Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/hafeok/product-cli/product-buildnpx skills add Hafeok/product-cli --skill product-buildgit clone --depth 1 https://github.com/Hafeok/product-cliWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hafeok/product-cli/product-build)<a href="https://agentmods.dev/skills/hafeok/product-cli/product-build"><img src="https://agentmods.dev/badge/skills/hafeok/product-cli/product-build.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00088 | $0.01143 |
| Opus 5 | $0.00044 | $0.00571 |
| Sonnet 5 | $0.00018 | $0.00229 |
| Haiku 4.5 | $0.00009 | $0.00114 |
Grade A, and why
product-build scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 82 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Product Session — the Build phase
Delivery is partitioning the What graph into shippable slices; "done" is a computed predicate, not a judgement (§7). Realise each slice through its work units, gate it with verifications, and finalize.
Precondition: product_workflow_status → phase must be build. If not, use
product-session.
The question script
- Slice — which section of the event model ships? Anchor it on the relevant
nodes. →
product_slice_new id=<s> anchors=[…] depth=N; inspect withproduct_slice_show/product_slice_context. - Deliverable —
product_deliverable_new id=<d> slice=<s> acceptance=["<id>: <statement>", …]. §7.2 (the gotcha): each criterion is the literal formid: statement, and the statement must be a checkable predicate, not a judgement — e.g."journal-created: .product/sessions/<id>/workflow.json exists after start", not "the start works well". Non-predicate criteria are rejected. - Work units must already exist.
product_build_runconsumes the §5 work units for the slice; if none target it, it falls back to unrelated units. Work units are produced in the How phase byproduct_cell_dispatch(bind the cell's slots to the slice's entities) — and that tool freezes once you're in Build (phases are forward-only). So dispatch every unit your deliverables will need before advancing from How. If you reach Build and one is missing, you cannot dispatch here — finalize and fix in a fresh pass. - Dry-run the build first —
product_build_run deliverable=<d> dry_run=true. It returns the assembled SPMC context, the worker + parallel run plan, the verify plan, and the gate status — with no worker dispatched. Review it before spending a real run. - Build it — two ways:
- In-process worker:
product_build_run deliverable=<d>dispatches the worker per the role bindings, writes artifacts, runs the gates. - Hand it to a Claude Code session:
product_build_emit deliverable=<d>returns a self-contained SPMC prompt (frozen What/How/Behaviour/Acceptance + the work-unit build plan in order + the verify commands). Save it and runclaude -p "$(cat <file>)"from the repo root, orproduct build <d> --emit-spmcto write.product/build/<d>.spmc.mddirectly. The agent builds every artifact at its declared path and makes the verify commands pass.
- In-process worker:
- Acceptance verdicts — bind a runner so the build auto-verifies a criterion:
product_deliverable_runner id=<d> criterion=<c> runner=cargo-test args="<test filter>"(orrunner=shell args="<command>"). Then the §6 verify step runs it and records the verdict. Without a runner, record manually withproduct_deliverable_accept id=<d> criterion=<c> status=passing|failing.product_deliverable_donecomputes whether the deliverable is done (§7.2). - Release (optional) —
product_release_newgroups deliverables;product_release_donechecks the cut is closed (no dangling dependency). - Finalize —
product_session_finalizevalidates the What, stamps provenance, and closes the session. Everything authored in the session (the What graph, How, and delivery artifacts alike) is already in canonical.product/— finalize is the conformance gate, not a promotion.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 82 lines · 88 tokens per session scan A a1cc64605ec5
product-build is a skill published in the GitHub repository Hafeok/product-cli (6 stars, last pushed 8d ago), licensed MIT. It adds 88 tokens to every session and 1,143 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…
chronicle
Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…