sdd-onboard

sdd-onboard is a command for Claude Code from Gentleman-Programming/gentle-ai. It costs 20 tokens per session (303 once invoked), scanned A, original, MIT.

A guided walkthrough of specification-driven development, or SDD, using the user’s real codebase. SDD is a process that turns a change into a proposal, specification, design, task list, implementation, verification, and archived record.

In plain words
What is it for?
Exploring a codebase, preparing and applying a change through the SDD stages, verifying the result, archiving the work, and recording onboarding progress.
Why use it?
It teaches the complete development cycle through an actual project rather than a toy example. It also saves progress so the onboarding can continue across steps.

Command for Claude Code

Written for Claude Code: a Claude Code command (commands/*.md). Also seen: agent in frontmatter; mentions subagents; mentions OpenCode.

Good fit Exploring a codebase, preparing and applying a change through the SDD stages, verifying the result, archiving the work, and recording onboarding progress.

Compare 6 commands from other repositories ↓
Install with agentmods
npx agentmods add commands/gentleman-programming/gentle-ai/sdd-onboard
About the project

Gentle-AI configures an existing AI coding agent into an engineering environment with persistent memory, planning workflows, skills, tool servers, model routing, and optional review. Developers and teams use it to make coding agents follow project conventions and retain decisions across sessions. The catalogue entries are its skills, commands, agents, and instruction.

Gentleman-Programming/gentle-ai · 6,328 stars · on GitHub · gentle-ai.gentlemanprogramming.com

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/Gentleman-Programming/gentle-ai

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for sdd-onboard

README.md
[![agentmods](https://agentmods.dev/badge/commands/gentleman-programming/gentle-ai/sdd-onboard.svg)](https://agentmods.dev/commands/gentleman-programming/gentle-ai/sdd-onboard)
Your own site
<a href="https://agentmods.dev/commands/gentleman-programming/gentle-ai/sdd-onboard"><img src="https://agentmods.dev/badge/commands/gentleman-programming/gentle-ai/sdd-onboard.svg" alt="Measured on agentmods" height="20"></a>
Per session 20 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 303 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00020 $0.00303
Opus 5 $0.00010 $0.00151
Sonnet 5 $0.00004 $0.00061
Haiku 4.5 $0.00002 $0.00030

Measured 6d ago against content hash 636524303a12, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

sdd-onboard scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

internal/assets/opencode/commands/sdd-onboard.md · 23 lines

What it actually says

You are the gentle-orchestrator, not an SDD executor. This command may launch the hidden sdd-onboard sub-agent only after the orchestration gates below pass.

CONTEXT:

  • Working directory: before doing anything else, run git rev-parse --show-toplevel 2>/dev/null || pwd with your bash tool and use the returned path as the authoritative workspace. In OpenCode Desktop (Electron) the parse-time interpolation resolves to the app data directory, not the project.
  • Current project: the basename of the detected workspace above.

HARD GATES:

  1. SDD Session Preflight must already be complete for this session. It must include execution mode, artifact store, chained PR strategy, and review budget. If missing, ask the exact orchestrator preflight prompt and STOP. Do not start onboarding in the same turn.
  2. Use the resolved artifact store from session preflight; do not hardcode Engram.

TASK: If all gates pass, launch the hidden sdd-onboard sub-agent to guide the user through a real SDD cycle. Keep user-facing pauses in interactive mode and enforce the review budget before apply.

Return a structured orchestration result with: status, executive_summary, artifacts, next_recommended, risks, and skill_resolution.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago Changed 636524303a12
  2. 8d ago First seen · 23 lines · 20 tokens per session scan A 644ba9813f42

Subscribe to this mod's changes

sdd-onboard is a command published in the GitHub repository Gentleman-Programming/gentle-ai (6,328 stars, last pushed yesterday), licensed MIT. It adds 20 tokens to every session and 303 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other commands, from other repositories

cross-critique

Adversarial multi-angle critique. All three auditors fire in parallel (codex=technical, gemini=strategic, claude=ux). Counter-args ranked by rebuttal survival score, not raw severity. Usage: /cross-critique [--with | list | compare].

FerroxLabs/ijfw · 65 tokens

cross-audit

Second-model review. Picks an auditor (codex/gemini/opencode/aider/copilot), excludes the caller, writes a prompt to paste, reads the response back. Usage: /cross-audit [--with | list | compare].

FerroxLabs/ijfw · 55 tokens

make

Refresh, reconfigure, or extend the project's harness at /.claude/. Asks the user what they want to do before invoking the CLI.

Ecro/harness-maker · 0 tokens

pr-feedback-ingest

Turn PR feedback (Greptile, CI, bots, humans) into a structured traceable backlog aligned with TASKSTATE.md, DECISIONS.md, and IMPLEMENTATIONPLAN.md so the next execution step can be a narrow implement-approved-slice or a small planning touch without losing alignment. Corrective scope only. Use when a PR is open or…

Mozurok/fhorja.dev · 230 tokens

repo-consistency-sweep

Proactive defect-class detection that handles the lower-value half of code review (per Bacchelli and Bird 2013) so human reviewers stay focused on design, intent, and knowledge transfer. Catches convention drift, ordering bugs, type-safety gaps, security and multi-tenant invariants (CWE-grounded), and operability…

Mozurok/fhorja.dev · 200 tokens

code-review

Run parallel specialized review agents and produce aggregated quality report.

zxpmail/ReqForge · 10 tokens