VerticalSlices: Skill for Claude Code

.ai/skills/add-business-rule/SKILL.md

add-business-rule is a skill for Claude Code, Codex from Cratis/VerticalSlices. It costs 32 tokens per session (1,478 once invoked), scanned A, a copy of add-business-rule, MIT.

A guide for adding validation rules or uniqueness checks to an existing command in a Cratis project. A command is a request to change or process something.

In plain words
What is it for?
Use it to add checks for values, related fields, fetched data, state-dependent conditions, or duplicate event data.
Why use it?
It helps put each rule in the right place and avoids treating normal business rejections as unexpected server errors.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

This is Cratis/VerticalSlices's own configuration. It tells Claude Code and Codex how to work on VerticalSlices itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything VerticalSlices configures →

Reuse

Borrowing it

Nothing to install: this file belongs to Cratis/VerticalSlices. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/Cratis/VerticalSlices/main/.ai/skills/add-business-rule/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/Cratis/VerticalSlices

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for add-business-rule

README.md
[![agentmods](https://agentmods.dev/badge/skills/cratis/verticalslices/add-business-rule/github.svg)](https://agentmods.dev/skills/cratis/verticalslices/add-business-rule)
Your own site
<a href="https://agentmods.dev/skills/cratis/verticalslices/add-business-rule"><img src="https://agentmods.dev/badge/skills/cratis/verticalslices/add-business-rule/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for add-business-rule

Your own site · 80×15
<a href="https://agentmods.dev/skills/cratis/verticalslices/add-business-rule"><img src="https://agentmods.dev/badge/skills/cratis/verticalslices/add-business-rule.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 32 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,478 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00032 $0.01478
Opus 5 $0.00016 $0.00739
Sonnet 5 $0.00006 $0.00296
Haiku 4.5 $0.00003 $0.00148

Measured 10d ago against content hash e94076cb3fc2, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

add-business-rule scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to add-business-rule — 2 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.ai/skills/add-business-rule/SKILL.md · 112 lines

How it starts

The opening of the file, as written. The whole thing — 112 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Add a business rule or event-store constraint to an existing command.

Choose the right mechanism

Pick by what the decision is — see vertical-slices.md "The decision matrix":

Scenario Use
Reusable value invariant (length, format, range) ConceptValidator<T> on the concept type
Command-input / cross-field / pre-handler rule (incl. injected read-model/service checks) CommandValidator<TCommand> with RuleFor(...)
Handler needs fetched/computed data before it can build the event Provide() — fetch the data; short-circuit with ValidationResult.Error(...) if unusable
State-dependent rule that must hold under concurrency inject the read model into Handle(), return Result<TEvent, ValidationResult>
Single-event uniqueness (most cases) [Unique] attribute on the event type
Multi-event uniqueness or needs RemovedWith IConstraint
Genuinely exceptional failure (bug, missing infra) throw a custom domain exception

Never throw for normal business rejection. A thrown exception from Provide()/Handle() surfaces as HasExceptions / HTTP 500 — not a validation result. Recoverable, user-facing rejections are validation: return them via a validator, Provide(), or Result<TEvent, ValidationResult>.

Business rules via DCB (read model as Handle() argument)

Use when the rule depends on Chronicle event-sourced state (current count, accumulated value) and must hold under concurrency. The framework injects the current read-model snapshot, resolved by the command's event-source id, before Handle() runs. Return a Result<TEvent, ValidationResult> — success carries the event, failure carries a typed validation error.

The read model must already exist in the slice ([ReadModel] + a model-bound projection). If it doesn't, add it first — see the add-projection / cratis-readmodel skills.

[Command]
public record AddItemToCart(CartId CartId, ItemId ItemId)
{
    /// <summary>Adds the item; rejects when the cart already holds the maximum.</summary>
    /// <param name="cart">The current cart summary (injected by event-source id).</param>
    /// <returns>The event on success, or a validation error.</returns>
    public Result<ItemAddedToCart, ValidationResult> Handle(CartSummary cart) =>
        cart.ItemCount >= 3
            ? ValidationResult.Error("A cart can hold at most 3 items.")
            : new ItemAddedToCart(ItemId);
}

Read the full file on GitHub · 112 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 112 lines · 32 tokens per session scan A e94076cb3fc2

Subscribe to this mod's changes

add-business-rule is a skill published in the GitHub repository Cratis/VerticalSlices (2 stars, last pushed 7d ago), licensed MIT. It adds 32 tokens to every session and 1,478 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to add-business-rule, differing in 2 lines, and is treated as a copy.

Related

Other skills, from other repositories

cratis-chronicle-client-kotlin

Talk to a Chronicle server from a Kotlin or Java application with the io.cratis:chronicle client - connection strings, ChronicleClient and the Spring Boot starter, @EventType classes, suspending append, reactors and reducers dispatched by first-parameter type, model-bound read models, classpath artifact discovery, and…

Cratis/AI · 121 tokens

cratis-chronicle-client-dotnet

Talk to a Chronicle server from a standalone .NET application with the Cratis.Chronicle client - connection strings, ChronicleClient construction outside any host, AddCratisChronicle for a worker or ASP.NET host, [EventType] records, IEventSequence.Append, reactors and reducers found by assembly scanning, the…

Cratis/AI · 123 tokens

cratis-chronicle-client-elixir

Talk to a Chronicle server from an Elixir application with the cratischronicle Hex package - putting Chronicle.Client in a supervision tree, connection strings, use Chronicle.Events.EventType structs, Chronicle.append returning ok or error tuples, reactors with the @handles attribute and a handle/2 callback…

Cratis/AI · 112 tokens

cratis-chronicle-client-typescript

Talk to a Chronicle server from a Node.js or TypeScript application with @cratis/chronicle - reflect-metadata and decorator compiler settings, ChronicleClient and connection strings, @eventType classes, eventLog.append, reactors and reducers dispatched by camelCase method name, model-bound and declarative projections…

Cratis/AI · 128 tokens

cratis-command

Step-by-step guidance for creating a Cratis Arc command — [Command] record, Handle() method, CommandValidator, proxy generation, and React .use() hook with CommandDialog. Use when adding or creating a command, wiring up a form or button to the backend, working with IEventLog, CommandResult, CommandValidator…

Cratis/AI · 80 tokens

cratis-chronicle-reactor

Implement a Chronicle IReactor - an automation that causes an external side effect, or a translation that appends follow-up events. Covers handler dispatch and parameter resolution, every supported return type, targeting another event source, replay handling with [OnceOnly] and [Replay], event filtering, failure and…

Cratis/AI · 91 tokens