Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add HoangNguyen0403/agent-skills-standard --skill sdlcgit clone --depth 1 https://github.com/HoangNguyen0403/agent-skills-standardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hoangnguyen0403/agent-skills-standard/sdlc)<a href="https://agentmods.dev/skills/hoangnguyen0403/agent-skills-standard/sdlc"><img src="https://agentmods.dev/badge/skills/hoangnguyen0403/agent-skills-standard/sdlc/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hoangnguyen0403/agent-skills-standard/sdlc"><img src="https://agentmods.dev/badge/skills/hoangnguyen0403/agent-skills-standard/sdlc.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00022 | $0.01624 |
| Opus 5 | $0.00011 | $0.00812 |
| Sonnet 5 | $0.00004 | $0.00325 |
| Haiku 4.5 | $0.00002 | $0.00162 |
Grade A, and why
sdlc scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 114 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Sdlc Skill
[!IMPORTANT] Route a task to the next synced SDLC workflow based on current artifacts and repo state.
Optional args: slug=, ticket=<id/url>, mode=interactive|autonomous|channel, channel=, auto_continue=true|false, profile=business|hybrid|technical.
Instructions
When the user asks to perform this workflow, execute the following steps:
SDLC Router Workflow
Goal: Select the next native workflow without loading every workflow body, while preserving a traceable BA -> PM -> IT Department handoff for offshore delivery.
Steps
-
Inspect state:
- User request; infer
operator_profile(business | hybrid | technical) percommon-operator-profileand carry it in every Handoff Payload. - Search
docs/brd/,docs/prd/, anddocs/srs/for a matching[slug]; if absent, use the newest BRD orgit status. Slug = lowercase kebab-case, minted once atbrainstorm-feature, reused verbatim downstream; never re-derived. - If multiple candidates exist, list them and ask whether to focus, consolidate, or sequence.
- Baseline reference:
docs/requirements-standards-baseline.md - Existing ticket, BRD-lite brief, PRD, SRS/FRS design, implementation plan, task list, walkthrough, UAT signoff, deployment report, release notes, and retro
- Jira, ADO, Zephyr, or other MCP context when already configured
- Changed files and current test status
- Offshore delivery context: business owner, product owner, implementation owners, QA owner, timezone/cadence constraints, environments, release window, and dependency teams
- Requirement trace health:
BRD-OBJ-* -> REQ-* -> AC-* -> SRS-* -> test evidence
- User request; infer
-
Choose next workflow (apply tie-break order when multiple bullets match: (1) workflow explicitly named by the operator or by the latest
recommended_next_workflow, (2) production-incident/urgent-regression signals, (3) earliest missing artifact along the chain below — never skip forward past a gap, (4) cross-cutting audits only on request or as a pre-release gate):- Unclear idea, missing business case, missing stakeholder owner, or missing measurable value (BRD-lite / Why, BA-owned intake) ->
brainstorm-feature - BRD-lite exists or business direction is clear but product scope, priorities, acceptance criteria, rollout, or delivery plan are unclear (PRD / What, PM-owned planning) ->
plan-feature - Scale, topology, capacity, or store choice unsettled, or an existing system needs an architecture audit ->
system-design-session - PRD exists but technical behavior/contracts unclear (SRS/FRS / How) ->
design-solution - Architecture, auth, trust boundaries, compliance controls, or agent/runtime safety need deeper technical validation ->
design-solution - BRD-lite, PRD, or SRS/FRS exists but readiness unclear ->
implementation-readiness - Approved plan with BRD/PRD/SRS trace and testable ACs needs code ->
implement-feature - Production incident or urgent regression ->
incident-hotfix - Bug ticket needs fix (non-urgent) ->
dev-fix - Ticket or cross-functional change needs specialist fanout, AC coverage, and PR metadata review ->
review-ticket - Design arrives as an artifact (diagram, doc, board export, IaC) and needs review ->
review-system-design - PR diff needs focused merge-risk review ->
code-review - Implementation GREEN but ACs lack executable E2E/mobile coverage, or an E2E suite is red after a previously green slice ->
test-loop. - Code complete but unproven ->
verify-work - Fix implemented and ticket has a UAT/Jira flow ->
verify-bug verify-workPASS on a feature, business acceptance not yet granted ->uat-signoff- Business acceptance granted and release window open ->
deploy-release - Deployed and needs user-facing communication ->
publish-notes - Trace health unknown before release or handoff ->
traceability-audit - Session ending with unfinished work or context handoff ->
session-report - Deployed or communicated, capture standards/process lessons ->
retro-learn - Repo-wide health/debt question with no single feature in scope ->
codebase-review
- Unclear idea, missing business case, missing stakeholder owner, or missing measurable value (BRD-lite / Why, BA-owned intake) ->
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago Changed · +1 lines 59d92a3fc2c5
- 9d ago First seen · 113 lines · 22 tokens per session scan A 9ebb258e0544
sdlc is a skill published in the GitHub repository HoangNguyen0403/agent-skills-standard (565 stars, last pushed 3d ago), licensed MIT. It adds 22 tokens to every session and 1,624 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
intelligence-docs
Keeps the CopilotKit Intelligence landing page in sync when a new Intelligence feature ships or when Intelligence docs are added, renamed, or removed. Use when adding Intelligence capabilities, writing or moving pages under docs/intelligence, editing IntelligenceFeatureCards, or changing…
plan
PM planning workflow that gathers requirements, decomposes them into prioritized tasks, defines API contracts, and produces both a machine-readable plan and a human-readable tracker in docs/plans/.
coordinate-pro
Thorough version of coordinate - high-quality development workflow with 11 review steps out of 17.
coordinate
Coordinate multiple agents for a complex multi-domain project using PM planning, parallel agent spawning, and QA review.
exec-plan
Create, manage, and track execution plans as first-class repository artifacts in docs/exec-plans/.
work
Coordinate multiple agents for a complex multi-domain project using PM planning, parallel agent spawning, and QA review.