vibe-scope-guard

vibe-scope-guard is a skill for Claude Code, Codex from ash1794/vibe-engineering. It costs 31 tokens per session (603 once invoked), scanned A, original, MIT.

A coding-scope checker that watches implementation work for requests or changes that were not actually asked for.

In plain words
What is it for?
Use it while implementing a feature to question unrequested additions, premature abstractions, gold-plating, and unrelated cleanup.
Why use it?
Coding tasks can grow through unnecessary features, refactoring, abstractions, or configuration. This helps keep the work focused on the requested result.

Skill for Claude CodeCodex

Part of the vibe-engineering plugin — 38 skills shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/ash1794/vibe-engineering/scope-guard
Any agent
npx skills add ash1794/vibe-engineering --skill scope-guard
Clone the repo
git clone --depth 1 https://github.com/ash1794/vibe-engineering

Made for: Claude Code, Codex.

Or install vibe-engineering, the plugin that ships this one along with the rest of its 38 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for vibe-scope-guard

README.md
[![agentmods](https://agentmods.dev/badge/skills/ash1794/vibe-engineering/scope-guard.svg)](https://agentmods.dev/skills/ash1794/vibe-engineering/scope-guard)
Your own site
<a href="https://agentmods.dev/skills/ash1794/vibe-engineering/scope-guard"><img src="https://agentmods.dev/badge/skills/ash1794/vibe-engineering/scope-guard.svg" alt="Measured on agentmods" height="20"></a>
Per session 31 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 603 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00031 $0.00603
Opus 5 $0.00015 $0.00302
Sonnet 5 $0.00006 $0.00121
Haiku 4.5 $0.00003 $0.00060

Measured 5d ago against content hash 7682bea04b6d, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

vibe-scope-guard scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

plugins/vibe-engineering/skills/scope-guard/SKILL.md · 69 lines

How it starts

The opening of the file, as written. The whole thing — 69 lines — stays where its author put it; the contents beside it link to each section on GitHub.

vibe-scope-guard

The best code is the code you don't write. Stay focused on what was asked.

When to Use This Skill

  • During any implementation task
  • When you notice you're "improving" code that wasn't in the request
  • When implementation is taking longer than expected
  • When you're about to create an abstraction "for later"

When NOT to Use This Skill

  • During brainstorming (ideas should be unconstrained)
  • When the user explicitly asks for broad improvements
  • When scope expansion is necessary for correctness

Scope Creep Signals

Watch for these patterns:

Signal Example Response
Unrequested features "While I'm here, let me add caching" Stop. Was caching requested?
Premature abstraction "Let me create a generic helper for this" Is it used more than once?
Gold plating "Let me add comprehensive error messages for every case" Only at system boundaries
Refactoring drive-by "This function could be cleaner" Was refactoring requested?
Over-engineering "Let me make this configurable" Does anyone need configuration?
Documentation creep "Let me add docstrings to all these functions" Only to functions you changed
Test over-expansion "Let me test every possible input" Test the boundaries, not every input

The Rule

Three similar lines of code is better than a premature abstraction.

Before adding anything not explicitly requested, ask:

  1. Was this requested? → No → Don't do it
  2. Is it necessary for correctness? → No → Don't do it
  3. Will it break without this? → No → Don't do it
  4. Is the user watching time/cost? → Yes → Definitely don't do it

Steps

When you detect scope creep:

  1. Stop — Don't commit the extra work
  2. Acknowledge — "I notice I'm adding [X] which wasn't requested"
  3. Offer — "Would you like me to also [X], or should I stay focused on [original task]?"
  4. If declined — Revert the extra work, continue with original scope
  5. If accepted — Proceed, but track it separately

Read the full file on GitHub · 69 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 69 lines · 31 tokens per session scan A 7682bea04b6d

Subscribe to this mod's changes

vibe-scope-guard is a skill published in the GitHub repository ash1794/vibe-engineering (10 stars, last pushed 3mo ago), licensed MIT. It adds 31 tokens to every session and 603 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

wechat-article-writer

公众号/自媒体全流程。根据用户表述自动匹配:撰写文章、封面图、正文插图、风格提取。支持多种写作风格。当用户提到写公众号、技术博客、公众号封面、正文插图、步骤图、演示图、流程示意、分析写作风格、克隆文风、模仿爆款、提取风格时使用。详见 reference 目录。.

xstongxue/best-skills · 105 tokens

prepare-release

Prepare a new release by collecting commits, generating bilingual release notes, updating version files, and creating a release branch. Use when asked to prepare/create a release, bump version, or run /prepare-release.

CherryHQ/cherry-studio · 44 tokens

find-skills

Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.

CherryHQ/cherry-studio · 67 tokens

cherry-assistant-guide

从当前安装包查询 Cherry Studio 产品信息并排查运行问题。当用户询问功能、路由、快捷键、Provider、语言、Agent、频道、定时任务、Code CLI、当前版本,或报告运行错误、连接失败、配置异常并需要诊断时触发。.

CherryHQ/cherry-studio · 68 tokens

cherry-electron-dev

Develop, fix, and profile Cherry Studio in a tracked Electron instance. Use for everyday implementation, UI and interaction work, bug fixing, runtime debugging, DevTools inspection, lag or jank investigation, CPU and memory monitoring, leak checks, and startup-performance analysis; reuse a verified workspace instance…

CherryHQ/cherry-studio · 75 tokens

issue-reporter

只在用户明确要求提交 GitHub Issue、GitHub Bug Report 或 GitHub Feature Request 时使用。用户只说“提交问题”“提交反馈”“上报 bug”“这是个 bug”或描述功能建议但未点名 GitHub 时不得触发,必须改用 cherry-studio-feedback 并默认提交飞书。.

CherryHQ/cherry-studio · 73 tokens