Borrowing it
Nothing to install: this file belongs to matheusbrramos/ProductFlow. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/matheusbrramos/ProductFlow/main/.claude/commands/pf-doctor.mdgit clone --depth 1 https://github.com/matheusbrramos/ProductFlowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/matheusbrramos/productflow/pf-doctor)<a href="https://agentmods.dev/commands/matheusbrramos/productflow/pf-doctor"><img src="https://agentmods.dev/badge/commands/matheusbrramos/productflow/pf-doctor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/matheusbrramos/productflow/pf-doctor"><img src="https://agentmods.dev/badge/commands/matheusbrramos/productflow/pf-doctor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00010 | $0.01269 |
| Opus 5 | $0.00005 | $0.00634 |
| Sonnet 5 | $0.00002 | $0.00254 |
| Haiku 4.5 | $0.00001 | $0.00127 |
Grade A, and why
pf-doctor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 225 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/pf-doctor - Validador do ProductFlow
Valida a instalacao, estrutura e consistencia do ProductFlow. Identifica problemas e sugere correcoes.
Entrada
$ARGUMENTS
Se nenhum argumento, executar validacao completa (all).
Checks Disponiveis
/pf-doctor estrutura
Valida presenca de diretorios e arquivos essenciais.
/pf-doctor agentes
Valida consistencia dos agentes (.claude/agents/).
/pf-doctor comandos
Valida consistencia dos comandos (.claude/commands/).
/pf-doctor seguranca
Valida configuracoes de seguranca.
/pf-doctor all
Executa todas as validacoes.
O que validar
1. ESTRUTURA (Diretorios Essenciais)
Verificar existencia de:
[REQUIRED]
- .claude/
- .claude/agents/
- .claude/commands/
- .context/
- docs/
- docs/templates/
- docs/briefings/
- scripts/
[OPTIONAL - com .gitkeep]
- docs/discovery/
- docs/research/
- docs/prd/
- docs/sdd/
- docs/stories/
- docs/sales/
- docs/reviews/
- .productflow/
2. SEGURANCA
Verificar:
[CRITICAL]
- settings.local.json NAO deve estar versionado (git ls-files)
- settings.local.json deve estar no .gitignore
- .quarantine/ deve estar no .gitignore
[WARNING]
- tmpclaude-* diretorios presentes
- arquivo "nul" presente
- Outros artefatos de sistema
3. AGENTES (Consistencia)
Para cada agente em .claude/agents/:
[REQUIRED - Front Matter]
- name: presente
- description: presente
- tools: lista definida
- disallowedTools: lista definida (pode ser vazia)
- model: definido
[REQUIRED - Secoes]
- <ROLE>
- <GOALS>
- <INPUTS_REQUIRED>
- <PROCESS>
- <OUTPUTS>
- <QUALITY_BAR>
- <EDGE_CASES>
- <HANDOFF>
4. COMANDOS (Consistencia)
Para cada comando em .claude/commands/:
[REQUIRED - Front Matter]
- description: presente
- argument-hint: presente
[REQUIRED - Secoes]
- ## Entrada (com $ARGUMENTS)
- ## O que fazer
- ## Output
- ## Exemplos
5. LIXO (Artefatos Suspeitos)
Procurar e listar:
[SHOULD NOT EXIST]
- tmpclaude-*-cwd/ (qualquer nivel)
- arquivo "nul" ou "NUL"
- .DS_Store (no root)
- Thumbs.db (no root)
- __pycache__/ (em qualquer nivel)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 225 lines · 10 tokens per session scan A 3428a7e28d8a
pf-doctor is a command published in the GitHub repository matheusbrramos/ProductFlow (2 stars, last pushed 5mo ago), licensed MIT. It adds 10 tokens to every session and 1,269 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
bug-report
Draft a bug report issue for lean4-skills.
triage
Query open Node bugs, classify by priority and sub-team, suggest assignments, and generate a triage summary.
speckit.companion.doctor
Report on a spec's run health — unfinished steps, unjournaled tasks, step bleed, drift you can judge, a step that closed having verified nothing, a step that closed without the file it promised, and why completion did not land (read-only, retroactive, never halts).
harvest-errors
Analyze the latest test262 run results, cross-reference with existing issues, and create new issues for unaddressed error patterns.
postmortem
Deliver a structured post-mortem after incidents, mistakes, or stuck sessions. Use when the user requests a structured post-mortem after incidents, mistakes, or stuck sessions.
harness:maintenance-pipeline
On-demand, report-first maintenance sweep — runs overdue checks via harness maintenance run, triages findings, and asks the human in plain text before dispatching any fix.