validate

A startup-validation workflow step that researches an idea, its market, and its competitors, then recommends GO, PIVOT, or NO-GO. It can pause for the founder's context and review before continuing.

In plain words
What is it for?
Use it to analyze the idea, research market size and competitors, create a research brief, and produce a founder-reviewed validation report.
Why use it?
It helps test whether an idea addresses a real opportunity before time is spent defining or building the product. Its saved research files also provide input for later planning phases.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/arslan70/haytham/validate
Clone the repo
git clone --depth 1 https://github.com/arslan70/haytham
Per session 27 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 4,917 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00027 $0.04917
Opus 5 $0.00014 $0.02459
Sonnet 5 $0.00005 $0.00983
Haiku 4.5 $0.00003 $0.00492

Measured 2d ago against content hash c34dce52b9d8, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

validate scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

curl -s -H "User-Agent: haytham/1.0" "[URL].json"
commands/validate.md · 403 lines

How it starts

The opening of the file, as written. The whole thing — 403 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Haytham: Idea Validation (Phase 1 - WHY)

You are running Phase 1 of the Haytham validation workflow. This phase analyzes the startup idea, researches the market, and produces a recommendation.

IMPORTANT: Always read agent output from files, not from conversation history.

Progress Tracking

After Setup completes (and before Step 0), call TodoWrite once with one todo per step that will actually run for this invocation. Steps 0, 4, 6 are skipped in BATCH_MODE; skipped steps must not be added to the todo list. If resuming from --from N, only include steps from N onward.

Default (interactive) todo set:

  1. Step 0 — Founder context
  2. Step 1 — Idea analysis
  3. Step 2 — Market & competitor research
  4. Step 3 — Research brief
  5. Step 4 — Founder review
  6. Step 5 — Validation report
  7. Step 6 — Gate 1

Mark each todo in_progress when starting the step and completed when its output file is written (or the gate decision is recorded). If a step re-runs because the founder corrected something, set it back to in_progress.

Setup & Resume Detection

Flag Parsing

First, check if the argument contains --batch. If so:

  • Remove --batch from the argument string (the remainder is the idea, URL, or --from N)
  • Set BATCH_MODE to true

Then check if the user passed --from N as the argument (e.g., /haytham:validate --from 5). If so, set START_STEP to N.

URL Detection

If the argument is not --from N, check if it looks like a URL:

If it matches https?://(www\.)?reddit\.com/ (Reddit post):

  1. Try WebFetch to retrieve the URL content
  2. If WebFetch fails (blocked or errors), fall back to the Reddit JSON API via Bash:
    curl -s -H "User-Agent: haytham/1.0" "[URL].json"
    
    Parse the JSON response to extract title and selftext from data.children[0].data.
  3. Extract the post title and body text from the fetched content
  4. Set IDEA_TEXT to the extracted title + body
  5. Set SOURCE_URL to the original URL
  6. Set SOURCE_TYPE to reddit_post

Read the full file on GitHub · 403 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 403 lines · 27 tokens per session scan A c34dce52b9d8

Subscribe to this mod's changes

validate is a command published in the GitHub repository arslan70/haytham (13 stars, last pushed 1mo ago), licensed MIT. It adds 27 tokens to every session and 4,917 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.