Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add J-StaR-Films-Studios/VibeCode-Protocol-Suite --skill engineering-principlesgit clone --depth 1 https://github.com/J-StaR-Films-Studios/VibeCode-Protocol-SuiteWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/j-star-films-studios/vibecode-protocol-suite/engineering-principles)<a href="https://agentmods.dev/skills/j-star-films-studios/vibecode-protocol-suite/engineering-principles"><img src="https://agentmods.dev/badge/skills/j-star-films-studios/vibecode-protocol-suite/engineering-principles/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/j-star-films-studios/vibecode-protocol-suite/engineering-principles"><img src="https://agentmods.dev/badge/skills/j-star-films-studios/vibecode-protocol-suite/engineering-principles.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00030 | $0.01666 |
| Opus 5 | $0.00015 | $0.00833 |
| Sonnet 5 | $0.00006 | $0.00333 |
| Haiku 4.5 | $0.00003 | $0.00167 |
Grade A, and why
engineering-principles scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 40 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Engineering Principles Suite
A catalogue of 21 foundational principles for software architecture, code quality, state management, and agentic workflows.
Principles Catalog
Read the specific principle file via view_file on demand when applying its rule:
| Principle | When to Apply | File Path |
|---|---|---|
boundary-discipline |
Apply when wiring validation, error handling, or framework adapters. Concentrate guards at system boundaries (CLI, config, network, external APIs); trust internal types and keep business logic in pure functions. | boundary-discipline/SKILL.md |
build-the-lever |
Apply to any non-trivial work, not just bulk work: edits, migrations, analyses, checks. Build the tool that does it or proves it (codemod, script, generator, or a skill your subagents follow) instead of working by hand. The tool is the artifact a reviewer can rerun. | build-the-lever/SKILL.md |
encode-lessons-in-structure |
Apply when you catch yourself writing the same instruction a second time, or notice a recurring correction. Encode the rule as a lint, metadata flag, runtime check, or script instead of more text. | encode-lessons-in-structure/SKILL.md |
exhaust-the-design-space |
Apply when facing a novel UI interaction or architectural decision with no precedent in the codebase. Build 2-3 competing prototypes and compare side by side before committing. | exhaust-the-design-space/SKILL.md |
experience-first |
Apply when product, UX, or feature-scope tradeoffs come up. Choose user delight over implementation convenience; ship fewer polished features over more rough ones. | experience-first/SKILL.md |
fix-root-causes |
Apply when debugging. Trace each symptom to its root cause and fix it there; reproduce first, ask why until you reach it, resist nil-check guards that silence crashes. | fix-root-causes/SKILL.md |
foundational-thinking |
Apply before writing logic: choosing core types and data structures, sequencing scaffold-vs-feature work, asking what concurrent actors share. Get the data structures right so downstream code becomes obvious. | foundational-thinking/SKILL.md |
guard-the-context-window |
Apply when context is filling up: large outputs, long files, repeated reads, fan-out planning. Route bulk to subagents; keep summaries in the main thread, not raw payloads. | guard-the-context-window/SKILL.md |
laziness-protocol |
Apply when refactoring, evaluating diff size, or tempted to add abstractions, layers, or signal threading. Bias toward deletion and the smallest change that solves the problem. | laziness-protocol/SKILL.md |
make-operations-idempotent |
Apply when designing commands, lifecycle steps, or processing loops that run amid crashes, restarts, and retries. Converge to the same end state regardless of partial prior runs. | make-operations-idempotent/SKILL.md |
migrate-callers-then-delete-legacy-apis |
Apply when introducing a new internal API while old callers still exist. Migrate callers and delete the old API in the same wave instead of preserving compatibility layers. | migrate-callers-then-delete-legacy-apis/SKILL.md |
minimize-reader-load |
Apply when reviewing or shaping code that's hard to trace. Count layers between question and answer, and hidden state in the reader's head; collapse one-caller wrappers and shrink mutable scope. | minimize-reader-load/SKILL.md |
model-the-domain |
Apply when writing stateful logic, or when code branches a lot or repeats a shape assumption across files. Encode the domain in a structure instead of scattered conditionals. | model-the-domain/SKILL.md |
never-block-on-the-human |
Apply when tempted to ask 'should I do X?' on reversible work. Proceed, present the result, let the human course-correct after the fact; reserve confirmation for irreversible actions. | never-block-on-the-human/SKILL.md |
outcome-oriented-execution |
Apply during planned rewrites and migrations with explicit phase boundaries. Converge on the target architecture; don't preserve smooth intermediate states with throwaway compatibility code. | outcome-oriented-execution/SKILL.md |
prove-it-works |
Apply after completing a task, before declaring done. Verify against the real artifact (run the feature, read the actual value, inspect the diff), not a proxy, self-report, or 'it compiles.' | prove-it-works/SKILL.md |
redesign-from-first-principles |
Apply when integrating a new requirement into an existing design. Redesign as if the requirement had been a foundational assumption from day one, instead of bolting it on. | redesign-from-first-principles/SKILL.md |
separate-before-serializing-shared-state |
Apply when concurrent actors might write to the same file, branch, key, or state object. Eliminate the sharing first; serialize structurally only when one shared writer is a real invariant. | separate-before-serializing-shared-state/SKILL.md |
sequence-verifiable-units |
Apply to multi-step work (sweeps, migrations, runs of similar edits) and to how you stack commits and PRs. Break work into small units that each end in a verifiable state, check each before the next, and order delivery so the sequence proves itself to a reviewer. | sequence-verifiable-units/SKILL.md |
subtract-before-you-add |
Apply when sequencing an addition, refactor, or rewrite. Remove dead weight, redundant validators, and stub references first, then build on the simpler base. | subtract-before-you-add/SKILL.md |
type-system-discipline |
Apply when designing types, reviewing a function signature, or writing code in any statically-typed language. Make illegal states unrepresentable, brand semantic primitives, parse external data at boundaries, refuse to lie to the compiler, exhaust variants, derive from authoritative schemas. | type-system-discipline/SKILL.md |
What ships with it
21 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- boundary-discipline/SKILL.md 1.9 KB
- build-the-lever/SKILL.md 2.5 KB
- encode-lessons-in-structure/SKILL.md 2.2 KB
- exhaust-the-design-space/SKILL.md 1.1 KB
- experience-first/SKILL.md 1.3 KB
- fix-root-causes/SKILL.md 1.3 KB
- foundational-thinking/SKILL.md 1.7 KB
- guard-the-context-window/SKILL.md 1.1 KB
- laziness-protocol/SKILL.md 1.5 KB
- make-operations-idempotent/SKILL.md 1.4 KB
- migrate-callers-then-delete-legacy-apis/SKILL.md 1.1 KB
- minimize-reader-load/SKILL.md 2.0 KB
- model-the-domain/SKILL.md 2.1 KB
- never-block-on-the-human/SKILL.md 1.6 KB
- outcome-oriented-execution/SKILL.md 1.1 KB
- prove-it-works/SKILL.md 2.0 KB
- redesign-from-first-principles/SKILL.md 943 B
- separate-before-serializing-shared-state/SKILL.md 1.6 KB
- sequence-verifiable-units/SKILL.md 2.2 KB
- subtract-before-you-add/SKILL.md 1.3 KB
- type-system-discipline/SKILL.md 5.0 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 40 lines · 30 tokens per session scan A 8050fcac9b94
engineering-principles is a skill published in the GitHub repository J-StaR-Films-Studios/VibeCode-Protocol-Suite (24 stars, last pushed today), licensed ISC. It adds 30 tokens to every session and 1,666 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
discount-review
Inspect the discount policy fixture with a repeatable review checklist and helper script.
code-review
Perform comprehensive code reviews focusing on best practices, security vulnerabilities, performance optimization, and maintainability.
code-review
Reviews code for bugs, security issues, and best practices.
code-review-csharp
Perform structured code reviews of C# source code covering naming conventions, performance, security, readability, and .NET best practices. Trigger phrases include "review this C# code", "check my C# for best practices", "analyze this C# class", "find issues in my C# code".
mcp-server-review
Review a Model Context Protocol (MCP) server implementation against the 2026-07-28 protocol revision, which removed the initialize handshake and Mcp-Session-Id and made the protocol stateless. Use when the user asks to review, audit, upgrade or migrate an MCP server, asks whether their MCP server is spec compliant…
refactor-advisor
A code review helper that finds common design and maintenance problems in a codebase and suggests ways to restructure the code.