Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/arsxxi/iterative-dev-workflow/workflow-methodologynpx skills add Arsxxi/iterative-dev-workflow --skill workflow-methodologygit clone --depth 1 https://github.com/Arsxxi/iterative-dev-workflowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00002 | $0.05615 |
| Opus 5 | $0.00001 | $0.02808 |
| Sonnet 5 | $0.00000 | $0.01123 |
| Haiku 4.5 | $0.00000 | $0.00562 |
Grade A, and why
workflow-methodology scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 563 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Step 0 - figure out what we're building (do this FIRST, before anything else)
Look at what was passed in: $ARGUMENTS
-
If it already clearly states a project name, a real description of what to build, AND the platform/stack (e.g. "React Native non-Expo", "Python backend service", "LLM agent pipeline"), confirm your understanding back to me in one or two sentences and proceed to the section below.
-
If any of those three are missing or vague, stop and ask me:
- What are we building? (be as comprehensive as you want me to be - the more detail, the better Phase 1 will be)
- What platform/stack is this for? (e.g. mobile app - React Native/Expo/native, backend service, LLM/agent pipeline, web frontend, CLI tool, etc. - this changes what Phase 1's library/service analysis actually looks like)
- What short project name should identify it? (used for the
.workflow/<slug>/folder, e.g.article-quality-widget)
Do not guess or invent a feature, and do not assume a default platform/stack (do not assume React Native or anything else) to analyze. Do not proceed past this point until I've answered.
Also ask (can be part of the same question round): what services/infra already exist in this project that Phase 1 should treat as "Existing Services" (e.g. a specific backend, database, auth provider, third-party APIs already wired up) - versus what's clearly new and would count as "Proposed Services". If I say I'm not sure or there's nothing existing yet, that's a valid answer - don't invent a services list.
Once you know the platform/stack and existing services, use them consistently for the rest of this workflow (Phase 1's library/package questions, Phase 2's architecture diagrams, etc. should all be framed for this specific project, not a generic or assumed one).
Step 1 - once we know what we're building
Here is the workflow we use for every feature, regardless of platform/stack:
- Phase 1: Analyze - requirements, libraries/packages, Existing vs. Proposed services, 5 candidate development paths, ATAM + SQALE, final timeline.
- Phase 2: Design - Solution Proposal (low-fidelity, divergent) -> ATAM -> Quality Attribute Assessment (weighted scoring, may loop back to the proposal bucket) -> High-Fidelity Design (System Context + User Flow diagrams in Mermaid.js).
- Phase 3: Implement - build it, following the High-Fidelity Design.
- Phase 4: Post-Mortem - retrospective.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 563 lines · 2 tokens per session scan A 807766b82824
workflow-methodology is a skill published in the GitHub repository Arsxxi/iterative-dev-workflow (2 stars, last pushed 1mo ago), licensed MIT. It adds 2 tokens to every session and 5,615 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
redteam
Expertise in offensive security research, vulnerability analysis, CMS-focused application testing, and red team operations.
redteam-source-audit
Focused source-code security review workflow for web applications, CMS extensions, APIs, and supporting services.
redteam-cms
Focused methodology for authorized CMS fingerprinting, component inventory, misconfiguration review, and vulnerability validation.
redteam-exploit-validation
Focused workflow for validating exploitability safely and turning candidate issues into reproducible, bounded proof.
redteam-recon
Focused reconnaissance workflow for authorized security assessments, bug bounty triage, lab targets, and CTF infrastructure.
redteam-reporting
Focused reporting workflow for converting verified red-team work into clear, reproducible assessment artifacts.