Borrowing it
Nothing to install: this file belongs to Harery/OCTALUME. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Harery/OCTALUME/main/.claude/skills/idea/SKILL.mdgit clone --depth 1 https://github.com/Harery/OCTALUMEWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/harery/octalume/idea)<a href="https://agentmods.dev/skills/harery/octalume/idea"><img src="https://agentmods.dev/badge/skills/harery/octalume/idea.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00183 | $0.03304 |
| Opus 5 | $0.00092 | $0.01652 |
| Sonnet 5 | $0.00037 | $0.00661 |
| Haiku 4.5 | $0.00018 | $0.00330 |
Grade A, and why
octalum-idea scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 308 lines — stays where its author put it; the contents beside it link to each section on GitHub.
OCTALUME Idea — Brain Dump → Build Orchestrator
Part of the OCTALUME framework (https://github.com/Harery/OCTALUME). This skill powers Phase 0 — the idea intake that feeds OCTALUME's 8-phase SDLC.
Who does what
You (Claude) own everything — A to Z:
- Discovery, analysis, business logic, architecture, stack decisions
- All writing: BRD, MVP, specs, plans, constitution, CLAUDE.md, MEMORY.md, HANDOFF.md
- All technical work: logic design, diagrams, code generation, deployment, monitoring, maintenance
- All research: live web search for tools, versions, pricing, competitors, SEO data
- Every role — product manager, business analyst, architect, engineer, DevOps — all yours
The operator's only job:
- Pass the real customer's raw idea to you
- Translate the customer's intent when something is unclear
- Say yes, no, or revise at each stage gate
- Answer gaps you cannot infer on your own
- The operator does NOT build. Does NOT code. Does NOT make technical decisions.
Before every session: Read references/operating-constraints.md.
For voice/tone: Read references/voice-guide.md.
Pyramid Questioning System — NON-NEGOTIABLE
Questions narrow as pipeline descends. Load only the active layer's rules.
Stage 1 → MACRO — vision, users, problem space, big picture
Stages 2–3 → MESO — business model, revenue, competition, scope
Stages 4–5 → MICRO — features, flows, roles, constraints
Stages 6–7 → NANO — technical specifics, architecture, security
Stage 8 → ATOMIC — task-level logic and diagrams
Stages 9–12 → BUILD — generate, monitor, maintain (no new questions)
Stage 1 — Dynamic Intake (Question 0 + 9 generated questions)
The intake is never static. Every project is different — so every set of questions must be too.
Step 0 — Ask for the raw idea first
Before generating any questions, send exactly this as your opening message:
"Tell me about your idea — don't worry about structure, don't worry about details. Just write it the way you'd explain it to a friend. I'll read everything you give me and come back with the right questions."
What ships with it
17 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/architecture.md 10 KB
- references/build-handoff.md 4.3 KB
- references/enhancements.md 9.0 KB
- references/operating-constraints.md 7.5 KB
- references/voice-guide.md 2.7 KB
- stages/s01-intake.md 4.7 KB
- stages/s02-brd.md 1.9 KB
- stages/s03-mvp.md 1.7 KB
- stages/s04-business-analysis.md 2.7 KB
- stages/s05-business-plan.md 2.6 KB
- stages/s06-tech-stack.md 6.2 KB
- stages/s07-constitution.md 10 KB
- stages/s08-logic.md 2.1 KB
- stages/s09-diagrams.md 1.8 KB
- stages/s10-build.md 1.4 KB
- stages/s11-monitoring.md 3.4 KB
- stages/s12-maintenance.md 2.8 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 308 lines · 183 tokens per session scan A f541ff579899
octalum-idea is a skill published in the GitHub repository Harery/OCTALUME (2 stars, last pushed 1mo ago), licensed MIT. It adds 183 tokens to every session and 3,304 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
raigo-owasp-llm
RAIGO × OWASP LLM Top 10 — official OWASP LLM Application Security Top 10 (2025) enforcement rules for Hermes agents. Covers all 10 OWASP LLM risks: prompt injection, insecure output handling, training data poisoning, model denial of service, supply chain vulnerabilities, sensitive information disclosure, insecure…
raigo
RAIGO Agent Firewall — comprehensive AI security policy enforcement for Hermes agents. Covers all known prompt security attack vectors: prompt injection, jailbreaks, encoding obfuscation, indirect injection, system prompt extraction, credential exfiltration, destructive commands, code injection, rogue agent detection…
extract
Run the full Semantica semantic extraction pipeline on a file or selected text — NER, relations, events, coreference resolution, triplets, and validation. Clears result cache before each run. Returns Markdown tables with entity/relation/event/triplet results and inline validator warnings.
dd-synthesis
Synthesize findings from multiple specialist agents into a coherent investment recommendation. Use when combining reports from 9+ specialist agents into a single decision document.
octocode-roast
Use when code needs a blunt evidence-backed roast or memorable critique: smell inventory, debt ranking, hot-path autopsy, savage/diff review, security or performance sins, or practical redemption paths. Phrases like roast this, brutal review, top sins, cleanup debt. Polite evidence-first PR review → octocode-research.
dataforseo-mcp-server
Run DataForSEO API tasks via the CLI in a shell (docs index, docs search, request). Use when the agent should execute terminal commands with npx dataforseo-mcp-server.