Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/stanislavnianko/product-discovery-claude-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/stanislavnianko/product-discovery-claude-skills/discovery-phase)<a href="https://agentmods.dev/plugins/stanislavnianko/product-discovery-claude-skills/discovery-phase"><img src="https://agentmods.dev/badge/plugins/stanislavnianko/product-discovery-claude-skills/discovery-phase/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/stanislavnianko/product-discovery-claude-skills/discovery-phase"><img src="https://agentmods.dev/badge/plugins/stanislavnianko/product-discovery-claude-skills/discovery-phase.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
discovery-phase scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "discovery-phase",
"description": "Outsourcing-first product discovery skill pack. 25 skills across 7 groups (foundation, discovery, evidence, synthesis, scoping, validation, deliverables) — drives a BA / agency / consultant from rough brief to validated proposal, prototype, or go/no-go decision. Skills run independently or via the optional discovery-conductor.",
"author": {
"name": "Stanislav Nianko",
"email": "[email protected]"
}
}
What it installs
The manifest is a name and a version. 25 skills travel with it, and installing the plugin installs all of them — 1,794 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill solution-architecture A 84 tokens
- Skill profile-builder A 114 tokens
- Skill insight-synthesis A 67 tokens
- Skill user-interviews A 78 tokens
- Skill journey-mapping A 80 tokens
- Skill proposal A 64 tokens
- Skill competitive-scan A 68 tokens
- Skill discovery-handoff A 72 tokens
- Skill estimation A 69 tokens
- Skill feasibility-spike A 71 tokens
- Skill feature-scoping A 73 tokens
- Skill go-nogo-memo A 66 tokens
- Skill mvp-definition A 73 tokens
- Skill opportunity-mapping A 67 tokens
- Skill personas A 72 tokens
- Skill problem-framing A 61 tokens
- Skill prototype-plan A 64 tokens
- Skill research-planning A 66 tokens
- Skill risk-assumption-mapping A 77 tokens
- Skill sow-draft A 66 tokens
- Skill stakeholder-mapping A 65 tokens
- Skill support-data-analysis A 63 tokens
- Skill discovery-conductor A 85 tokens
- Skill secondary-research A 60 tokens
- Skill sme-workshops A 69 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 9 lines scan A 0b23216a7d3f
discovery-phase is a plugin published in the GitHub repository stanislavnianko/product-discovery-claude-skills (1 stars, last pushed 4mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
prd-taskmaster
Zero-config goal-to-tasks engine for Claude Code (the Atlas engine). Graded PRD validation, dependency-ordered task graph, and CDD-verified execution.
pushary
Push notifications, human-in-the-loop questions, and permission gating for AI agents. When a running agent is about to do something irreversible, is blocked on a decision that is not its to make, or finishes a long task with nobody watching, it reaches you on your phone and you answer from the lock screen.
pm-skills
PM workflow and product thinking skills for AI product managers. 17 structured frameworks covering PRDs, prioritization, metrics, strategy, product sense, research synthesis, and more.
nextjs
Official Next.js skills: adopt and optimize Cache Components, adopt Partial Prefetching, and verify runtime behavior against a running dev server.
themes-example
themes-example. An open-source AI agent that brings the power of Gemini directly into your terminal.
claude-plugins-official marketplace
Directory of popular Claude Code extensions including development tools, productivity plugins, and MCP integrations.