Agent skill

No UI Flash

by vvedantb in vvedantb/eva

A skill your agent uses when an SPA or SSR app flashes the wrong UI before client-side data resolves — an app-shell skeleton shown to visitors who get bounced to login, a results skeleton before "no…

MITAuto-check: warningsFrontend & Design

Install No UI Flash

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add vvedantb/eva --skill no-ui-flash -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vvedantb/eva no-ui-flash --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vvedantb/eva.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/no-ui-flash .claude/skills/no-ui-flash && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
no-ui-flash
GitHub stars
101
Used in
1 other repo
Token cost
~1.9k tokens
SKILL.md length
1,116 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when an SPA or SSR app flashes the wrong UI before client-side data resolves — an app-shell skeleton shown to visitors who get bounced to login, a results skeleton before "no…

  • SSR app flashes the wrong UI before client-side data resolves — an app-shell skeleton shown to visitors who get bounced to login
  • SKILL.md covers Layer 1 — resolve the state at…, Layer 2 — a hint cookie for…, Layer 3 — the client fallback… and Redirect-back (returnTo) for…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • A results skeleton before no results found

What it does

No UI Flash is an agent skill from vvedantb/eva. Use when an SPA or SSR app flashes the wrong UI before client-side data resolves — an app-shell skeleton shown to visitors who get bounced to login, a results skeleton before "no results found", a light-theme flash before dark mode, a generic placeholder that swaps to something jarringly different. Covers resolving state at the edge/server, optimistic hint cookies, redirect-back (returnTo) flows, and how to test the loading window.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Frontend & Design, covering Theming and dark mode. The repository describes itself as: Orchestrate sandboxed agents that run in the cloud while you work. The licence is MIT.

When your agent uses it

  • SSR app flashes the wrong UI before client-side data resolves — an app-shell skeleton shown to visitors who get bounced to login
  • A results skeleton before no results found
  • A light-theme flash before dark mode
  • A generic placeholder that swaps to something jarringly different

Example prompts

  • “no results found”
  • “/no-ui-flash”

What it can do on your machine

Read from SKILL.md and the folder at commit a5a4df2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

No UI Flash loads about 1.9k tokens when it runs. Until then it costs about 112 tokens; SKILL.md has 1,116 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:3
    ifferent. Covers resolving state at the edge/server, optimistic hint cookies, redirect-back (returnTo) flows, and how to

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vvedantb/eva at commit a5a4df2, republished under its MIT licence (© vvedantb). 1,116 words, ~1,920 tokens.

Download SKILL.mdSave it as .claude/skills/no-ui-flash/SKILL.md (or your agent's skills folder).
name
no-ui-flash
description
Use when an SPA or SSR app flashes the wrong UI before client-side data resolves — an app-shell skeleton shown to visitors who get bounced to login, a results skeleton before "no results found", a light-theme flash before dark mode, a generic placeholder that swaps to something jarringly different. Covers resolving state at the edge/server, optimistic hint cookies, redirect-back (returnTo) flows, and how to test the loading window.

Never flash the wrong UI

Client-rendered apps have a window between first paint and the moment client-side data resolves. The classic bug is filling that window with a placeholder that bets on one outcome — and losing the bet:

  • An app-shell skeleton (sidebar, nav, content cards) shown to a signed-out visitor who is about to be bounced to login. They're shown an app they'll never reach, then a jarring swap.
  • A results-grid skeleton on a search/list page that resolves to "no results found" — the skeleton promised content that doesn't exist.
  • A light-theme first paint that snaps to dark once a preference loads.
  • A skeleton for a route that turns out to be a 404.

The rule: render the placeholder for the state you have verified, not the state you hope for. When you can't verify, render a placeholder that's correct in every outcome (neutral, layout-stable) — not the happy path's. Getting there is three layers; each makes the next one's job smaller.

Layer 1 — resolve the state at the edge, before the document is served

The server/edge that serves the SPA's HTML usually already holds what the client will spend a round trip discovering. Use it there:

  • Auth: most session schemes verify with no upstream round trip — sealed/signed cookies verify with local crypto, JWTs against a cached JWKS. Gate document requests: signed out → 302 /login?returnTo=<path> before any app HTML exists. The wrong shell can't flash if it's never served. Anyone who receives the SPA at a gated path is now known to be signed in — which makes the client's skeleton honest again.
  • Data-shaped states: if the edge can cheaply answer "empty vs. populated" (a count, a KV flag, a cookie recording last-known state), it can serve the right variant — empty-state HTML, the populated shell, a redirect to onboarding — instead of a one-skeleton-fits-all document.
  • Preferences (theme, locale, density): read the preference cookie at the edge and serve the correct variant in the initial HTML. A class on <html> beats a client-side flip.

Edge cases that bite (described for auth, but they generalize to any cookie-carried state):

  • Gate document navigations only (GET/HEAD with sec-fetch-dest: document, falling back to Accept: text/html). API routes, module requests, and health probes answer for themselves.
  • Clear invalid state carriers, don't just route around them. A cookie that fails validation is worse than none — anything keyed on its presence keeps misbehaving until it's gone. Expire it on the response.
  • Persist anything the check rotated. If verification refreshed a token, the new value MUST reach the browser on this response — refresh tokens are typically single-use, and dropping the rotation silently breaks the session later. Applies on the serve path, not just redirects.
  • Failures inside the edge check collapse to the safe state (signed out, default theme), never to a 500.

Whatever the client normally learns from its first probe (/me, first search, preferences fetch), snapshot it into a non-HttpOnly cookie so the next load paints correctly without waiting:

  • The client writes it whenever the server confirms the state, and reads it on the next load to seed an optimistic version while the probe is in flight. (Auth: identity display data. Search/list: "this account has data" or last result count. Theme: the resolved preference.)
  • It is a hint, never an authority. Real authorization and real data still come from the server; a stale or forged hint can only change which placeholder briefly renders. Keep the payload to display data the user already knows; schema-validate on read and treat anything malformed as absent.
  • The resolved probe always wins — reconcile the moment it lands.
  • Clear it everywhere the underlying state dies (logout, account wipe, preference reset) — server-side on those responses, and client-side when a probe contradicts it. A hint that outlives its truth paints the wrong UI confidently.
  • In an SSR/hydrating app, read the cookie after mount (effect/state), not during the first render — the first client render must match the server HTML. The flip costs one frame, not a round trip.

With layers 1+2, the client's "loading" placeholder is only reachable in states where it's genuinely correct (e.g. a verified user's first visit on a new browser) — so the optimistic skeleton is finally honest.

Show full SKILL.md (417 more words)Show less

Layer 3 — the client fallback becomes a safety net

The in-app state gate no longer handles fresh loads; it handles mid-session change (logout in another tab, expiry, data deleted elsewhere):

  • On a state that invalidates the current UI, transition via a full navigation and render something neutral (a blank themed screen) for the moment that takes — never the placeholder of the UI they just lost.
  • Unknown routes need a real 404 page, not the shell or skeleton. If there's no notFound route, the fallback is probably the thing accidentally rendering a skeleton for garbage URLs — check.

Redirect-back (returnTo) for gates that bounce

If the edge redirects (login, onboarding), deep links must survive the detour. Resist adding a second cookie for it — if the flow is OAuth-shaped, the state parameter already round-trips through the provider verbatim and is already authenticated by the CSRF check (state pinned in a cookie, compared timing-safe at the callback). Ride along: state = base64url(JSON { nonce, returnTo }). One value, one cookie, and an attacker can't swap the destination without breaking the comparison.

Wherever a returnTo enters (gate query, login page, callback's decoded state), validate it as a same-origin relative path: starts with /, not // (protocol-relative is an absolute URL in disguise), and not an API path. Anything else falls back to /. Decoding must be total — providers send callbacks with state you never minted; junk reads as "no returnTo", never a throw.

Testing the loading window

The bug lives in a timing window, so the test must hold the window open:

  • Intercept the probe and delay it (e.g. Playwright page.route on /me or the search endpoint with a sleep). Assert what is painted during the delay: for the bounced visitor, the destination page with zero skeleton elements; for the hinted user, the real UI — plus a flag proving the probe had not resolved when it painted.
  • Drive the full redirect round trip over the wire: gated deep link → redirect carrying returnTo → provider → callback → lands on the deep link. Then the forged version: an off-origin returnTo completes the flow but lands on /.
  • Assert cookie hygiene as Set-Cookie headers: invalid state carrier → cleared (Max-Age=0) alongside its hint; the death event (logout etc.) → both gone.
  • Drive the rotation path without waiting out expiry: if the carrier is a sealed cookie, unseal it with the same library the server uses, corrupt the inner token's signature, reseal. The edge sees invalid-but-refreshable: assert the page is served, the rotated value is set on the response, and the spent one is refused on replay.

© vvedantb, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/no-ui-flash of vvedantb/eva.

Open the folder on GitHubat commit a5a4df2

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in vvedantb/eva, which our catalogue first saw on October 7, 2026.

Compare with similar skills

No UI Flash next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

No UI Flash compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
No UI Flash this skillvvedantb/eva1011 repos~1.9kAutomated safety check: WarnMIT
Impeccablebestofjs/bestofjs3.1k27 repos~2.6kAutomated safety check: PassMIT
Figma Design System Builderwarpdotdev/warp65k2 repos~4.4kAutomated safety check: PassAGPL-3.0
Tailwindcss Developmentanonaddy/anonaddy4.9k10 repos~865Automated safety check: PassMIT
UI StylingOhh-889/skyroc79513 repos~2.5kAutomated safety check: PassMIT
MCP Developmentcoollabsio/coolify63k1 repos~949Automated safety check: PassMIT

Similar skills

  • Impeccable

    bestofjs/bestofjs

    A skill your agent uses when the user wants to design, redesign, shape, critique, audit, polish, clarify, distill, harden, optimize, adapt, animate, colorize, extract, or otherwise improve a…

    3.1k GitHub starsUsed in 27 repos~2.6k tokens
    Frontend & DesignAuto-check passed
  • Builds or updates a design system in Figma from a codebase in ordered phases: discovery, variables and tokens, components, theming and documentation, with checkpoints.

    65k GitHub starsUsed in 2 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • Tailwindcss Development

    anonaddy/anonaddy

    Always invoke when the user's message includes 'tailwind' in any form.

    4.9k GitHub starsUsed in 10 repos~865 tokens
    Frontend & DesignAuto-check passed
  • UI Styling

    Ohh-889/skyroc

    Create beautiful, accessible user interfaces with shadcn/ui components (built on Radix UI + Tailwind), Tailwind CSS utility-first styling, and canvas-based visual designs.

    795 GitHub starsUsed in 13 repos~2.5k tokens
    Frontend & DesignAuto-check passed
  • MCP Development

    coollabsio/coolify

    A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 1 repo~949 tokens
    Frontend & DesignAuto-check passed
  • UI UX Pro Max

    saoudi-h/solar-icons

    UI/UX design intelligence for web and mobile. An agent skill from saoudi-h/solar-icons.

    186 GitHub starsUsed in 18 repos~11k tokens
    Frontend & DesignAuto-check: notes

More from vvedantb/eva

All 23 skills in this repo
  • Eva Feature Demo

    vvedantb/eva

    Record a real agent-browser screencast of one eva feature being used end to end, convert it to an X-ready mp4, and write a tweet for it.

    101 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Animate

    vvedantb/eva

    Build an animation from scratch, making the decisions in the order that determines whether it feels right — should it animate at all, what purpose, which tool, which properties, which curve and…

    101 GitHub starsUsed in 6 repos~2.9k tokens
    Auto-check passed
  • Design and build Convex components with clear boundaries, isolated state, and app-facing wrappers.

    101 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Grab a single clean HD screenshot of a new eva feature from the real running app (Playwright at deviceScaleFactor 2, 1280 layout captured crisp at 2560×1440, dev overlays hidden) and write a tweet…

    101 GitHub stars~3.2k tokensUpdated today
    Auto-check: notes
  • Code Structure

    vvedantb/eva

    A skill your agent uses when multiple workflows duplicate the same operational logic, when deciding what belongs in actions vs shared services, or when refactoring repeated operational blocks across…

    101 GitHub starsUsed in 2 repos~1.1k tokens
    Auto-check passed
  • Eva Launch Video

    vvedantb/eva

    Produce polished, mobile-friendly product demo videos of the eva app with Remotion — 1280×720, snappy beat-synced hard cuts, lo-fi music that swells on every cut, and footage captured from the REAL…

    101 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Questions about No UI Flash

What does No UI Flash do?

A skill your agent uses when an SPA or SSR app flashes the wrong UI before client-side data resolves — an app-shell skeleton shown to visitors who get bounced to login, a results skeleton before "no…. No UI Flash is an agent skill from vvedantb/eva. Use when an SPA or SSR app flashes the wrong UI before client-side data resolves — an app-shell skeleton shown to visitors who get bounced to login, a results skeleton before "no results found", a light-theme flash before dark mode, a generic placeholder that swaps to something jarringly different.

When should I use No UI Flash?

No UI Flash fits situations like: SSR app flashes the wrong UI before client-side data resolves — an app-shell skeleton shown to visitors who get bounced to login; A results skeleton before no results found; A light-theme flash before dark mode; A generic placeholder that swaps to something jarringly different.

How do I install No UI Flash in Claude Code?

Run `npx skills add vvedantb/eva --skill no-ui-flash -a claude-code`. Or copy the skill folder (.agents/skills/no-ui-flash in vvedantb/eva) into .claude/skills/no-ui-flash in your project. Claude Code loads it when a task matches its description.

How do I install No UI Flash in Codex?

Run `npx skills add vvedantb/eva --skill no-ui-flash -a codex`. Or copy the skill folder (.agents/skills/no-ui-flash in vvedantb/eva) into .agents/skills/no-ui-flash in your project. Codex loads it when a task matches its description.

Can I use No UI Flash in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vvedantb/eva --skill no-ui-flash -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/no-ui-flash, .gemini/skills/no-ui-flash, .github/skills/no-ui-flash and .opencode/skills/no-ui-flash in your project.

What does No UI Flash need to run?

SKILL.md names no scripts, command-line tools or credentials: No UI Flash is instructions for the agent only.

Does No UI Flash access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is No UI Flash safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does No UI Flash use?

No UI Flash is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does No UI Flash use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to No UI Flash?

Skills that share tags, products or a category with No UI Flash: Impeccable (bestofjs/bestofjs, 3.1k stars), Figma Design System Builder (warpdotdev/warp, 65k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars) and UI Styling (Ohh-889/skyroc, 795 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains No UI Flash?

vvedantb (a GitHub user) maintains it in vvedantb/eva, which has 101 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 9, 2026.

Source: vvedantb/eva on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.