Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/ihudak/ihudak-claude-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/ihudak/ihudak-claude-plugins/product-workflows)<a href="https://agentmods.dev/plugins/ihudak/ihudak-claude-plugins/product-workflows"><img src="https://agentmods.dev/badge/plugins/ihudak/ihudak-claude-plugins/product-workflows/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/ihudak/ihudak-claude-plugins/product-workflows"><img src="https://agentmods.dev/badge/plugins/ihudak/ihudak-claude-plugins/product-workflows.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
product-workflows scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "product-workflows",
"version": "3.3.3",
"description": "Twelve slash commands for the product-definition half of the dev-workflows pipeline: a six-command BRD-to-PRD route (/brd-intake → /brd-split → /prd-ground → /brd-split → /brd-interview → /brd-package → /brd-reconcile) that grounds a customer's requirements document, settles it with them, and seeds the PRD, ARD and specification; the idea→PRD→ARD→specification ladder (/idea → /create-prd → /update-prd → /create-ard → /specify), where /prd-ground now also optionally grounds the PRD itself, feeding /create-ard and /specify; and /epics, deriving phase-appropriate Epics from a PRD. Twelve agents carry the grounding, reconciliation, PRD/ARD/spec/Epic review, and Epic writing these commands share. Ten reference pages define the BRD, code-defect-log, decision-register, coverage-ledger, customer-review, idea, ARD and specification artifact formats.",
"author": {
"name": "Ivan Gudak",
"email": "[email protected]"
},
"homepage": "https://github.com/ihudak/ihudak-claude-plugins/tree/main/plugins/product-workflows",
"repository": "https://github.com/ihudak/ihudak-claude-plugins",
"license": "MIT",
"dependencies": [
"workflows-core",
"prose-style"
],
"keywords": [
"idea",
"prd",
"ard",
"specify",
"epics",
"brd",
"requirements",
"product-management",
"workflow"
]
}
What it installs
The manifest is a name and a version. 12 commands, 12 agents travel with it, and installing the plugin installs all of them — 2,796 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Command brd-reconcile A 287 tokens
- Command brd-split A 0 tokens
- Command prd-ground A 389 tokens
- Command brd-interview A 256 tokens
- Command brd-package A 254 tokens
- Command create-ard A 0 tokens
- Command create-prd A 0 tokens
- Command epics A 156 tokens
- Command specify A 0 tokens
- Command idea A 267 tokens
- Command brd-intake A 151 tokens
- Command update-prd A 0 tokens
- Agent grounding-verifier A 107 tokens
- Agent idea-reader A 138 tokens
- Agent brd-package-reviewer A 52 tokens
- Agent customer-review-reader A 78 tokens
- Agent design-grounder A 0 tokens
- Agent epic-reviewer A 77 tokens
- Agent code-grounder A 129 tokens
- Agent epic-writer A 110 tokens
- Agent brd-reader A 73 tokens
- Agent prd-reviewer A 97 tokens
- Agent ard-reviewer A 107 tokens
- Agent spec-reviewer A 68 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 28 lines scan A 2fcf1c0d1899
product-workflows is a plugin published in the GitHub repository ihudak/ihudak-claude-plugins (2 stars, last pushed today), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-09.
Other plugins, from other repositories
pm-execution
Execution and product management skills: PRDs, OKRs, roadmaps, sprints, pre-mortems, stakeholder maps, user stories, prioritization frameworks, and more.
ados marketplace
Agentic Delivery OS - AI-powered software delivery system with 10-phase workflow.
draft
Context-Driven Development: draft specs and plans before implementation. Structured workflows for features and fixes.
odin-core
Core ODIN gates every session runs: intent, scope, verification, and hand-off checks.
atlassian
Run Jira and Confluence from a conversation, including reviewed Jira or Jira Align refresh with capability-scoped write-back.
github
Read GitHub Issues or Milestones into repository intake, then review refresh deltas and confirm narrow coordination write-back.