Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add khadinakbarlabs/shopify-app-builder --skill app-validationgit clone --depth 1 https://github.com/khadinakbarlabs/shopify-app-builderWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/khadinakbarlabs/shopify-app-builder/app-validation)<a href="https://agentmods.dev/skills/khadinakbarlabs/shopify-app-builder/app-validation"><img src="https://agentmods.dev/badge/skills/khadinakbarlabs/shopify-app-builder/app-validation.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00103 | $0.04694 |
| Opus 5 | $0.00051 | $0.02347 |
| Sonnet 5 | $0.00021 | $0.00939 |
| Haiku 4.5 | $0.00010 | $0.00469 |
Grade A, and why
app-validation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 494 lines — stays where its author put it; the contents beside it link to each section on GitHub.
When to Use This Skill
Call this when:
- You have an app idea and need confidence before 4 weeks of build time
- You want to avoid false starts with market validation first
- You need to prioritize which app idea to build if you have multiple
- You're mid-build and getting customer feedback signals
Do NOT use this if:
- You've already shipped and have paying customers (use metrics instead)
- You're in execution mode and decided to build (stay focused)
The 7-Question Pre-Build Validation Framework
Answer all 7 questions with your best estimate. Score each 1-5 (5 = strong yes, 1 = strong no).
Question 1: Problem Severity (Does it hurt bad enough?)
"On a scale of 1-5, how much pain do merchants have right now?"
- 5: Merchants spend 5+ hours/week on this; lose money if unsolved; manual workaround fails 50%+ of the time
- 4: Spend 2-5 hours/week; workaround exists but tedious; minor money loss
- 3: Spend <2 hours/week; annoying but manageable workaround
- 2: Nice-to-have improvement; low time cost
- 1: Merchants don't really complain about this
Validation method: Ask 5 merchants "How many hours/week does [problem] cost you?" If 4/5 say >2 hours, you're at 4-5.
Red flag: If score <3, problem is aspirational, not acute. Merchants won't pay.
Question 2: Willingness-to-Pay Signal (Will they actually pay?)
"Would a typical merchant in your target market pay $X/month for this?"
- 5: Multiple merchants have said "Yes, I'd pay $50+/month for this"
- 4: 3+ merchants said "Maybe $25-30/month" unprompted
- 3: Merchants said "Maybe I'd try it if free" or "Could work at $10/month"
- 2: "I'd use it if free but wouldn't pay"
- 1: "Not worth paying for"
Validation method: Ask in interviews: "What's the maximum you'd pay monthly for this? What's minimum to make it worth your time?" If 4/5 say >$15, score 4-5.
Red flag: If score <3, problem is real but not monetizable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 494 lines · 103 tokens per session scan A c78739202ce7
app-validation is a skill published in the GitHub repository khadinakbarlabs/shopify-app-builder (1 stars, last pushed 28d ago), licensed MIT. It adds 103 tokens to every session and 4,694 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
nft-standards
Implement NFT standards (ERC-721, ERC-1155) with proper metadata handling, minting strategies, and marketplace integration. Use when creating NFT contracts, building NFT marketplaces, or implementing digital asset systems.
ebay-search
Search eBay listings - find items, auctions, deals, and compare prices.
ulw-execute
Executes a written Prometheus work plan with Boulder state, evidence ledger, worktree discipline, and parallel subagents. Use when the user says ulw-execute or asks to run a .omo/plans plan.
frontend
Builds, styles, and polishes web UI and UX. Use for any frontend, page, component, styling, layout, animation, or visual-quality task, or when asked to make an interface look or feel a certain way.
review-work
Post-implementation gate review: run manual QA on the real surface yourself, then launch ONE gate reviewer (never a panel) to audit goal, constraints, code quality, security, missed context, and QA evidence. Use before a PR handoff or when the user explicitly asks to review completed work.
lcx-report-bug
Create a high-signal bug issue or PR in the repo that owns the defect. Use this whenever the user asks to report, file, open, or triage a LazyCodex, lazycodex-ai, omo-codex, Codex plugin, or upstream Codex CLI bug, especially when they need source-backed root cause, reproduction steps, fix guidance, and GitHub routing.