workflow

A method for building features as bounded workflows instead of open-ended agent loops. It lays out stages along the data flow and requires each failure to return to one named stage with a limited budget or be sent to a person.

In plain words
What is it for?
Use it to design an LLM-based feature, define its stages and recovery paths, front-load contracts and invariants, create a state machine, check side effects, and prepare the workflow for execution.
Why use it?
Clear stages reduce the need for repeated guessing, decomposition, and clock-based correction. The approach produces contracts and checks that make the feature's behavior inspectable.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/cognitive-fab/polygraph/workflow
Any agent
npx skills add cognitive-fab/polygraph --skill workflow
Clone the repo
git clone --depth 1 https://github.com/cognitive-fab/polygraph

Made for: Claude Code, Codex.

Per session 227 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,769 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00227 $0.01769
Opus 5 $0.00113 $0.00885
Sonnet 5 $0.00045 $0.00354
Haiku 4.5 $0.00023 $0.00177

Measured 2d ago against content hash 9d13c728f284, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/workflow/SKILL.md · 133 lines

How it starts

The opening of the file, as written. The whole thing — 133 lines — stays where its author put it; the contents beside it link to each section on GitHub.

workflow — build it as a workflow, not a loop

The composition skill: where polygen authors one machine, this skill builds the whole feature the workflows-not-loops way, driving the other engines in order. The method's premise (after Adron Hall's "Loop Engineering" critique): an agentic loop exists to compensate for starved context, missing decomposition, and clock-driven correction — remove each reason and the loop collapses into a directed, checkable workflow. Each of those removals is an ARTIFACT here, not advice.

The full worked recipe with rationale is ${CLAUDE_PLUGIN_ROOT}/examples/workflows-not-loops/MANUAL.md; the two reference builds are ${CLAUDE_PLUGIN_ROOT}/examples/workflows-not-loops/ (document pipeline, incl. the v1→v2 polyvers evolution) and ${CLAUDE_PLUGIN_ROOT}/examples/todo-machine/ (an ordinary app: durable per-item timers replacing the cron scan, plus an HTTP shell). Read the MANUAL before Step 1; crib file shapes from the examples, not from memory.

Same disclosure as every engine: the checks are exhaustive over the contract's DECLARED finite domains — a consistency check, not a proof. The contract and invariants are a reading of intent and need the user's review.

Step 1 — Draw the pipeline as data flow (WITH the user, no tools)

One line per stage: what comes in, what goes out, what can go wrong. Then force the two-answer rule — for EVERY failure the user must pick exactly one:

  • bend back to ONE named stage, carrying the exact signal (violation, reason) verbatim, under a bounded budget (pick the number now); or
  • escalate to a human, terminal, with the reason recorded.

"Retry the whole thing" / "re-plan" is not an option — that is the loop sneaking back in. If the user cannot name the target stage and the signal, the design is not done. Also decide the fuzzy middle now: which single stage(s) does a model own? Everything else must be a deterministic function.

Step 2 — Contract + invariants (front-loaded context)

Read the full file on GitHub · 133 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 133 lines · 0 tokens per session scan A 9d13c728f284

Subscribe to this mod's changes

workflow is a skill published in the GitHub repository cognitive-fab/polygraph (11 stars, last pushed 5d ago), licensed Apache-2.0. It adds 227 tokens to every session and 1,769 once invoked, about $0.0011 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

electron-node-upgrade

Guide for performing Node.js version upgrades in the Electron project. Use when working on the roller/node/main branch to fix patch conflicts during e sync --3. Covers the patch application workflow, conflict resolution, analyzing upstream Node.js changes, building, running the Node.js test suite, and proper commit…

electron/electron · 69 tokens

lint-js

Lint JS/TS code only. Use before opening a PR when only JavaScript or TypeScript files were changed (no Rust).

denoland/deno · 29 tokens

Shade dropdown surface contract

DropdownMenu, Select, and Popover share one visual recipe (bg-surface-elevated-2 + border-border/60 dark:border-border/30 + shadow-md). Change them together. Trigger when editing any of those three Shade files.

TryGhost/Ghost · 54 tokens

Shade ShadCN install

Guardrails for running pnpm dlx shadcn@latest add in Shade — never overwrite existing components, fresh branch first, swap raw colours for semantic tokens after integrating. Trigger when the user proposes a shadcn add, or when a fresh ShadCN-shaped file lands in apps/shade/src/components/ui.

TryGhost/Ghost · 72 tokens

Shade use primitives

Replace bare divs that only carry flex/grid/gap utilities with Shade primitives (Stack, Inline, Box, Grid, Container, Text). Use semantic gap="md" instead of gap-4. Trigger when editing TSX in Shade-consuming apps.

TryGhost/Ghost · 54 tokens

geometry-and-math

Use this skill when using Phaser 4 math and geometry utilities. Covers vectors, rectangles, circles, triangles, polygons, random number generation, angles, distance, interpolation, and snapping. Triggers on: Vector2, Rectangle, Circle, math, distance, angle, random, lerp.

phaserjs/phaser · 64 tokens