Install
$ agentstack add skill-spritecook-skills-spritecook-workflow-essentials ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
SpriteCook Workflow Essentials
Use this alongside the SpriteCook image or animation skill whenever SpriteCook MCP tools are available.
Requires: SpriteCook MCP server connected to your editor. Set up with npx spritecook-mcp setup or see spritecook.ai.
Preflight Checklist
- Check credits first with
get_credit_balancebefore starting a batch or multi-asset workflow. - Prefer presigned download URLs over authenticated asset endpoints.
- Save important
asset_idvalues in a local manifest whenever there is a writable workspace, unless the user explicitly wants a throwaway result. - When a workflow involves follow-up generations or animations for the same subject, identify and reuse the canonical
asset_idinstead of generating from scratch again. - If the agent loses track of generated asset IDs, recover them with
list_recent_assets(limit=...)before failing.
Credential Safety
- Never ask the user to paste a SpriteCook API key into chat, prompts, code blocks, shell commands, or generated files.
- Never print, persist, echo, or inline API keys or
Authorizationheaders in agent output. - Prefer SpriteCook MCP tools, presigned URLs, or a preconfigured local connector/helper that handles authentication outside the prompt.
- If a raw API call is required and no authenticated helper exists, stop and ask the user to configure one.
Asset Library Tools
- Use
spritecook-upload-assetspluscreate_asset_uploadandfinalize_asset_uploadwhen a local file path needs to become a SpriteCook asset before animation, editing, reference, or tileset-style reuse. - Use
import_asset(image=..., pixel=..., display_name=..., file_name=...)only when the image is already a small data URL or raw base64 value that can be passed without printing it. - Use
remove_background(asset_id=...)for owned SpriteCook assets that need a transparent cutout. Useremove_background(image=...)only when the user supplies local image data and does not need a reusable imported asset first. - Use
update_asset_label(asset_id=..., label=...)after generation, import, or cleanup when a clearer asset name will help the project manifest or future agent steps. - Do not tell the user to use the SpriteCook HTTP API or API keys for local image import when the SpriteCook MCP tools are available. Prefer the upload bridge for file paths.
Preset Tools
- When the user says to use one of their saved presets, call
list_presets(query=...)first and identify the best matching preset by title, mode, and status. - Then call
get_preset_settings(preset_id=...)and apply the returned settings as guidance for the next SpriteCook MCP generation or edit tool. - Treat presets as saved settings and reference guidance, not as a separate generation path.
- Private draft presets can return owned reference asset IDs in
settings.reference.styleAssetIds,contextAssetId, andeditAssetId. - For still-image generation, map
settings.reference.styleAssetIdstostyle_asset_idsongenerate_game_art; use up to 10 IDs. - Treat style guide images as ambient style context for new related assets; agents do not need to restate them in the prompt unless calling out a specific visual trait.
- Map
settings.reference.contextAssetIdtoreference_asset_idwhen the preset provides one specific visual/context reference asset. - Use
reference_asset_idwhen a prompt refers to one specific source or context asset, such as a particular building, character, prop, or part. - Use
edit_asset_idonly for the one asset being directly modified. - Published presets can return frozen preset media URLs in
settings.reference.styleUploadUrls,contextUploadUrl, andeditUploadUrl; use these only when the target MCP tool supports upload URL references. - Use
save_private_preset(...)only when the user explicitly asks to save a private preset. It creates a private draft preset only and does not publish, share, or submit anything for moderation.
Defaults
- Prefer
smart_crop_mode="tightest"for the best default results. Use"power_of_2"only when the user explicitly asks for it. - Model guidance:
gemini-2.5-flash-image: cheapestgemini-3.1-flash-image-preview: recommended defaultgemini-3-pro-image-preview: most expensive
Asset Manifest
- Treat
asset_idas the primary stable identifier. - Store a 12-character SHA-256 prefix (
sha12) for saved local files. - Use a minimal manifest entry shape:
asset_idsha12- optional
label - Prefer a simple machine-readable file such as
spritecook-assets.jsonunless the project already has an asset manifest. - Before generating a new reference asset or asking the user for an asset id, check the local manifest first.
- Before reusing a local file, compute its
sha12and match it against the manifest to recover the correctasset_id.
Downloading Assets
- For recent-asset recovery flows, prefer
list_recent_assets(limit=...). - Treat
sprite_urlas the single primary asset URL to inspect, save, or hand off to downstream tools. - Treat
spritesheet_urlas an optional secondary artifact. Use it only when present and only when you specifically need a spritesheet export. - For single-asset inspection flows,
get_asset_metadata(asset_id)also exposes a primaryurlplus optionalspritesheet_url. - Avoid relying on low-level internal fields such as
_presigned_pixel_urlor_presigned_urlin agent-facing workflows unless no higher-level field is available. - Avoid direct authenticated download endpoints in skill-driven workflows unless a helper handles auth out of band.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: SpriteCook
- Source: SpriteCook/skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.