Borrowing it
Nothing to install: this file belongs to Cratis/VerticalSlices. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Cratis/VerticalSlices/main/.ai/skills/add-business-rule/SKILL.mdgit clone --depth 1 https://github.com/Cratis/VerticalSlicesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cratis/verticalslices/add-business-rule)<a href="https://agentmods.dev/skills/cratis/verticalslices/add-business-rule"><img src="https://agentmods.dev/badge/skills/cratis/verticalslices/add-business-rule/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/cratis/verticalslices/add-business-rule"><img src="https://agentmods.dev/badge/skills/cratis/verticalslices/add-business-rule.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00032 | $0.01478 |
| Opus 5 | $0.00016 | $0.00739 |
| Sonnet 5 | $0.00006 | $0.00296 |
| Haiku 4.5 | $0.00003 | $0.00148 |
Grade A, and why
add-business-rule scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to add-business-rule — 2 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 112 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Add a business rule or event-store constraint to an existing command.
Choose the right mechanism
Pick by what the decision is — see vertical-slices.md "The decision matrix":
| Scenario | Use |
|---|---|
| Reusable value invariant (length, format, range) | ConceptValidator<T> on the concept type |
| Command-input / cross-field / pre-handler rule (incl. injected read-model/service checks) | CommandValidator<TCommand> with RuleFor(...) |
| Handler needs fetched/computed data before it can build the event | Provide() — fetch the data; short-circuit with ValidationResult.Error(...) if unusable |
| State-dependent rule that must hold under concurrency | inject the read model into Handle(), return Result<TEvent, ValidationResult> |
| Single-event uniqueness (most cases) | [Unique] attribute on the event type |
Multi-event uniqueness or needs RemovedWith |
IConstraint |
| Genuinely exceptional failure (bug, missing infra) | throw a custom domain exception |
Never throw for normal business rejection. A thrown exception from
Provide()/Handle()surfaces asHasExceptions/ HTTP 500 — not a validation result. Recoverable, user-facing rejections are validation: return them via a validator,Provide(), orResult<TEvent, ValidationResult>.
Business rules via DCB (read model as Handle() argument)
Use when the rule depends on Chronicle event-sourced state (current count, accumulated value) and must hold under concurrency. The framework injects the current read-model snapshot, resolved by the command's event-source id, before Handle() runs. Return a Result<TEvent, ValidationResult> — success carries the event, failure carries a typed validation error.
The read model must already exist in the slice ([ReadModel] + a model-bound projection). If it doesn't, add it first — see the add-projection / cratis-readmodel skills.
[Command]
public record AddItemToCart(CartId CartId, ItemId ItemId)
{
/// <summary>Adds the item; rejects when the cart already holds the maximum.</summary>
/// <param name="cart">The current cart summary (injected by event-source id).</param>
/// <returns>The event on success, or a validation error.</returns>
public Result<ItemAddedToCart, ValidationResult> Handle(CartSummary cart) =>
cart.ItemCount >= 3
? ValidationResult.Error("A cart can hold at most 3 items.")
: new ItemAddedToCart(ItemId);
}
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 112 lines · 32 tokens per session scan A e94076cb3fc2
add-business-rule is a skill published in the GitHub repository Cratis/VerticalSlices (2 stars, last pushed 7d ago), licensed MIT. It adds 32 tokens to every session and 1,478 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to add-business-rule, differing in 2 lines, and is treated as a copy.
Other skills, from other repositories
cratis-chronicle-client-kotlin
Talk to a Chronicle server from a Kotlin or Java application with the io.cratis:chronicle client - connection strings, ChronicleClient and the Spring Boot starter, @EventType classes, suspending append, reactors and reducers dispatched by first-parameter type, model-bound read models, classpath artifact discovery, and…
cratis-chronicle-client-dotnet
Talk to a Chronicle server from a standalone .NET application with the Cratis.Chronicle client - connection strings, ChronicleClient construction outside any host, AddCratisChronicle for a worker or ASP.NET host, [EventType] records, IEventSequence.Append, reactors and reducers found by assembly scanning, the…
cratis-chronicle-client-elixir
Talk to a Chronicle server from an Elixir application with the cratischronicle Hex package - putting Chronicle.Client in a supervision tree, connection strings, use Chronicle.Events.EventType structs, Chronicle.append returning ok or error tuples, reactors with the @handles attribute and a handle/2 callback…
cratis-chronicle-client-typescript
Talk to a Chronicle server from a Node.js or TypeScript application with @cratis/chronicle - reflect-metadata and decorator compiler settings, ChronicleClient and connection strings, @eventType classes, eventLog.append, reactors and reducers dispatched by camelCase method name, model-bound and declarative projections…
cratis-command
Step-by-step guidance for creating a Cratis Arc command — [Command] record, Handle() method, CommandValidator, proxy generation, and React .use() hook with CommandDialog. Use when adding or creating a command, wiring up a form or button to the backend, working with IEventLog, CommandResult, CommandValidator…
cratis-chronicle-reactor
Implement a Chronicle IReactor - an automation that causes an external side effect, or a translation that appends follow-up events. Covers handler dispatch and parameter resolution, every supported return type, targeting another event source, replay handling with [OnceOnly] and [Replay], event filtering, failure and…