Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add danweinerdev/claude-sdd-planner --skill sdd-poke-holesgit clone --depth 1 https://github.com/danweinerdev/claude-sdd-plannerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/danweinerdev/claude-sdd-planner/sdd-poke-holes)<a href="https://agentmods.dev/skills/danweinerdev/claude-sdd-planner/sdd-poke-holes"><img src="https://agentmods.dev/badge/skills/danweinerdev/claude-sdd-planner/sdd-poke-holes/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/danweinerdev/claude-sdd-planner/sdd-poke-holes"><img src="https://agentmods.dev/badge/skills/danweinerdev/claude-sdd-planner/sdd-poke-holes.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00037 | $0.02021 |
| Opus 5 | $0.00018 | $0.01010 |
| Sonnet 5 | $0.00007 | $0.00404 |
| Haiku 4.5 | $0.00004 | $0.00202 |
Grade A, and why
sdd-poke-holes scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 120 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Adversarial Critical Analysis
Resources
Before opening shared/..., follow symlinks in this loaded file's path, then derive <plugin-root> from <plugin-root>/skills/<name>/SKILL.md; fallback search roots are repository/user .agents/ (including $HOME/.agents/plugins/*/), Codex ${CODEX_HOME:-$HOME/.codex}/plugins/cache/*/*/*/, and runtime-configured skill roots. Accept only a root containing this skill, shared/agent-runtime.md, and the matching plugin manifest; never use the working directory. Then read <plugin-root>/shared/agent-runtime.md and <plugin-root>/shared/path-resolution.md, and resolve every shared/<path> reference in this skill against <plugin-root>.
Resource boundary: Read the plugin, all SKILL.md files, and shared/ resources in place. Never copy or symlink them into the working directory, target repository, or planning root. Only generated SDD outputs may be materialized from bundled resources.
When to Use
When you need an adversarial critical review of a planning artifact before committing to it. Good for stress-testing plans before approval, finding gaps in specs, and challenging design assumptions. This is not a structural review (the plan-review prompt (shared/agent-prompts/plan-reviewer.md) and the spec-review prompt (shared/agent-prompts/spec-reviewer.md) handle that). This skill actively tries to break the thinking.
Think of it as the planning-artifact counterpart to the review_blind_spots lane (shared/review-prompts/blind-spots.md) (which does the same thing against code diffs): fresh eyes, hostile framing, deliberately looking for what the author didn't think about.
Process
-
Identify Target
- Ask which artifact to analyze (plan, spec, design, or brainstorm)
- Confirm the artifact path before proceeding
-
Gather Context Read the full target artifact yourself in the primary context (a single-artifact read is lightweight and the raw wording is the attack surface). Dispatch the researcher prompt (
shared/agent-prompts/researcher.md) only for the related-context sweep:- Read all documents referenced in the target's
relatedfrontmatter - Search for any specs, designs, or plans that reference this artifact (by filename or title)
- Return a structured summary containing:
- Related context that informs analysis (from
relateddocs and reverse references) - Cross-references, dependencies, and any conflicts between documents
- Related context that informs analysis (from
- Read all documents referenced in the target's
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 120 lines · 37 tokens per session scan A 324d64668791
sdd-poke-holes is a skill published in the GitHub repository danweinerdev/claude-sdd-planner (2 stars, last pushed 2d ago), licensed MIT. It adds 37 tokens to every session and 2,021 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
hns-lsel-curator
Local Self-Evolution Loop (LSEL) curator — the CLUSTER + drain engine for the GOOS-local PROPOSE→APPLY seam closure (SPEC-LSEL-LOCAL-EVOLUTION-001). Companion-offset drain of .moai/lessons-inbox.jsonl with a drain-side severity filter that drops the 65% Bash-timeout/sandbox noise, eventkey clustering with a frequency…
moai-workflow-worktree
Git worktree management for parallel SPEC development with isolated workspaces, automatic branch registration, and seamless MoAI-ADK integration. Use when setting up parallel development environments.
hns-workflow-ci-loop
Unified CI watch + auto-fix loop skill. Polls gh pr checks after /moai sync PR creation, classifies required vs auxiliary failures, attempts safe automated patches (max 3 iterations), and escalates semantic failures to the user. Use for CI loop workflow — NOT for general loop iteration patterns (see…
hns-moaiadk-patterns
Skill "hns-moaiadk-patterns" from modu-ai/moai-adk, covering moai-adk-go domain patterns, architecture quick reference, key source paths, pipeline specialist delegation map and template-first build cycle.
moai-harness-learner
Harness learning subsystem coordinator. Produces Tier 4 auto-update proposal payloads consumed by the orchestrator (which surfaces them via AskUserQuestion) and orchestrates Apply/Rollback flows. Triggers when harness learning proposals are pending or learning lifecycle management is needed.
moai-kanban-foreman
One unattended kanban foreman iteration: watch the backlog queue, dispatch the next operator-picked card to an isolated worker, collect completion evidence on read (not on claims), and report. This is the body the project's loop.md driver invokes each iteration of a bare /loop; it can also be invoked directly to test…