Agent skill

Nuxt Agent Ready Best Practices

by vinayakkulkarni in vinayakkulkarni/nxui

Nuxt agent-readiness guidelines for making a site operable by autonomous AI agents — not just cited by them.

MITAuto-check passedAgent Workflows

Install Nuxt Agent Ready Best Practices

skills CLI
$ npx skills add vinayakkulkarni/nxui --skill nuxt-agent-ready-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayakkulkarni/nxui nuxt-agent-ready-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayakkulkarni/nxui.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nuxt-agent-ready-best-practices .claude/skills/nuxt-agent-ready-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nuxt-agent-ready-best-practices
GitHub stars
212
Token cost
~2.4k tokens
SKILL.md length
1,107 words
Files
15 (incl. scripts)
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Nuxt agent-readiness guidelines for making a site operable by autonomous AI agents — not just cited by them.

  • Works in 3 steps: auth.md is content-scanned for "agent… → The agent_auth block in… → WebMCP runs in a headless, no-GPU…
  • Tasks involving agent-ready
  • SKILL.md covers GEO vs Agent-Readiness (know…, When to Apply, THE HONESTY RULE (load-bearing… and THE SCANNER-BEHAVIOR RULES…, plus 4 more sections
  • Runs TypeScript scripts from its folder; calls wrangler; reaches isitagentready.com

What it does

Nuxt Agent Ready Best Practices is an agent skill from vinayakkulkarni/nxui. Nuxt agent-readiness guidelines for making a site operable by autonomous AI agents — not just cited by them. Covers the isitagentready.com standards: Markdown content negotiation, RFC 8288 Link headers, RFC 9727 API catalogs, Agent Skills discovery indexes, WebMCP browser tools, MCP Server Cards, OAuth/OIDC agent auth discovery, and DNS-AID. Triggers on tasks involving agent-ready, isitagentready, MCP, WebMCP, model context protocol, agent skills, API catalog, well-known discovery, agent auth, DNS-AID, A2A, or…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 16 other files, including scripts (for example `AGENTS.md`, `package.json` and `rules/_template.md`).

It sits in Agent Workflows, covering MCP servers and OAuth and OpenID Connect. It works with Model Context Protocol and Nuxt. The repository describes itself as: Beautiful animated components for Vue. Built with Tailwind CSS and motion-v. The licence is MIT.

When your agent uses it

  • Tasks involving agent-ready
  • Model context protocol
  • Well-known discovery
  • Agentic commerce

Example prompts

  • “/nuxt-agent-ready-best-practices”

Requirements

  • Node.js

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. auth.md is content-scanned for "agent registration markers", not just existence. A 200 response with a valid H1 and generic OAuth…
  2. The agent_auth block in /.well-known/oauth-authorization-server must use WorkOS field names. register_uri (not registration_uri), skill…
  3. WebMCP runs in a headless, no-GPU browser with an 8-second navigation timeout. If your page ships heavy client JS that keeps the network…

What it can do on your machine

Read from SKILL.md and the folder at commit 46001b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (TypeScript), which the agent can run.

    Shell commands in SKILL.md call:

    • wrangler

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • isitagentready.com

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nuxt Agent Ready Best Practices loads about 2.4k tokens when it runs. Until then it costs about 141 tokens; SKILL.md has 1,107 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~141
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from vinayakkulkarni/nxui at commit 46001b5, republished under its MIT licence (© vinayakkulkarni). 1,107 words, ~2,352 tokens.

Download SKILL.mdSave it as .claude/skills/nuxt-agent-ready-best-practices/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.
name
nuxt-agent-ready-best-practices
description
Nuxt agent-readiness guidelines for making a site operable by autonomous AI agents — not just cited by them. Covers the isitagentready.com standards: Markdown content negotiation, RFC 8288 Link headers, RFC 9727 API catalogs, Agent Skills discovery indexes, WebMCP browser tools, MCP Server Cards, OAuth/OIDC agent auth discovery, and DNS-AID. Triggers on tasks involving agent-ready, isitagentready, MCP, WebMCP, model context protocol, agent skills, API catalog, well-known discovery, agent auth, DNS-AID, A2A, or agentic commerce.
license
MIT
metadata.author
vinayakkulkarni
metadata.version
1.1.0

Nuxt Agent-Ready Best Practices

Guidelines for making a Nuxt 4 site operable by autonomous AI agents — measured by the isitagentready.com scanner (Cloudflare's "Is Your Site Agent-Ready?"). This is a different axis from GEO: GEO is about being cited in AI answers; agent-readiness is about being operated — an agent authenticating, discovering your API, calling your tools, and taking action.

Proven on production Nuxt 4 + Nitro cloudflare_module Workers:

  • A marketing site (only public POST endpoints, no auth/MCP server): 21 → 50+ (Level 1 → Level 4 "Agent-Integrated") — the auth + MCP surfaces are honesty-gated OFF (see below).
  • A full platform with a real OAuth server (Better-Auth oauth-provider) + a real remote MCP server: 21 → 100/100 (Level 5 "Agent-Native"), all 14 checks green. The auth + MCP surfaces are legitimately publishable there, which is what unlocks the last ~40 points.

The ceiling is set by what you actually run, not by effort. A marketing site tops out around Level 4 and that is the correct score — do not fabricate an auth server to chase 100 (see THE HONESTY RULE). Only a site with a real authorization server and a real MCP server can honestly reach Level 5.

GEO vs Agent-Readiness (know the difference)

GEO (nuxt-geo-best-practices)Agent-Readiness (this skill)
GoalBe cited in AI answersBe operated by agents
Question"Will ChatGPT mention me?""Can an agent call my tools and act?"
Leversllms.txt, crawler allowlist, RAG content, JSON-LD entitiesMCP/WebMCP, API/skill discovery, agent auth, DNS-AID, agentic commerce

Shared primitives live in the GEO skill. robots.txt AI-crawler allowlisting, llms.txt/llms-full.txt, and the XML sitemap are covered by nuxt-geo-best-practices (rules ai-robots-allowlist, ai-llms-txt, ai-sitemap). The isitagentready scanner scores those too — set them up via the GEO skill first, then apply this skill for the agent-operation layer on top.

When to Apply

  • Raising a site's score on https://isitagentready.com/<domain>
  • Supporting Accept: text/markdown content negotiation for agents
  • Advertising resources via RFC 8288 Link headers
  • Publishing an RFC 9727 API catalog (/.well-known/api-catalog)
  • Publishing an Agent Skills discovery index (/.well-known/agent-skills/index.json)
  • Exposing site actions to in-browser agents via WebMCP (navigator.modelContext)
  • Publishing an MCP Server Card (only if you run a real MCP server)
  • Publishing OAuth/OIDC discovery for agent auth (only if you run a real auth server)
  • Publishing DNS-AID records (_index._agents.<domain>) + DNSSEC

THE HONESTY RULE (load-bearing — read before publishing anything)

Only publish discovery for services that actually exist. A discovery document that sends an agent to a dead end — a /.well-known/openid-configuration with no auth server behind it, an MCP Server Card whose transport endpoint 404s, a _mcp._agents DNS record with no MCP server — is worse than a lower score. Agents will try to use it and fail.

This mirrors the "never fake customers/logos/scale" rule: a fabricated capability that fails on first contact destroys trust. On a marketing site with only public POST endpoints, skip OAuth/OIDC discovery, oauth-protected-resource, auth.md, and the MCP Server Card — they belong on the app/console domain (real auth server) or require building a real MCP server. Decline these explicitly and say why.

The flip side — when you DO run the real thing, publish it fully. If your site runs a real OAuth authorization server (e.g. Better-Auth oauth-provider plugin) and a real remote MCP server, the auth + MCP surfaces are no longer dishonest — they are the highest-value checks and unlock Level 5. maps.guru scored 100/100 precisely because those services exist. The honesty rule cuts both ways: don't fake it, but don't under-claim a real capability either.

THE SCANNER-BEHAVIOR RULES (what actually flips a check green)

Passing the harder checks is NOT "publish the file and move on" — the isitagentready scanner inspects content and runtime behavior, not just presence. Three non-obvious behaviors cost real time to discover:

  1. auth.md is content-scanned for "agent registration markers", not just existence. A 200 response with a valid H1 and generic OAuth instructions still FAILS with "auth.md exists but does not describe agent registration". The body must follow the WorkOS AUTH.md recipe shape — "You are an agent", "agentic registration", the ordered discover → register → authorize → exchange → revoke steps, and references to register_uri/agent_auth. See auth-oauth-discovery for the exact markers.

  2. The agent_auth block in /.well-known/oauth-authorization-server must use WorkOS field names. register_uri (not registration_uri), skill, identity_types_supported with valid values, plus one complete method (e.g. anonymous.credential_types_supported + claim_uri). Intuitive names silently fail the check.

  3. WebMCP runs in a headless, no-GPU browser with an 8-second navigation timeout. If your page ships heavy client JS that keeps the network busy (a live MapLibre/WebGL map streaming tiles), the checker never reaches networkidle and reports "Could not check WebMCP: Navigation timeout" — even though your tools ARE registered. Fix: skip the heavy widget when navigator.webdriver === true (bots get a static fallback; humans get the full experience). See discovery-webmcp.

Show full SKILL.md (339 more words)Show less

SECURITY HARDENING (do this BEFORE you publish, not after)

Publishing agent-discovery surfaces widens your attack surface: you're advertising a public API key to every page + browser agent, echoing request data into markdown, and adding new well-known routes. Run a security pass on the new surfaces — see the security-hardening rule. The load-bearing items: the page-embedded system API key MUST be origin-restricted and owned by a non-privileged account (an admin-owned key bypasses quota on every worker); WebMCP tool errors must never echo the key; htmlToMarkdown must not decode <>"' entities (indirect XSS); and the Link header must be skipped on /api/** responses.

THE NITRO/WORKERS GOTCHA (self-referential renders)

Several checks require "render my own page, then transform it" (llms-full.txt aggregation, markdown negotiation). On a deployed Cloudflare Worker, an absolute-URL $fetch('https://<origin>/path') becomes a real edge subrequest that returns empty on the same-zone self-loopback — but it works on wrangler dev (single local server), so the bug is invisible until production.

Always use relative in-process event.$fetch(path, { headers }) — Nitro's internal router, no network hop, identical on dev and prod. Works in both route handlers and middleware. This silently served an empty 81-byte llms-full.txt in production for weeks before it was caught.

Verification Discipline

  1. Build + boot on wrangler dev (workerd); curl each route/header.
  2. CRITICAL: verify on PRODUCTION after deploy — the self-$fetch bug only manifests in prod. Confirm llms-full.txt is full-size (not ~81 bytes) and markdown negotiation returns text/markdown.
  3. Fetch each check's hosted SKILL.md at https://isitagentready.com/.well-known/agent-skills/<check>/SKILL.md for the exact record/format the scanner validates.
  4. Re-scan isitagentready.com/<domain> to confirm the category flipped green. The scan API is POST https://isitagentready.com/api/scan {"url":"https://<domain>"} → check checks.<category>.<check>.status === "pass".

Rule Categories

  • discovery — Link headers, API catalog, agent-skills index, markdown negotiation, WebMCP, MCP server card, DNS-AID
  • content — markdown content negotiation
  • auth — OAuth/OIDC + protected-resource + auth.md content-markers + agent_auth block (honesty-gated)
  • dns — DNS-AID records + DNSSEC
  • security — hardening the new agent surfaces (origin-restricted public key, error sanitization, entity encoding, Link-skip on /api)

Commerce checks (x402, MPP, UCP, ACP) are informational-only on non-commerce sites and do NOT affect the score — skip them unless the site actually sells to agents.

© vinayakkulkarni, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 14 other files (scripts) in .agents/skills/nuxt-agent-ready-best-practices of vinayakkulkarni/nxui.

  • SKILL.md
  • AGENTS.md
  • package.json
  • rules/_template.md
  • rules/auth-oauth-discovery.md
  • rules/content-markdown-negotiation.md
  • rules/discovery-agent-skills-index.md
  • rules/discovery-api-catalog.md
  • rules/discovery-link-headers.md
  • rules/discovery-mcp-server-card.md
  • rules/discovery-webmcp.md
  • rules/dns-aid.md
  • rules/security-hardening.md
  • scripts/build.ts
  • scripts/validate.ts

Open the folder on GitHubat commit 46001b5

Compare with similar skills

Nuxt Agent Ready Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nuxt Agent Ready Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nuxt Agent Ready Best Practices this skillvinayakkulkarni/nxui212—~2.4kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Building MCP Server On CloudflareCommandCodeAI/agent-skills133—~1.5kAutomated safety check: PassMIT
Nv Onboard Dcr MCPnovuhq/novu40k—~1.8kAutomated safety check: PassCustom licence
GitLab CLI Without MCPzereight/gitlab-mcp2k—~787Automated safety check: PassMIT
Add MCP Integrationvellum-ai/vellum-assistant1.4k—~2.8kAutomated safety check: PassMIT

Similar skills

  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Building MCP Server On Cloudflare

    CommandCodeAI/agent-skills

    Builds remote MCP (Model Context Protocol) servers on Cloudflare Workers with tools, OAuth authentication, and production deployment.

    133 GitHub stars~1.5k tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed
  • Onboard a new DCR OAuth MCP catalog entry with provider-doc vetting and curl probes.

    40k GitHub stars~1.8k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • GitLab CLI Without MCP

    zereight/gitlab-mcp

    Authenticates and runs zereight-mcp-gitlab as a plain command line tool to read GitLab merge requests, diffs, discussions, issues and pipelines when no MCP client is set up.

    2k GitHub stars~787 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Add MCP Integration

    vellum-ai/vellum-assistant

    Add a vendor's remote MCP server to the bundled integrations catalog (plugins/mcp-catalog/<name/ + plugins/marketplace.json) so users can connect it from the Integrations page.

    1.4k GitHub stars~2.8k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Official

    Add a third-party MCP server (Linear, Notion, GitHub, ...) to the PostHog MCP store catalog.

    40k GitHub stars~1.6k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from vinayakkulkarni/nxui

  • Nuxt Best Practices

    vinayakkulkarni/nxui

    Nuxt 4 performance optimization and architecture guidelines (current through Nuxt 4.5) for building fast, maintainable full-stack applications.

    212 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Nuxt Geo Best Practices

    vinayakkulkarni/nxui

    Nuxt GEO (Generative Engine Optimization) guidelines for getting cited by ChatGPT, Perplexity, Claude, Google AI Overviews, and Gemini.

    212 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Nuxt SEO Best Practices

    vinayakkulkarni/nxui

    Nuxt SEO optimization guidelines for Cloudflare-deployed applications.

    212 GitHub stars~819 tokensUpdated 2 days ago
    Auto-check passed
  • Vue Best Practices

    vinayakkulkarni/nxui

    Vue.js performance optimization guidelines for building fast, maintainable applications.

    213 GitHub stars~871 tokensUpdated 2 days ago
    Auto-check passed
  • Nxui Design

    vinayakkulkarni/nxui

    Project-level design skill for nxui (nxui.geoql.in). An agent skill from vinayakkulkarni/nxui.

    212 GitHub stars~2.8k tokensUpdated 2 days ago
    Auto-check passed

Questions about Nuxt Agent Ready Best Practices

What does Nuxt Agent Ready Best Practices do?

Nuxt agent-readiness guidelines for making a site operable by autonomous AI agents — not just cited by them. Nuxt Agent Ready Best Practices is an agent skill from vinayakkulkarni/nxui. Nuxt agent-readiness guidelines for making a site operable by autonomous AI agents — not just cited by them.

When should I use Nuxt Agent Ready Best Practices?

Nuxt Agent Ready Best Practices fits situations like: tasks involving agent-ready; model context protocol; well-known discovery; agentic commerce.

How do I install Nuxt Agent Ready Best Practices in Claude Code?

Run `npx skills add vinayakkulkarni/nxui --skill nuxt-agent-ready-best-practices -a claude-code`. Or copy the skill folder (.agents/skills/nuxt-agent-ready-best-practices in vinayakkulkarni/nxui) into .claude/skills/nuxt-agent-ready-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Nuxt Agent Ready Best Practices in Codex?

Run `npx skills add vinayakkulkarni/nxui --skill nuxt-agent-ready-best-practices -a codex`. Or copy the skill folder (.agents/skills/nuxt-agent-ready-best-practices in vinayakkulkarni/nxui) into .agents/skills/nuxt-agent-ready-best-practices in your project. Codex loads it when a task matches its description.

Can I use Nuxt Agent Ready Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayakkulkarni/nxui --skill nuxt-agent-ready-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nuxt-agent-ready-best-practices, .gemini/skills/nuxt-agent-ready-best-practices, .github/skills/nuxt-agent-ready-best-practices and .opencode/skills/nuxt-agent-ready-best-practices in your project.

What does Nuxt Agent Ready Best Practices need to run?

Going by SKILL.md and its folder, Nuxt Agent Ready Best Practices needs TypeScript for the scripts in its folder and the command-line tools its instructions call (wrangler). Our summary lists: Node.js.

Does Nuxt Agent Ready Best Practices access the network?

SKILL.md names 2 domains. In commands or code: isitagentready.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Nuxt Agent Ready Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Nuxt Agent Ready Best Practices use?

Nuxt Agent Ready Best Practices is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nuxt Agent Ready Best Practices use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nuxt Agent Ready Best Practices?

Skills that share tags, products or a category with Nuxt Agent Ready Best Practices: MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars), Building MCP Server On Cloudflare (CommandCodeAI/agent-skills, 133 stars), Nv Onboard Dcr MCP (novuhq/novu, 40k stars) and GitLab CLI Without MCP (zereight/gitlab-mcp, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nuxt Agent Ready Best Practices?

vinayakkulkarni (a GitHub user) maintains it in vinayakkulkarni/nxui, which has 212 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.

Source: vinayakkulkarni/nxui on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.