Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Abhillashjadhav/AI-PM-essential-skills --skill builder-validatorgit clone --depth 1 https://github.com/Abhillashjadhav/AI-PM-essential-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/abhillashjadhav/ai-pm-essential-skills/builder-validator)<a href="https://agentmods.dev/skills/abhillashjadhav/ai-pm-essential-skills/builder-validator"><img src="https://agentmods.dev/badge/skills/abhillashjadhav/ai-pm-essential-skills/builder-validator/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/abhillashjadhav/ai-pm-essential-skills/builder-validator"><img src="https://agentmods.dev/badge/skills/abhillashjadhav/ai-pm-essential-skills/builder-validator.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00139 | $0.00716 |
| Opus 5 | $0.00069 | $0.00358 |
| Sonnet 5 | $0.00028 | $0.00143 |
| Haiku 4.5 | $0.00014 | $0.00072 |
Grade A, and why
builder-validator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 46 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Builder-Validator
Lock the spec first, build second, audit third. The builder never grades its own homework mid-flight — validation is a separate pass against criteria frozen before generation began.
Step 1 — Freeze the spec (silent)
Extract every stated requirement into binary (yes/no) criteria. Rules:
- Each criterion must be checkable by reading the output alone (no "feels good").
- Mark each as GATE (failure = artifact rejected) or SCORE (failure = noted, tradeable).
- If a requirement is vague ("make it engaging"), convert to a proxy ("opens with a specific number or question") — record the conversion but don't narrate it to the user.
- Never invent facts to pass a gate. If a gate-critical criterion depends on a fact not given by the user — a date, a name, a number, a policy detail, a metric — stop and ask the user for it before drafting. Do not fabricate a plausible-sounding value to make the criterion checkable.
- Freeze the checklist silently. It cannot change during this cycle. Show only the audit result (Step 3), not the checklist itself. If the user adds requirements later, that starts a new cycle with a new frozen spec.
Step 2 — Build
Generate the artifact. Do not reference the checklist while generating beyond following the requirements — no criterion-by-criterion writing, which produces stilted output.
Step 3 — Validate (separate pass)
Re-read the frozen checklist, then audit the artifact criterion by criterion. Output this scorecard:
SPEC AUDIT — cycle N
GATES: [PASS/FAIL] <criterion> — <one-line evidence>
SCORES: [PASS/FAIL] <criterion> — <one-line evidence>
RESULT: X/Y passed. Gates: ALL PASS | FAILED (list)
Step 4 — Iterate or ship
- Any GATE failed → revise the artifact targeting only the failed criteria, re-audit. Max 3 cycles, then stop and report what's stuck and why.
- All gates pass → present the artifact + final scorecard.
- Never silently revise: every cycle's scorecard is shown.
Limitations
- Criteria quality bounds audit quality: vague specs produce weak proxies; the checklist itself stays silent, but every proxy conversion is still recorded and available if the user asks to see the frozen spec.
- Self-audit by the same model has blind spots; for high-stakes artifacts, recommend a second-model or human review of the frozen checklist itself.
- Max 3 cycles is a cost guardrail, not a quality guarantee.
- Silence on the checklist is a presentation choice, not a secrecy rule: the user can always ask to see the frozen criteria before or after the audit.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 46 lines · 139 tokens per session scan A 5dc0def66f3e
builder-validator is a skill published in the GitHub repository Abhillashjadhav/AI-PM-essential-skills (3 stars, last pushed 9d ago), licensed MIT. It adds 139 tokens to every session and 716 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
github-code-review
Comprehensive GitHub code review with AI-powered swarm coordination.
recipe-create-meet-space
Create a Google Meet meeting space and share the join link.
x-tweet-by-conversation
Collects every tweet in an X (Twitter) conversation thread given a conversation id (root tweet id) — the focal tweet plus all replies, sub-replies, and quote chains — and returns normalized per-tweet data with text, author, engagement counts, media, hashtags, mentions, inreplyto mapping, and cursor for pagination. Use…
atmos-validation
Validate Atmos projects, components, arbitrary JSON Schema inputs, EditorConfig, and GitHub Actions; use affected-file selection and native CI annotations.
atmos-config
Atmos root configuration: atmos.yaml discovery, precedence, deep merging, basepath, imports, minimal bootstrap, and routing to narrower Atmos skills.
detecting-privilege-escalation-in-kubernetes-pods
Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.