02 · Brand Layer
For AI agents
Wire the brand into any AI tool — choose the live MCP path, or the no-MCP path: read URLs, one file to upload, or the whole package as a download.
01 · Connect an agent
Connect an agent
How does your AI tool connect?
Tool can’t add MCP? .
If your AI agent lives inside the browser, it does not need any of the steps below. This site registers 10 of its brand tools with the page itself over WebMCP, the W3C proposal for exposing a page’s capabilities to agents. Open any page here and the agent can read the real design system instead of scraping what it can see.
Status: Checking this browser.
Support is early: Chrome and Edge run it behind an origin trial, and Firefox and Safari have not shipped it. Where it is missing, nothing breaks and nothing is registered, so use one of the two paths below. The same tools are always available over MCP at https://galton-ai-assets.vercel.app/api/mcp and as plain HTTP at https://galton-ai-assets.vercel.app/api/tool.
https://galton-ai-assets.vercel.app/api/mcpSet up your tool
Pick your tool below. The endpoint above is the same everywhere — only the config key name changes, so each guide ships the exact snippet to paste.
Talk to the brand in a normal chat. Newer apps (Claude, ChatGPT, Perplexity, Mistral Vibe) add it as a custom connector; where that's not possible — e.g. the consumer Gemini app — switch this page to No MCP access for the load-a-file path.
- Open Customize → Connectors, click +, then Add custom connector.
- Name it
GALTON Assetsand set the Remote MCP server URL to the endpoint below. - Leave Advanced settings (OAuth) empty — the server is public, no auth. Click Add.
- In any chat, open the "+" / Connectors menu and enable it, then paste the connect-and-remember prompt above.
https://galton-ai-assets.vercel.app/api/mcpNote · Claude reaches the server from Anthropic's cloud, so a public URL (this one) is required — a localhost server won't work. Free plan = 1 custom connector; Pro, Max, Team and Enterprise have no stated limit. One connector covers Claude, Claude Desktop and Cowork. On Team/Enterprise an Owner adds it once under Organization settings → Connectors → Add → Custom → Web, then members enable it from their own Connectors list.
- Settings → Security and login → turn on Developer mode (Plus, Pro, Business, Enterprise and Edu, web only).
- Open ChatGPT Plugins (
chatgpt.com/plugins) and hit the + button to create a developer-mode app. - Give it a name and description; under Connection pick the public endpoint and paste the MCP server URL below (the
/mcppath is required). Authentication = No authentication. - Create it, then review the tools ChatGPT discovered from the server.
- The app lands under Drafts and then in the composer's Developer mode tool — enable it in a chat and paste the connect-and-remember prompt above.
https://galton-ai-assets.vercel.app/api/mcpNote · OpenAI renamed connectors → apps (Dec 2025) and folded the app directory into the Plugins directory (9 Jul 2026), so older guides pointing at “Apps & Connectors → Advanced settings” are stale. Developer mode gives full MCP tool support on Plus, Pro, Business, Enterprise and Edu; on a workspace plan an admin enables it first under Workspace settings → Permissions & roles. Nothing here writes anyway: every tool on this server is read-only. No MCP? A Custom GPT with the brand file as Knowledge still works, but since 16 Aug 2026 only a Business, Enterprise or Edu workspace can create a new one; Plus and Pro keep the GPTs they already own. Switch this page to No MCP access for that recipe and the upload path.
- Open Account settings → Connectors, and under Custom choose + Custom connector → Remote (Pro, Max or Enterprise).
- Set the MCP Server URL to the endpoint below and Authentication = None. Tick the box acknowledging that custom connectors carry risk, then Add.
- The connector appears in your Connectors list: click its card to enable it, then paste the connect-and-remember prompt above.
https://galton-ai-assets.vercel.app/api/mcpNote · On Enterprise an admin has to turn on Allow members to add custom connectors in Enterprise settings first, and whoever adds it has to share it with the organisation from the Permissions screen before anyone else sees it. Perplexity also browses the open web reliably, so as a quick alternative you can just paste the read URLs and it will fetch them.
- Open the Connectors page, click + Add Connector and switch to the Custom MCP Connector tab. This is an administrator-only feature; on Free, Pro and Student the account owner is the administrator by default.
- Fill in Connector name (a unique identifier, no spaces or special characters), set Server URL to the endpoint below, optionally add a description, then click Connect — Vibe detects by itself that the server needs no authentication.
- Turn it on in a chat (Tools icon → tick the connector) and paste the connect-and-remember prompt above.
https://galton-ai-assets.vercel.app/api/mcpNote · Mistral renamed Le Chat to Vibe on 28 May 2026 and folded the assistant into Vibe's Work Mode, so guides that still say Le Chat are describing the same product under its old name. Mistral's own docs are mid-rename and use both.
B1 · the read URLs
Can your tool open URLs? Point it at /llms.txt — the index that links the rest of the read URLs.
B2 · upload
Can't fetch at all? (Gemini app, ChatGPT Free) Download /llms-full.txt — the whole brand in one file — and add it as Knowledge (a Gem / Custom GPT) or paste it. Works even where URL-reading doesn’t.
C · the offline package
Need the files themselves? Download /bundle.zip, unzip, hand your agent the folder. The knowledge, the orchestrator skill and every logo, icon and font, with no connection at all.
Download the whole thing
One ZIP with the complete brand: every knowledge file, the orchestrator skill, and every logo, icon and font as a real file. Unzip it, drop the folder next to your agent, and point it at SKILL.md. No connector, no developer mode, no network.
SKILL.md the orchestrator: which file for which task
START-HERE.md the map: what is where, how to import it
MANIFEST.json every file with its size and SHA-256
brand.css fonts, token variables, one class per component
knowledge/ intake.md · design.md · brand.md · verbal-identity.md
linkedin.md · layouts.md · prompts.md · llms-full.txt
data/ brand.json · layouts.json · icons.json
snippets.json · llms.txt
brand/ the files themselves: logos/ fonts/ icons/
icons-line/ icons-line-light/ icons-3d/ layouts/
+ ASSET-INDEX.mdBuilt live from the same source as everything else, so it is never a stale copy. integrity.json publishes its SHA-256.
Or take a single file
llms-full.txt is not a summary of the files below it: it carries them word for word, which is why the row says what is already inside. The three at the bottom are the same brand in another shape rather than another copy, so those are worth taking on their own. For the asset files themselves, take the package above.
The whole knowledge base in one file, for an upload box that takes one document and no folder.
Already inside it: intake.md, design.md, verbal-identity.md, linkedin.md, plus the layout catalog, the icon library, the asset URLs. Take one of those separately only if you want it on its own.
Guided mode: what to fill from defaults, what to ask, how to report back.
The design system: tokens, components, the rules and the fallback contract.
The brand voice, with a ready-to-paste AI brief.
The LinkedIn playbook: post types, anatomy, hashtag rules.
The orchestrator: which tool or file answers which task. Routing, not knowledge.
The short index: every surface with a token estimate. Start here if you are choosing what to read.
The same brand as structured JSON, for code that would rather parse than read.
Step-by-step: no-MCP tools
The four reliable ways to get the brand into a tool that can't connect over MCP.
- Download
bundle.zipfrom Download the whole thing above, and unzip it. - Put the folder where your agent can read it: inside the repository for a coding agent, or a mounted folder for a desktop agent.
- Tell the agent to read
SKILL.mdfirst.START-HERE.mdnext to it is the map of everything else. - The assets are already local:
brand/logos/,brand/fonts/,brand/icons-line/. Nothing to fetch, nothing to hotlink.
Note · The only path that carries the actual logo, font and icon files. MANIFEST.json inside lists a SHA-256 per file, so a security review can verify the folder before anyone uses it.
- Download
llms-full.txtfrom Get the brand file above. For more depth also grabdesign.md,verbal-identity.md,linkedin.md. - In the Gemini app open Gems → New Gem (Gem manager on desktop).
- Under Knowledge, Add files and upload
llms-full.txt— Gems take up to 10 files, or link a Google Drive file/folder and Gemini keeps using the latest version. - Open the Gem instructions below, copy them, paste into the Gem's Instructions field, then Save.
- Leave Default tool on No default tool. Canvas belongs to the request, not to the Gem: you want it for a slide, not for a question about a colour.
- Disable Knowledge Citations off at first, so you can see the Gem quoting the file and know it is really reading it. Turn it on once you trust it and want clean copy.
- Chat with the Gem — it now answers from the brand, no URL fetching required.
- Asking for a visual, a slide or a carousel? Switch Canvas on in the composer for that request. Canvas renders HTML live, which is what turns the catalog's measured geometry into an actual slide instead of a description of one.
Note · This is the fix for the “I can't read those links” error (see the matrix below) — you feed the Gem the content as Knowledge instead. The instructions below are written for a Gem specifically: they never ask Gemini to open a URL or reach the MCP server, because a Gem can do neither, and a Gem that spends its first turn failing to fetch will guess instead.
- Download
llms-full.txt(plusdesign.md/verbal-identity.mdif you want the long form). - ChatGPT → Explore GPTs → + Create → Configure.
- Under Knowledge, upload the file(s) — up to 20 files, 512 MB each.
- Paste the connect-and-remember prompt (below) into Instructions, then Save / Update.
- Use that GPT for anything on-brand. (For a live connection instead, use a developer-mode MCP app — switch to Connect via MCP above.)
Note · On 16 Aug 2026 OpenAI restricted creating new GPTs to Business, Enterprise and Edu workspaces. Free, Go, Plus and Pro can still use and edit a GPT they already own, including adding this file as Knowledge, but they cannot build a new one. On those plans use the developer-mode MCP app instead, or upload the file per conversation.
- Download
llms-full.txtinto a folder you keep the brand in (adddesign.md/verbal-identity.md/linkedin.mdfor the long form). - In Kimi Work, mount that folder — the agent reads and writes local files under the paths you authorise.
- Paste the connect-and-remember prompt (below) at the start of a task and point it at the file.
Note · Work's plugin centre only installs marketplace plugins — there's no field for your own MCP URL — so the local file is the way in. For the live server, use Kimi Code CLI instead (switch to Connect via MCP).
- Open
llms-full.txtand download it (or select-all and copy the text). - Drag the file into the chat, or paste the text, then paste the connect-and-remember prompt below.
- Works anywhere — but you repeat it per new conversation. A Gem or Custom GPT makes it stick.
What works where
Two things vary by tool: can it add a remote MCP connector, and can it reliably open a URL? The consumer Gemini app does neither — so load the brand file instead.
| AI tool | MCP | Reads a URL | How to proceed |
|---|---|---|---|
| Claude — web & desktop | ✓ | ✓ | Add the endpoint as a custom connector (Settings → Connectors). |
| Coding agents — Claude Code, Cursor, VS Code Copilot, Kimi Code, Windsurf, Cline, Zed, JetBrains, Antigravity | ✓ | ✓ | Add the MCP server in config — switch to Connect via MCP above for the per-tool guides. |
| ChatGPT — Plus / Pro | ✓ | ~ | Developer-mode app, enabled from your own settings with no admin involved. Building a new Custom GPT is no longer an option on these plans (OpenAI restricted creation to workspaces on 16 Aug 2026); a Custom GPT you already own still works and still takes new Knowledge. |
| ChatGPT — Business / Enterprise / Edu | ✓ | ~ | Same developer-mode app, but a workspace admin enables it first. These are also the only plans that can still create a new Custom GPT with llms-full.txt as Knowledge. |
| ChatGPT — Free / Go | ✕ | ~ | Upload or paste llms-full.txt into the chat. |
| Gemini — consumer app (web & mobile) | ✕ | ✕ | Create a Gem → add llms-full.txt under Knowledge (or link Google Drive). Gemini does have custom Connected Apps, but only with Spark access and only inside Spark tasks, and they are partnership-only, so this is not a way in. |
| Gemini — Enterprise / API / Antigravity | ✓ | ✓ | Custom-MCP data store, the API's remote-MCP tool, or the ~/.gemini CLI/Antigravity config. |
| Gemini in Chrome (the agent built into the browser) | ✕ | ✓ | Nothing to set up: open any page of this site and its tools register themselves with the agent over WebMCP. Chrome runs WebMCP as an origin trial, so it depends on the Chrome version. |
| Copilot Mode in Edge | ✕ | ✓ | Same as Chrome: the page hands the agent its tools over WebMCP, no configuration. Edge runs its own origin trial. |
| ChatGPT Desktop (browsing a page) | ✓ | ✓ | It consumes WebMCP already, so a page of this site arrives with the tools attached. For chat without browsing, the developer-mode app. |
| Perplexity — Pro / Max / Enterprise | ✓ | ✓ | Add a custom remote connector — or just paste a URL, it browses reliably. |
| Microsoft Copilot Studio (maker / enterprise) | ✓ | ~ | Add the MCP server to the agent via the MCP wizard. |
| Microsoft 365 Copilot — chat | ~ | ~ | Federated MCP connectors reached Copilot Chat, Excel and Researcher in spring 2026: add the server through Copilot Studio, and it reads live rather than indexing. Invocation is still up to Copilot's orchestrator, so a healthy connector is not a guarantee it gets called. Attaching llms-full.txt to a Copilot agent stays the predictable path. |
| Mistral Vibe, formerly Le Chat (all plans) | ✓ | ✓ | Add a custom MCP connector. Administrator-only; on Free, Pro and Student the account owner is the administrator. |
| Kimi — chat app (kimi.com) | ✕ | ~ | No custom connectors in the chat app — upload llms-full.txt (50 files / 100 MB each, and the context window swallows it whole). |
| Kimi Work — desktop agent (macOS / Windows) | ✕ | ✓ | Plugin centre is marketplace-only (no custom MCP URL). Unzip bundle.zip into a mounted folder — Work reads local files natively. |
| Other chats — Grok, DeepSeek, Meta AI… | ✕ | ~ | Upload or paste llms-full.txt into the chat. |
| Anything that reads a folder — coding agents, desktop agents, an internal tool | ✕ | ✕ | Unzip bundle.zip and point it at the folder. Works with no network at all, and it is the only path that includes the asset files. |
✓ works · ~ limited / unreliable · ✕ not supported
Paste the connect-and-remember prompt
Whichever path you picked, paste this once — into the chat, or into a Gem / Custom GPT’s instructions. It points at the brand, names the tools and the read URLs, and tells the agent to remember and follow the guidelines for the rest of the project.
You now have access to the GALTON brand design system. Treat it as the single source of truth for anything GALTON-branded. PRIMARY SOURCE, live and queryable (preferred): the MCP server "galton-design" at https://galton-ai-assets.vercel.app/api/mcp. Start with get_skill, the versioned orchestrator skill (optionally save it; re-fetch when the brand version changes). Use the tools as authoritative: get_intake, get_brand_overview, get_design_spec, list_tokens, get_component, get_voice_guide, get_linkedin_playbook, get_sound_guide, get_layout, list_presentation_slides, get_presentation_slide, get_fallback, get_chart_palette. IF YOU CANNOT USE MCP, use the read URLs (open CORS, plain text/JSON): • https://galton-ai-assets.vercel.app/llms.txt: the curated index (start here) • https://galton-ai-assets.vercel.app/llms-full.txt: the whole brand in one file (best as uploaded Knowledge) • https://galton-ai-assets.vercel.app/intake.md: guided mode, parameters, defaults, the report block • https://galton-ai-assets.vercel.app/brand.json: the structured index (tokens, components, pointers) • https://galton-ai-assets.vercel.app/design.md: the design system (colours, type, components) • https://galton-ai-assets.vercel.app/verbal-identity.md: verbal identity (brand voice + AI brief) • https://galton-ai-assets.vercel.app/linkedin.md: LinkedIn playbook • https://galton-ai-assets.vercel.app/presentations.json: presentation slide types (16:9 decks) with slots, limits and example images • https://galton-ai-assets.vercel.app/sound.md: sound branding (sound logo, anthem, beds, which track for which job) IF YOU CANNOT REACH A URL EITHER, I will give you the offline package (https://galton-ai-assets.vercel.app/bundle.zip, unzipped): a folder whose root holds SKILL.md and START-HERE.md, with the knowledge under knowledge/, the same data as JSON under data/, and every logo, icon and font under brand/. Read SKILL.md first and treat those files as the source. WORK IN GUIDED MODE: my requests will usually be one sentence long. Don't wait for a perfect brief and don't guess silently. Read https://galton-ai-assets.vercel.app/intake.md (MCP: get_intake), fill every unset parameter from its default, then ask me at most three questions: the blocking ones from the protocol, plus a question of your own if this specific request genuinely needs one (a date, a name, which product, a conflict with the brand). Never ask about anything the brand fixes or anything that already has a default. Then produce the asset and end with the "Brand choices" block: what you chose, and the one word that changes each choice. If I answer "go", use the defaults. REMEMBER THIS FOR THE REST OF THE PROJECT: before you produce ANY on-brand asset (UI, slide, post, image, video, sound, or copy) pull the relevant tokens, components, voice and layouts from the source above and follow them exactly. Never invent a colour, font, radius or component. The accent is ALWAYS #FFD700 (colors.primary), never red, blue or green. H1/display headlines and section titles (H2) are UPPERCASE. Every text colour is SOLID: no opacity, no alpha, no grey type, and no em dash in any copy. Anything undefined: derive via the fallback contract, or ask. The logo is white or black ONLY — never the primary yellow or any other color. White on dark, black on light or on a yellow surface. Never recolor, rotate, stretch, add shadows/gradients, or re-typeset the wordmark. Treat these guidelines as binding defaults for every future request in this project, without me having to repeat them.
Keep it on-brand across a project
For coding work, commit an AGENTS.md (read by Codex, Copilot, Cursor, Windsurf, Zed, Jules…) or CLAUDE.md at the repo root. The agent auto-loads it every session, so it keeps calling the MCP tools and following the brand without being reminded.
# AGENTS.md (also works as CLAUDE.md)
## GALTON brand
This project follows the GALTON brand system. Before generating ANY
on-brand asset (UI, slides, posts, copy), pull the real values — don't guess.
- Source of truth: the "galton-design" MCP server at https://galton-ai-assets.vercel.app/api/mcp
key tools (of 18): get_skill · get_intake · get_brand_overview · list_tokens ·
get_component · get_voice_guide · get_layout · get_fallback
- No MCP? the read URLs: https://galton-ai-assets.vercel.app/llms.txt (index), https://galton-ai-assets.vercel.app/llms-full.txt
(the whole brand in one file) and https://galton-ai-assets.vercel.app/brand.json (structured index).
Rules: follow the tokens exactly; never invent colours, fonts, radii or
components; keep the logo white or black only; if something is undefined, read
get_fallback or ask. These are binding defaults for the whole project.02 · What the agent pulls
What the agent pulls
Not everything lives in design.md — that is only the design system. The full brand spans the files below, all aggregated into brand.json + llms.txt and exposed through the MCP tools. Point agents at the MCP server or /llms.txt, not at design.md alone.
intake.md— Guided mode: output types, their parameters and defaults, the report block, the self-checkdesign.md— Design system — colours, type scale, components, the fallback contract, agent promptsbrand.md— Brand identity & long-form guide — about, logo policyverbal-identity.md— Verbal identity — essence, personality, registers, lexicon, principles + a ready-to-paste AI brieflinkedin.md— LinkedIn playbook — post types, anatomy, hooks, hashtag ruleslayouts.md— Slide canvas + layout archetypes & carousel recipesassets.json · icons.json— Downloadable logos, fonts and the icon library
Aggregated for agents · everything above is rolled into https://galton-ai-assets.vercel.app/brand.json (the structured index), https://galton-ai-assets.vercel.app/llms.txt (the curated index) and https://galton-ai-assets.vercel.app/llms-full.txt (the self-contained bundle), and queried live through 17 MCP tools — plus MCP resources and prompts on the same endpoint. All of it, plus every logo, icon and font as a file, also ships as one download at https://galton-ai-assets.vercel.app/bundle.zip.
The orchestrator skill
skill.md (also the get_skill MCP tool) is the versioned orchestrator skill — it tells an agent which tool to use for which task and how to keep itself current. Saving it is optional — download it and drop it next to your AI tool (e.g. .claude/skills/…/SKILL.md), or let the agent fetch it itself.
Preview skill.md
---
name: galton-brand
description: Routes any GALTON-branded output task (UI, pages, slides, posts, charts, copy, images) to the right knowledge via MCP tools or the read URLs. Use before creating any GALTON-branded asset.
compatibility: Requires network access to https://galton-ai-assets.vercel.app. MCP server at https://galton-ai-assets.vercel.app/api/mcp preferred; the read URLs work without MCP.
metadata:
brand-version: "2.21.1"
source: https://galton-ai-assets.vercel.app/skill.md
---
# GALTON Brand Layer, the orchestrator skill
You are working with the GALTON brand, served by a read-only Brand Layer knowledge base: MCP server at https://galton-ai-assets.vercel.app/api/mcp (preferred) or the read URLs. It returns brand data only: YOU produce the asset in your own tools.
No brand tools visible? Connect first: `claude mcp add --transport http galton-brand https://galton-ai-assets.vercel.app/api/mcp` (or your client's HTTP-MCP equivalent). No MCP at all? Use the read URLs below, or POST to https://galton-ai-assets.vercel.app/api/tool, which runs the same tools over plain HTTP. If you are an agent inside a browser, open any page of https://galton-ai-assets.vercel.app: it registers these tools with you directly over WebMCP, with nothing to configure.
## Keep this skill current
This skill is generated from the brand and carries its version (`2.21.1`). At the start of a session call `get_brand_overview` (it returns `version`; or read https://galton-ai-assets.vercel.app/brand.json meta) and compare versions. If they differ, re-fetch https://galton-ai-assets.vercel.app/skill.md and replace your saved copy. Saving the skill is optional: if your environment supports skills (e.g. `.claude/skills/galton-brand/SKILL.md`), save it there; otherwise just keep it in context.
## Hard rules (never break)
1. Never invent a colour, font, radius or component. The accent is ALWAYS #FFD700 (colors.primary), never red, blue or green. H1/display headlines and section titles (H2) are UPPERCASE. Every text colour is SOLID: no opacity, no alpha, no grey type, and no em dash in any copy. Anything undefined: derive via the fallback contract, or ask.
2. Call `get_agent_rules` once per session for the rules of engagement: the colour and type rules, the fallback protocol, the voice prohibitions and the starting prompts. It carries rules, not values; the values are in `list_tokens`, `get_fallback` and `get_voice_guide`.
3. Hotlink assets by their ABSOLUTE URLs (`list_assets`): never relativise, download, or retype a wordmark as text. ONE exception, and only this one: inside the unzipped offline package (https://galton-ai-assets.vercel.app/bundle.zip) the local path `./brand/X` **is** `https://galton-ai-assets.vercel.app/brand/X`, the same file shipped alongside this skill. On a machine with no network, use that path. Everywhere else the absolute URL stands.
## Guided mode: run this BEFORE you produce anything
Most requests are one sentence long and leave most parameters unset. Fill them from the defaults in the table below, ask only about what you cannot infer, report what you chose, then run the self-check.
The protocol itself is 9 numbered steps and it is not repeated here: read it once from `get_intake` (or https://galton-ai-assets.vercel.app/intake.md), which also carries the per-output parameters, the licence to ask your own question and its boundary, and the exact report block to append. This section is the summary you act from once you have.
Never ask more than 3 questions, and never ask twice. If the user replies `go` / `choď` / `chod`, produce immediately from the defaults.
| Output | Ask only about | Everything else defaults to |
|---|---|---|
| Poster / out-of-home (`poster`) | headline | surface: dark; format: 4:5 portrait; icons: none; image: no; logo: primary wordmark lockup; language: Slovak |
| Social post (visual + caption) (`social`) | topic | surface: dark; canvas: 1080x1350; layout: cover; icons: none; image: no; caption: yes; language: Slovak |
| Presentation / deck (`deck`) | topic | slides: 10; surface: mixed; ratio: 16:9; sequence: picked from the presentation catalog by the content: cover-main, agenda, a divider per chapter, the content slides, cover-closing; format: HTML; icons: line icons; chart: yes; language: Slovak |
| Table / data sheet (`table`) | data | size: 5 columns, 5 rows; surface: light; tags: no; language: Slovak |
| Chart / data visualization (`chart`) | data | type: bar chart; surface: dark; series: 1; language: Slovak |
| Copy / text (`copy`) | subject | register: consultative; length: short; cta: one soft next step; language: Slovak |
| Web page / UI (`web`) | purpose | surface: dark; sections: hero, three content sections, footer; components: yes; language: Slovak |
Then append the report block (`Brand choices`), in the user's language: every parameter you resolved, its value, and the one-word alternative. `get_intake` carries the worked example.
**Never a parameter, never offered as a choice:** The accent colour. It is always the brand primary, on every surface, in every state. The typeface and the type scale. Both come from the design spec. The logo. White or black only, never recoloured, never retyped as text. The UPPERCASE rule for H1/display headlines and section titles (H2). The chart palette. Charts never use a library-default rainbow. Status colours (success/warning/error/info). Functional feedback only, never decoration.
**Self-check before delivering:**
- The accent is the brand primary, used for emphasis only, never as a large fill.
- The case follows `typeRules.case`.
- The logo is white or black, hotlinked from its real asset URL, not redrawn or retyped.
- Every text colour came from a role or a `.bl-text-*` class and satisfies `colorRules.text`; on a light surface it came from the `lightSurface` map, not from a dark-tuned token.
- Every colour, size, radius and component came from the spec, or from `fallback` where the spec is silent.
- Any chart uses the chart palette; any icon comes from the icon library, in the variant that matches the surface.
- Copy follows the verbal identity (register, lexicon, mechanics), not generic marketing language, and contains no em dash.
- Anything the spec does not define went through the fallback contract.
## Route by task
| You are asked to make | Do this, in order |
|---|---|
| Anything (first step) | `get_brand_overview`: identity, surfaces, the text system, the critical rule. |
| Web / UI / HTML | Link the stylesheet `https://galton-ai-assets.vercel.app/brand.css` (fonts + token variables + `.bl-{component}` classes), take markup from `https://galton-ai-assets.vercel.app/snippets.json` or `get_component` (`snippetHtml`). Tokens: `list_tokens` (pass `ref` to resolve one). |
| Anything on a LIGHT surface | The brand is dark-first, so every token and every `.bl-{component}` class is the dark rendering. Do not invert it yourself: wrap the light area in `.bl-light` and keep the same classes (brand.css carries the overrides), or read the map with `list_tokens { category: 'lightSurface' }`. `get_component` returns the light `changes` for that one component. The accent never inverts, and a link on light is ink, not yellow. |
| A colour for type, anywhere | Never pick one yourself. On the web use the `.bl-text-*` classes; elsewhere take the role from `get_brand_overview.essentials.text`, which carries the rule with the values. |
| Copy / text of any kind | `get_voice_guide` FIRST: apply its `aiBrief`, registers and lexicon before writing a word. |
| LinkedIn post | `get_voice_guide` first, then `get_linkedin_playbook` (post types, anatomy, hashtag rules), then `list_carousel_recipes` for a carousel: it picks the slide sequence by post type. |
| Video, reel, presentation, event or demo with sound | `get_sound_guide`: pick the track by `jobs`, hotlink its `url`, follow `principles` (house tempo, instrumental under a narrator, the sound logo as the last sound). Never use stock or generated music in its place. |
| Which slide layouts exist | `list_layouts`, the fast index: every layout as one row with its example image and SVG source. Start here; it costs a fraction of the detail call. |
| Slides / carousel visuals | `get_layout { id }`, and add `ratio` for another canvas height: the server resolves the geometry for you, so never rescale a measured number by hand. You get that layout's slots, its MEASURED geometry in absolute px, its `must` list, a reference SVG, and the slice of the shared canvas it uses. Build the slide yourself from the numbers; never place an element by eye off the example image, and never drop the rule, the logo or the URL. |
| A slide question the layout does not answer | Call `get_layout` with no arguments once per session. That is where the rest of the canvas lives: the legends for `sizing` (before you resize any box), `slot` and `verified`, `ratioAdaptation`, the composition model, and `imageTreatment` (before you put type over a picture). It is identical in every reply, which is why a layout call carries only the slice it needs. |
| A presentation / deck (16:9) | Its own catalog, not the social layouts. PLAN with `list_presentation_slides`: pick every slide by what its content has to do (intent, density, limits) and obey the deck rules (cover first, closing last, the full yellow box at most once). Then `get_presentation_slide` without id ONCE for the 1920x1080 canvas (type scale, spacing, footer), and `get_presentation_slide { id }` per slide type for its slots, must list and measured boxes. Never stretch a slide past its item count: split the content over two slides. |
| A canvas the catalog does not measure | The measured canvases are the ones `get_layout` lists under `ratios`, plus the 1920x1080 deck canvas of the presentation catalog; every other size (a 4:3 deck, A3 print) has NO geometry, and `get_layout` refuses the ratio rather than guess. Build it from the shared canvas: the padding, the type scale, the chrome bands and the anchoring rules in `ratioAdaptation`. Then say in the brand-choices block that the canvas was derived, not measured. |
| Icons | `list_icons`. Without args you get the whole library, one row per icon with its hotlinkable `url` (dark surfaces) and `lightUrl` (light surfaces). Pass `query` or `set` to narrow it and get the keywords too. |
| Charts / data viz | `get_chart_palette`: categorical, sequential, semantic. Never a library-default rainbow. |
| Several token values at once | `list_tokens { refs: [...] }`: one call, not one per value. |
| The whole design system | `get_design_spec` without arguments is the section INDEX; fetch the slice you need with `get_section` or `part`. The full document is ~79 KB and rarely what you want. |
| Anything undefined | `get_fallback`: the derivation protocol. |
| Finding a rule | `search_design` (full-text) or `get_section`. |
## No MCP available?
Use the read URLs: https://galton-ai-assets.vercel.app/llms.txt (index) or https://galton-ai-assets.vercel.app/llms-full.txt (the whole brand in one file, good as uploaded Knowledge). Everything is open-CORS plain text/JSON.
No URL access either? Download the offline package: https://galton-ai-assets.vercel.app/bundle.zip. It unzips to a folder carrying this skill, every knowledge file, and every logo, icon and font as a real file. Its START-HERE.md is the map. Inside that folder, the absolute URL `https://galton-ai-assets.vercel.app/brand/X` and the local path `./brand/X` are the same file.
03 · Security & data flow
Security & data flow
Leaves your tool
- The name of a read tool (for example get_component).
- Its arguments: short identifiers like a component name, a token ref, a search word.
- Standard HTTP metadata: IP, user agent, timestamp.
Comes back
- Brand data as text or JSON: tokens, component definitions, prose rules, the voice guide, layout schemas, asset URLs.
- Nothing executable. No scripts, no redirects, no credentials.
Never leaves your tool
- Your documents, decks, spreadsheets and drafts.
- Your prompts and conversation history.
- Client data, personal data, anything you paste into the chat.
- No endpoint accepts your content. https://galton-ai-assets.vercel.app/api/mcp and https://galton-ai-assets.vercel.app/api/tool take a tool name and its arguments, nothing else, and store neither.
Read-only by construction
Every tool returns brand data and nothing else. There is no write tool, no upload endpoint, no database and no user account. A read-only server cannot be made to store or forward anything, because there is nothing to store it in.
No authentication, because there is no secret
The endpoint is public and unauthenticated. That is a deliberate consequence of the above: with no writes and no user data there is no credential to issue, leak or rotate. It also means nothing to escalate: a reviewer approving this connector is approving read access to a design system that is already published on the open web.
Stateless
Streamable HTTP, one request in, one response out. Nothing is held between calls, so there is no session to hijack and no state to poison for the next caller.
The content is a reviewed git repository
What the server returns is a handful of Markdown and JSON files under version control, with a release history. It is not user-generated, not scraped and not crowd-edited, so there is no channel through which a third party can put text into a response.
The full tool surface · get_skill · get_intake · get_brand_overview · get_design_spec · list_tokens · get_component · get_section · search_design · list_assets · get_voice_guide · get_linkedin_playbook · get_sound_guide · list_layouts · get_layout · list_carousel_recipes · list_presentation_slides · get_presentation_slide · list_icons · get_fallback · get_chart_palette · get_agent_rules. Every one of them reads; none of them writes.
Prompt injection, stated honestly
Any text a model reads can contain instructions. That is true of this server, of an uploaded file, of a PDF from a supplier and of a web page an agent opens. It is not specific to MCP. What differs is who controls the text. Here it is a reviewed repository with a published version, and the content deliberately contains brand instructions (never invent a colour, the accent is always the primary) because that is the product. What it must never contain is an instruction that changes agent behaviour beyond the brand.
An automated check for exactly that
Every build runs a scan over the brand content for the patterns that have no business in a brand document: attempts to override earlier instructions, references to system prompts or credentials, exfiltration verbs, and links to domains outside the allow list. The build fails rather than shipping a file that trips it.
Verify the file you are given
Each release publishes the size and SHA-256 of every machine-readable surface. Download the file, hash it, compare. It is the same check whether you are reviewing the upload path or pinning a version.
integrity.jsonOr take the network out of it
The no-MCP path needs no connector, no developer mode and no live connection: one file, or the offline package as one download, read once and reviewable in full before anyone uses it. The package carries a MANIFEST.json with a SHA-256 per file, so the review is a comparison rather than a judgement call. For many organisations that is not the fallback, it is the right answer.
The no-MCP pathOr run it yourself
It is a standard Next.js application. Fork it, deploy it inside your own perimeter, and point your tools at your own origin. Only the URL in the client config changes. Pin a version and update on your own schedule.
Logging
The deployment keeps ordinary platform request logs (route, status, timing) for operational purposes. Prompts and conversations never reach the server, so they cannot be logged by it.
