Distilled SDK
alchemy-run/distilled
Build or update a distilled SDK for an API provider — sourcing its OpenAPI/Smithy/GraphQL/discovery description, adding the spec mirror that feeds it, generating packages/<provider, listing it on…
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
$ npx skills add webhtv/webhtv --skill webhome-extension-builder -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install webhtv/webhtv webhome-extension-builder --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/webhtv/webhtv.git skills-src && mkdir -p .claude/skills && cp -r skills-src/webhome-devkit/skills/webhome-extension-builder .claude/skills/webhome-extension-builder && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "webhome-extension-builder" agent skill from https://github.com/webhtv/webhtv/tree/main/webhome-devkit/skills/webhome-extension-builder into .claude/skills/webhome-extension-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "webhome-extension-builder", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/webhtv/webhtv/tree/main/webhome-devkit/skills/webhome-extension-builderType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add webhtv/webhtv --skill webhome-extension-builder -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install webhtv/webhtv webhome-extension-builder --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/webhtv/webhtv.git skills-src && mkdir -p .agents/skills && cp -r skills-src/webhome-devkit/skills/webhome-extension-builder .agents/skills/webhome-extension-builder && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "webhome-extension-builder" agent skill from https://github.com/webhtv/webhtv/tree/main/webhome-devkit/skills/webhome-extension-builder into .agents/skills/webhome-extension-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "webhome-extension-builder", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add webhtv/webhtv --skill webhome-extension-builder -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install webhtv/webhtv webhome-extension-builder --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/webhtv/webhtv.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/webhome-devkit/skills/webhome-extension-builder .cursor/skills/webhome-extension-builder && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "webhome-extension-builder" agent skill from https://github.com/webhtv/webhtv/tree/main/webhome-devkit/skills/webhome-extension-builder into .cursor/skills/webhome-extension-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "webhome-extension-builder", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/webhtv/webhtv.git --path webhome-devkit/skills/webhome-extension-builder--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add webhtv/webhtv --skill webhome-extension-builder -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install webhtv/webhtv webhome-extension-builder --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/webhtv/webhtv.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/webhome-devkit/skills/webhome-extension-builder .gemini/skills/webhome-extension-builder && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "webhome-extension-builder" agent skill from https://github.com/webhtv/webhtv/tree/main/webhome-devkit/skills/webhome-extension-builder into .gemini/skills/webhome-extension-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "webhome-extension-builder", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install webhtv/webhtv webhome-extension-builderInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add webhtv/webhtv --skill webhome-extension-builder -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/webhtv/webhtv.git skills-src && mkdir -p .github/skills && cp -r skills-src/webhome-devkit/skills/webhome-extension-builder .github/skills/webhome-extension-builder && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "webhome-extension-builder" agent skill from https://github.com/webhtv/webhtv/tree/main/webhome-devkit/skills/webhome-extension-builder into .github/skills/webhome-extension-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "webhome-extension-builder", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add webhtv/webhtv --skill webhome-extension-builder -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install webhtv/webhtv webhome-extension-builder --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/webhtv/webhtv.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/webhome-devkit/skills/webhome-extension-builder .opencode/skills/webhome-extension-builder && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "webhome-extension-builder" agent skill from https://github.com/webhtv/webhtv/tree/main/webhome-devkit/skills/webhome-extension-builder into .opencode/skills/webhome-extension-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "webhome-extension-builder", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
webhome-extension-builderBuild, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
Webhome Extension Builder is an agent skill from webhtv/webhtv. Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages. Use when Codex is asked to create or improve WebHome extensions, webHomeExtensions, sites[].extensions, fm SDK scripts, native App play buttons, pan/magnet/native playback routing, fm.vodInline episode resolvers, TV remote focus helpers, WebHome extension manifests/configuration, JS/API/player reverse engineering for WebHome extensions, or Cloudflare/WAF feasibility diagnosis for…
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 28 other files, including scripts, reference files and assets (for example `agents/openai.yaml`, `assets/examples/dm.xueximeng.com.js` and `assets/examples/dm.xueximeng.manifest.json`).
It sits in Security, covering GraphQL and Reverse engineering and malware. It works with Cloudflare. The repository describes itself as: WebHomeTV 基于FongMi二次开发,增强了 WebHome 自定义首页、App Native SDK、网盘链接检测 和 Nostr推荐首页。 这个项目的核心目标是让 CSP 站点首页可以变成一个真正可开发的网页应用:开发者可以用 HTML/CSS/JavaScript 定制首页,再通过 App 暴露的 Native… The licence is GPL-3.0.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4e30ffa. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Webhome Extension Builder loads about 2.8k tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 143 tokens; SKILL.md has 1,324 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from webhtv/webhtv at commit 4e30ffa, republished under its GPL-3.0 licence (© webhtv). 1,324 words, ~2,815 tokens.
.claude/skills/webhome-extension-builder/SKILL.md (or your agent's skills folder). This skill also uses 24 other files; get the full folder from GitHub.Use this skill to produce production-ready WebHome extension scripts that enhance real websites loaded in the App WebView. Prefer small, site-specific enhancements over replacing the site: route verified resources to native playback, add clear App play controls, clean harmful UI, support TV focus, and keep the original site's search, filtering, login, pagination, and detail navigation intact.
Before writing a non-trivial script, read the relevant source material:
references/webhome-extension-guide.md: full WebHome extension guide and API reference. Read sections 4, 7, 9-15 for most scripts; read section 8 for fm.vodInline; read section 13 before final compatibility review.references/template-and-example-catalog.md: choose templates and example patterns.references/js-reverse-and-waf-workflow.md: read when the target requires hidden API/signature/player/resource discovery, runtime request capture, local JS reproduction, or Cloudflare/WAF diagnosis.assets/templates/*.js: copy or adapt the relevant template source instead of recreating the skeleton from memory.assets/examples/*.js and *.manifest.json: consult for full real-world patterns after choosing a strategy.scripts/probe_webhome_target.py: run on unknown remote targets before choosing direct homepage fetching, injected extension work, or an authorized backend path.Establish these facts from the user, local files, target HTML, browser inspection, or analyzer output:
cspKeyRegex such as ^site-key$.fm.vodInline episode playback.href, onclick, nearby text, copied text, API response, player constructor, encrypted page state, or runtime media requests.If page access is unavailable, ask for one of: target HTML, screenshots plus DOM snippets, or output from assets/templates/page-analyzer.js.
For login, PoW, browser safety checks, or shield/WAF pages that the user can legitimately pass, start a visible browser or attach to an App WebView with CDP/DevTools, have the user complete the interaction in that session, then capture the post-verification network, DOM, console, frames, and media evidence from the same session. Do not replace this with curl guessing, stealth automation, CAPTCHA solving, or cookie/clearance harvesting.
If the target is unknown or may be protected, first run python3 scripts/probe_webhome_target.py <url> from this skill. Treat waf-blocked as: direct fm.req scraping is not reliable; build an extension only if the App WebView can normally load the page. If the App WebView is also blocked, require authorized API access, owner-controlled proxying, or user-supplied HAR/HTML instead of attempting to bypass the challenge.
Choose the lowest-risk strategy that fits the page:
assets/templates/auto-resource-router.js.assets/templates/inject-play-buttons.js.assets/templates/pan-link-router.js; call fm.config() and only run fm.pan.check() when driveCheck is enabled.assets/templates/inline-episodes.js; register window.__fmWebHomeInlineResolver before calling fm.vodInline().assets/templates/media-sniffer.js during analysis, then keep only the specific hook/extraction logic required.references/js-reverse-and-waf-workflow.md; observe network and scripts first, add narrow hooks second, and use local Node reproduction only after real page evidence identifies the entry function.assets/templates/site-enhance-skeleton.js.assets/templates/tv-focus-helper.js as a dependency and declare depends.assets/templates/site-cleanup.js conservatively.Default to runAt: "document-end". Use document-start only for early hooks such as window.open, fetch, XMLHttpRequest, history routing, or player constructor wrapping, and make the script tolerate downgrade to document-end. Do not add stealth fingerprint patches, CAPTCHA solving, Cloudflare clearance harvesting, or token cracking to extension scripts.
Write one top-level IIFE with all site-specific values in CONFIG. Include these common helpers unless the chosen template already has them:
log() using GM_log first, console fallback second.whenFm() that waits for the fmsdk event.ready(fn) for DOM readiness.cleanText(), URL normalization, title fallback, and resource classification.MutationObserver, fmurlchange, and data-fm-* markers to avoid duplicate injection.Resource routing rules:
a[href]; only intercept elements classified as resources.try/catch or .catch().fm.play(url, title, { headers: { Referer: ... }, credentials: "include" }) for direct media.fm.pan.play({ type, url, password, title, pic, wallPic }) for pan, magnet, ed2k, thunder, jianpian, and generic push links. Pass the best known poster as pic and backdrop/still as wallPic; do not expect pic to become a playback background.fm.req() for JS/API reads that need native networking; use fm.res() for DOM media/image URLs that need the local resource gateway.UI and TV rules:
chromeMode: "edge" or immersive. In normal chrome after exiting fullscreen, remove the top reservation so the page does not show a blank row. Use fm.ui.getViewport() and fmviewport when available, write a fallback first, then use max(var(--fm-safe-top, 0px), env(safe-area-inset-top, 0px)); never add native --fm-safe-top and browser env() together.:focus styles, map OK/Enter to native .click() for custom focusables, and guard text inputs with readonly until confirmation.Assume old Android WebViews and keep generated JavaScript at ES2017 or below. Do not emit:
?., nullish coalescing ??, logical assignment, class fields, private fields, catch {} without binding.s regex literals.replaceAll, Promise.allSettled, Object.fromEntries, Array.flat/flatMap, structuredClone, or unguarded AbortController.CSS must avoid fragile modern selectors and values:
:is(), :where(), :has(), or :focus-visible.gap in injected panels unless a margin fallback is already present.aspect-ratio, clamp(), inset, backdrop-filter, and viewport units.var(--fm-web-height, 100vh) instead of bare full-screen height when sizing WebHome overlays.Always output a fixed manifest/config unless the user only requested a review:
{
"extensions": [
{
"id": "site-native-router",
"name": "Site native router",
"version": "1.0.0",
"runAt": "document-end",
"cspKeyRegex": ["^site-key$"],
"js": ["./site.js"]
}
]
}For sites[].extensions, omit cspKeyRegex unless the user wants extra narrowing. For root-level webHomeExtensions, include cspKeyRegex and enabled: true only when the extension should load by default.
Use stable kebab-case IDs containing the site name. Start new scripts at 1.0.0, and increment versions when editing an existing extension. Declare depends when sharing helpers such as tv-focus-helper.
When creating a new extension, provide:
sites[].extensions snippet.When editing files in a repo, create the JS and manifest files directly, then validate with the checklist below.
Verify before finishing:
GM_getValue/GM_setValue, fm.req, fm.play, fm.pan.play, and fm.vodInline calls are awaited or caught.id, version, runAt, and exact site key matching.© webhtv, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 24 other files (scripts, references, assets) in webhome-devkit/skills/webhome-extension-builder of webhtv/webhtv.
Open the folder on GitHubat commit 4e30ffa
Webhome Extension Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Webhome Extension Builder this skillwebhtv/webhtv | 1.7k | — | ~2.8k | Automated safety check: Pass | GPL-3.0 | |
| Distilled SDKalchemy-run/distilled | 431 | — | ~6k | Automated safety check: Pass | Apache-2.0 | |
| Certmanager Dns01 Gke Private Clusterdivinevideo/divine-mobile | 266 | — | ~1.8k | Automated safety check: Pass | MPL-2.0 | |
| Reverse Flowlingbol088-spec/reverse-flow-skill | 936 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Ctf Malwareljagiello/ctf-skills | 3.4k | 1 repos | ~2.1k | Automated safety check: Notes | MIT | |
| Openfasttrace Reverse Specsitsallcode/openfasttrace | 198 | — | ~2.9k | Automated safety check: Pass | GPL-3.0 |
alchemy-run/distilled
Build or update a distilled SDK for an API provider — sourcing its OpenAPI/Smithy/GraphQL/discovery description, adding the spec mirror that feeds it, generating packages/<provider, listing it on…
divinevideo/divine-mobile
Fix cert-manager DNS01 ACME challenges stuck in "pending" state with "DNS record not yet propagated" inside GKE private clusters, even when TXT records exist in Cloudflare DNS.
lingbol088-spec/reverse-flow-skill
Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
itsallcode/openfasttrace
Reverse-engineer missing or incomplete OpenFastTrace system requirements and arc42-style design documentation from a project's user guide, existing documentation, tests, and code.
CSS-Electronics/can-bus-reverse-engineering-skills
Combine multiple individual single-signal DBC files into one combined DBC at the application level.
webhtv/webhtv
Build, review, debug, reverse-engineer data sources for, and package FongMi/WebHome custom homepage single-file HTML.
webhtv/webhtv
Inventory related upstream repositories, generate or refresh exhaustive commit-ledger assessment documents, and evaluate or implement dependency integrations safely, efficiently, and reversibly.
Works with
Categories
Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages. Webhome Extension Builder is an agent skill from webhtv/webhtv. Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.
Webhome Extension Builder fits situations like: Codex is asked to create; improve WebHome extensions; webHomeExtensions; sites[].extensions.
Run `npx skills add webhtv/webhtv --skill webhome-extension-builder -a claude-code`. Or copy the skill folder (webhome-devkit/skills/webhome-extension-builder in webhtv/webhtv) into .claude/skills/webhome-extension-builder in your project. Claude Code loads it when a task matches its description.
Run `npx skills add webhtv/webhtv --skill webhome-extension-builder -a codex`. Or copy the skill folder (webhome-devkit/skills/webhome-extension-builder in webhtv/webhtv) into .agents/skills/webhome-extension-builder in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add webhtv/webhtv --skill webhome-extension-builder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/webhome-extension-builder, .gemini/skills/webhome-extension-builder, .github/skills/webhome-extension-builder and .opencode/skills/webhome-extension-builder in your project.
Going by SKILL.md and its folder, Webhome Extension Builder needs JavaScript for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Webhome Extension Builder is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 20k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Webhome Extension Builder: Distilled SDK (alchemy-run/distilled, 431 stars), Certmanager Dns01 Gke Private Cluster (divinevideo/divine-mobile, 266 stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 936 stars) and Ctf Malware (ljagiello/ctf-skills, 3.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
webhtv (a GitHub organization) maintains it in webhtv/webhtv, which has 1,661 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 8, 2026.
Source: webhtv/webhtv on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.