constraints

constraints is a command for Claude Code from vinvcn/addyosmani-agent-skills-zh. It costs 20 tokens per session (726 once invoked), scanned A, original, MIT.

A command for defining a project's quality standards through a short interview and a written CONSTRAINTS.md file. It records checks, thresholds, exceptions, and commands for enforcing them.

In plain words
What is it for?
It helps set up quality gates, choose measurable thresholds, install relevant checking tools, and connect those checks to project commands and agent instructions.
Why use it?
It prevents important standards such as testing, security, performance, or accessibility from being left as informal expectations. It also makes clear which checks block work and which only warn.

Command for Claude Code

Written for Claude Code: $ARGUMENTS substitution. Also seen: mentions CLAUDE.md.

Part of the agent-skills plugin — 26 skills, 10 commands, 4 agents, 1 hook shipped together

Good fit It helps set up quality gates, choose measurable thresholds, install relevant checking tools, and connect those checks to project commands and agent instructions.

Compare 6 commands from other repositories ↓
Install with agentmods
npx agentmods add commands/vinvcn/addyosmani-agent-skills-zh/constraints
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/vinvcn/addyosmani-agent-skills-zh

Made for: Claude Code.

Or install agent-skills, the plugin that ships this one along with the rest of its 26 skills, 10 commands, 4 agents, 1 hook.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for constraints

README.md
[![agentmods](https://agentmods.dev/badge/commands/vinvcn/addyosmani-agent-skills-zh/constraints/github.svg)](https://agentmods.dev/commands/vinvcn/addyosmani-agent-skills-zh/constraints)
Your own site
<a href="https://agentmods.dev/commands/vinvcn/addyosmani-agent-skills-zh/constraints"><img src="https://agentmods.dev/badge/commands/vinvcn/addyosmani-agent-skills-zh/constraints/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for constraints

Your own site · 80×15
<a href="https://agentmods.dev/commands/vinvcn/addyosmani-agent-skills-zh/constraints"><img src="https://agentmods.dev/badge/commands/vinvcn/addyosmani-agent-skills-zh/constraints.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 20 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 726 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00020 $0.00726
Opus 5.5 $0.00008 $0.00290
Sonnet 5 $0.00004 $0.00145
Haiku 4.5 $0.00002 $0.00073

Measured 12d ago against content hash 72f1435020e8, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-28, from the pricing page.

Security

Grade A, and why

constraints scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/commands/constraints.md · 33 lines

What it actually says

调用 agent-skills:constraint-driven-development skill。

$ARGUMENTS

不带参数时的默认行为:为本仓库设置 constraints。

  1. 先检测。 读取 package.json / pyproject.toml / go.mod、test runner、现有 lint configs、当前 coverage 输出、CI workflows,以及正在使用的 agent harness。用两行汇报你的发现。绝不询问任何你自己能读到的东西。

  2. 访谈,最多四个问题。 一次一个,每个都附上你的最佳猜测和一个可用的默认值,让 "我不知道" 也能产出一份能用的配置:

    • 除了 floor 之外还要哪些维度(coverage、security、performance、accessibility、architecture)
    • 任务中途某项检查失败时,是 block 还是 warn
    • 目标数值,还是测量今天的值并守住它们
    • 在把工作交还给人之前,能容忍的最慢一次检查
  3. 在仓库根目录编写 CONSTRAINTS.md,包含 Floor 部分、被强制执行的数值、仅测量类指标及其今日数值,以及一张带 owner 和到期日期的 exceptions 表。每个数值都需要给出陈述过的理由。

  4. 为每个选中的维度安装所需工具。 一个维度有数值却背后没有工具,那只是愿望。使用事实标准工具,让现有配置继续可用:代码扫描用 Semgrep,secrets 用 gitleaks(始终带 --redact),依赖用 osv-scanner,accessibility 用 axe-core,web vitals 用 Lighthouse,bundles 用 size-limit,boundaries 用 dependency-cruiser,断言质量用 Stryker。在 CONSTRAINTS.md 中把确切命令记录在每条规则旁边。Accessibility 和 performance 需要一个可运行的 URL;如果项目没有,如实说明并舍弃该维度,而不是编造一项检查。把这些命令作为 check:fast / check:task / check:full 添加到 package.json。

  5. 按成本摆放每项检查。 Types、lint 和 secrets 放在 edit loop 里(秒级)。相关 tests 和 changed-line coverage 放在任务结束时(90 秒以内)。其余全部放在 review 或 CI 中。检查范围限定在 diff,而不是整个仓库。

  6. 让 agent 指向它。 在 CLAUDE.md 中加一行,告诉 agents 阅读 CONSTRAINTS.md,且绝为了让某个变更通过而弱化它。

  7. 验证。 对当前分支运行这些 constraints。如果某项失败而用户不同意,现在就修 constraint,而不是留下一个人们会学着无视的门禁。

子命令:

  • /constraints check — 对当前分支运行现有 constraints 并报告
  • /constraints guard — 在 diff 中检查被弱化的标准:调低的阈值、被跳过或删除的 tests、新增的 suppression 注释、未完成的 stubs、新增的 exceptions
  • /constraints ratchet — 把今天的测量值记录为不得下降的 floor
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 33 lines · 20 tokens per session scan A 72f1435020e8

Subscribe to this mod's changes

constraints is a command published in the GitHub repository vinvcn/addyosmani-agent-skills-zh (36 stars, last pushed 13d ago), licensed MIT. It adds 20 tokens to every session and 726 once invoked, about $0.0001 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-16.