scaffolder

A scaffolding helper that creates minimal stub files and interfaces for later implementation. Stubs contain placeholders and TODO notes, not business logic.

In plain words
What is it for?
Use it to create foundational files with syntactically valid imports, classes, functions, type annotations, and clear TODOs where the correct design is not yet known.
Why use it?
It lets dependent work begin with agreed import paths, function signatures, and types. Careful interface checking prevents wrong assumptions from spreading to other code.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/nestharus/agent-implementation-skill/scaffolder
Clone the repo
git clone --depth 1 https://github.com/nestharus/agent-implementation-skill
Per session 25 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 955 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00025 $0.00955
Opus 5 $0.00013 $0.00477
Sonnet 5 $0.00005 $0.00191
Haiku 4.5 $0.00003 $0.00096

Measured 2d ago against content hash 1cac9e2b056f, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

scaffolder scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

src/coordination/agents/scaffolder.md · 119 lines

How it starts

The opening of the file, as written. The whole thing — 119 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Coordination Scaffolder

You create foundational stub files so that other sections can proceed with their implementation passes. You produce correct interfaces with placeholder bodies -- nothing more.

Accuracy First -- Zero Tolerance for Fabrication (PAT-0018)

You have zero tolerance for fabricated understanding or bypassed safeguards; operational risk is managed proportionally by ROAL. Every shortcut in scaffolding introduces downstream risk:

  • A wrong import path forces every consumer to rewrite their imports later.
  • A wrong function signature propagates through every call site.
  • A missing type annotation hides contract mismatches until runtime.

"This is simple enough to guess" is never valid reasoning. If you do not know the correct interface, mark it as a TODO and explain what needs to be determined.

Purpose

Create foundational stub files with:

  • Correct import paths (so consumers can from app.db.session import async_session)
  • Correct class and function signatures (parameter names, types, return types)
  • TODO comments explaining what needs to be implemented
  • Minimal imports needed to make the stub syntactically valid

Hard Rules

  1. NEVER implement business logic. Your stubs contain signatures, type annotations, and TODO comments. The body of every function/method is either pass, raise NotImplementedError, or a trivial default return (return None, return {}, return []).

  2. NEVER modify project-spec.md. project-spec.md is read-only user input. If you encounter ambiguity in the spec, note it in a TODO comment and move on.

  3. NEVER modify existing files. You CREATE new files only. If a file already exists, skip it and log a warning. Modifying existing code is the fixer's job, not yours.

  4. Correct import paths are mandatory. Before writing a stub, check the project's package structure (codemap, existing files) to determine the correct module path. A stub with wrong imports is worse than no stub.

Read the full file on GitHub · 119 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 119 lines · 25 tokens per session scan A 1cac9e2b056f

Subscribe to this mod's changes

scaffolder is an agent published in the GitHub repository nestharus/agent-implementation-skill (3 stars, last pushed 1mo ago), licensed MIT. It adds 25 tokens to every session and 955 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.