OverviewHistoryStatsSecurity
npx skills add ...
Documentation
SKILL.md
npx skills add xixu-me/skills --skill develop-userscripts
Use when building, debugging, packaging, or publishing browser userscripts for Tampermonkey or ScriptCat, including GM APIs, metadata blocks, permission issues, @match/@grant/@connect setup, ScriptCat background or scheduled scripts, UserConfig blocks, or subscription workflows.
npx skills add xixu-me/skills --skill develop-userscripts
Userscript work usually breaks at the runtime and metadata boundary, not in the page logic. Choose the runtime first, declare the minimum permissions up front, then debug in the environment where the script actually runs.
Use this skill for:
GM_* behavior@background or @crontab==UserConfig====UserSubscribe== bundle or preparing a CloudCat-compatible scriptDo not use this skill for full browser extension development or general browser automation outside userscript managers.
Allow User Scripts or browser developer mode before scripts run.@match, @grant, @connect, @run-at, and any update URLs.==UserScript== patterns for ordinary page scripts. Only switch to ScriptCat-only headers when the requested behavior actually needs them.background.html for real-environment debugging.@version accurate and add @updateURL or @downloadURL only when needed.==UserSubscribe==, HTTPS URLs, and subscription-level @connect.| Intent | Default choice | Watch for |
|---|---|---|
| Page UI, DOM scraping, page patching | Portable ==UserScript== | @match, @grant, @run-at, CSP-sensitive injection |
| Cross-origin API access | GM_xmlhttpRequest with explicit @connect | Missing hosts, cookie behavior differences, user authorization |
| Long-running worker | ScriptCat @background | No DOM, must return Promise for async work |
| Scheduled task | ScriptCat @crontab | Only first @crontab counts, prefer 5-field cron, avoid interval overlap |
| User-editable settings | ==UserConfig== plus GM_getValue | Block placement and group.key naming |
| Silent bundle install and updates | ==UserSubscribe== | HTTPS, user.sub.js, subscription connect overrides child scripts |
@grant for APIs the script actually uses.@connect for hosts used by GM_xmlhttpRequest or GM_cookie.@include as a better default than @match for ordinary host targeting.==UserScript== and ==UserSubscribe== packaging concepts.==UserConfig== in the wrong place or reading config keys without the group.key name.