Borrowing it
Nothing to install: this file belongs to akaghef/M3E. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/akaghef/M3E/main/.agents/skills/kiro-discovery/SKILL.mdgit clone --depth 1 https://github.com/akaghef/M3EWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/akaghef/m3e/kiro-discovery)<a href="https://agentmods.dev/skills/akaghef/m3e/kiro-discovery"><img src="https://agentmods.dev/badge/skills/akaghef/m3e/kiro-discovery/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/akaghef/m3e/kiro-discovery"><img src="https://agentmods.dev/badge/skills/akaghef/m3e/kiro-discovery.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00044 | $0.02866 |
| Opus 5.5 | $0.00018 | $0.01146 |
| Sonnet 5.5 | $0.00009 | $0.00573 |
| Haiku 4.5 | $0.00004 | $0.00287 |
Grade A, and why
kiro-discovery scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
94% identical to kiro-discovery — 34 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 263 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Discovery
<background_information>
- Success Criteria:
- Correct action path or work decomposition identified based on existing project state
- User's intent clarified through questions, not assumptions
- Output is an actionable next step (not just a description) </background_information>
Step 1: Lightweight Scan
Gather only metadata to determine the action path. Do NOT read full file contents yet.
- Specs inventory: Scan
.kiro/specs/*/spec.jsonforname,phasefields andapprovalsstatus. Note feature names and their current status. - Steering existence: Check which files exist in
.kiro/steering/(product.md, tech.md, structure.md, roadmap.md). Do NOT read their contents yet. - Roadmap check: If
.kiro/steering/roadmap.mdexists, read it. This contains project-level context (approach, scope, constraints, spec list) from a previous discovery session. Use it to restore project context. - Top-level structure: List the project root directory to note key directories and files. Do NOT recurse into subdirectories.
This step should consume minimal context. If specs/ is empty and no steering exists, note "greenfield project" and move to Step 2.
Step 2: Determine Action Path
Based on the user's request and the metadata from Step 1, determine which path applies:
Path A: Existing spec covers this
- The request is an extension, enhancement, or fix within an existing spec's domain
- Every meaningful part of the request fits that same spec boundary
- Any remaining small follow-up work can be handled directly without creating a new spec
- Skip remaining steps
Path B: No spec needed
- The request is a bug fix, config change, simple refactor, or trivial addition
- No meaningful part of the request needs a new or updated spec boundary
- The request does not need to update an existing spec either
- Skip remaining steps
Path C: New single-scope feature
- The request is new, doesn't overlap with existing specs, and fits in one spec
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 263 lines · 44 tokens per session scan A f437f9e1cded
kiro-discovery is a skill published in the GitHub repository akaghef/M3E (11 stars, last pushed 5d ago), licensed MIT. It adds 44 tokens to every session and 2,866 once invoked, about $0.0002 per session on Opus 5.5. A static security scan graded it A with 0 findings. It is 94% identical to kiro-discovery, differing in 34 lines, and is treated as a copy.
Other skills, from other repositories
story-readiness
Is a story implementation-ready? Checks clear acceptance criteria, open questions, ADR refs. READY/NEEDS WORK/BLOCKED/NOT ASSESSED.
recipe-create-meet-space
Create a Google Meet meeting space and share the join link.
workthreads
SpecStory Workthreads - a weekly work-thread rollup across a team's repos from SpecStory coding histories (any agent - Claude Code, Codex, Cursor, Gemini, and more). It groups the window's sessions into threads of work per project and labels each new / open / recently closed, so a lead sees what shipped, what is still…
atmos-config
Atmos root configuration: atmos.yaml discovery, precedence, deep merging, basepath, imports, minimal bootstrap, and routing to narrower Atmos skills.
projects
List all managed projects with status, branch, open PRs, and open issue counts — portfolio-level view.
remove
Remove a deployed framework or addon from the current workspace.