Categories

Questions about Spiceflow

What does Spiceflow do?

Spiceflow is a super simple, fast, and type-safe API and React Server Components framework for TypeScript. Spiceflow is an agent skill from remorses/spiceflow. Spiceflow is a super simple, fast, and type-safe API and React Server Components framework for TypeScript.

When should I use Spiceflow?

Spiceflow fits situations like: tasks that involve OpenAPI specifications; tasks that involve Type safety.

How do I install Spiceflow in Claude Code?

Run `npx skills add remorses/spiceflow --skill spiceflow -a claude-code`. Or copy the skill folder (skills/spiceflow in remorses/spiceflow) into .claude/skills/spiceflow in your project. Claude Code loads it when a task matches its description.

How do I install Spiceflow in Codex?

Run `npx skills add remorses/spiceflow --skill spiceflow -a codex`. Or copy the skill folder (skills/spiceflow in remorses/spiceflow) into .agents/skills/spiceflow in your project. Codex loads it when a task matches its description.

Can I use Spiceflow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add remorses/spiceflow --skill spiceflow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spiceflow, .gemini/skills/spiceflow, .github/skills/spiceflow and .opencode/skills/spiceflow in your project.

What does Spiceflow need to run?

Going by SKILL.md and its folder, Spiceflow needs the command-line tools its instructions call (curl, pnpm, npm and bun). Our summary lists: Node.js; Docker.

Does Spiceflow access the network?

SKILL.md names 1 domain. In commands or code: getspiceflow.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Spiceflow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Spiceflow use?

Spiceflow is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spiceflow use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Spiceflow?

Skills that share tags, products or a category with Spiceflow: Posthog SDK Patterns (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Typescript (ericrisco/rsc-harness, 167 stars), Api2cli (alexknowshtml/api2cli, 455 stars) and Javascript SDK (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spiceflow?

remorses (a GitHub user) maintains it in remorses/spiceflow, which has 167 GitHub stars. The repository was last updated on October 6, 2026.

Source: remorses/spiceflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.