Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/kok-o/koko-contextos-agents/engineering-workflownpx skills add kok-o/koko-contextos-agents --skill engineering-workflowgit clone --depth 1 https://github.com/kok-o/koko-contextos-agentsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/kok-o/koko-contextos-agents/engineering-workflow)<a href="https://agentmods.dev/skills/kok-o/koko-contextos-agents/engineering-workflow"><img src="https://agentmods.dev/badge/skills/kok-o/koko-contextos-agents/engineering-workflow.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00057 | $0.02906 |
| Opus 5 | $0.00028 | $0.01453 |
| Sonnet 5 | $0.00011 | $0.00581 |
| Haiku 4.5 | $0.00006 | $0.00291 |
Grade A, and why
engineering-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 344 lines — stays where its author put it; the contents beside it link to each section on GitHub.
engineering-workflow
Overview
Systematic 6-phase engineering pipeline (DEFINE → PLAN → BUILD → VERIFY → REVIEW → SHIP) enforcing role declarations, atomic task execution, quality gates, regression prevention, and structured requirements elicitation.
When to Use
Activate on all project tasks to orchestrate structured development, spec definition, architectural planning, and verification gates.
Rules & Patterns
Inspired by addyosmani/agent-skills by Addy Osmani (Google Chrome) and obra/superpowers.
Core Principle
A junior writes code immediately. A senior writes a spec first.
You are a senior. You never write code until the spec and plan are approved.
The 6-Phase Development Pipeline
DEFINE PLAN BUILD VERIFY REVIEW SHIP
┌──────┐ ┌──────┐ ┌──────┐ ┌──────┐ ┌──────┐ ┌──────┐
│ Idea │ ───▶ │ Spec │ ───▶ │ Code │ ───▶ │ Test │ ───▶ │ QA │ ───▶ │ Go │
│Refine│ │ PRD │ │ Impl │ │Debug │ │ Gate │ │ Live │
└──────┘ └──────┘ └──────┘ └──────┘ └──────┘ └──────┘
/spec /plan /build /test /review /ship
[ROLE: Product Manager] [ROLE: Architect] [ROLE: Senior Dev] [ROLE: QA Lead] [ROLE: Staff Eng] [ROLE: Release Eng]
IRON RULE: In interactive development, no phase can be skipped and no code is written before /plan is approved.
Direct Build Exception: When the prompt/caller explicitly requests a standalone implementation, or declares [PHASE: Build], execute the BUILD phase directly and deliver the complete, self-contained production code without conversational pauses.
Phase 1: DEFINE — /spec
Auto-activates → [ROLE: Product Manager]
Turn vague intent into a precise, executable specification.
Step 1.1: The Interview Protocol (interview-me)
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · -7 lines bcc86ef092c3
- 6d ago First seen · 351 lines · 57 tokens per session scan A deb5a1748e9a
engineering-workflow is a skill published in the GitHub repository kok-o/koko-contextos-agents (2 stars, last pushed 2d ago), licensed MIT. It adds 57 tokens to every session and 2,906 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
karpathy-coding-principles
Use when andrej Karpathy's 4 coding principles — think before coding, simplicity first, surgical changes, goal-driven execution. Use when coding, reviewing code quality, reducing overengineering,.
universal-patterns
Use when implementing language-agnostic patterns like layered architecture, dependency injection, error handling, or code organization principles across any technology stack.
rust-best-practices
Comprehensive Rust best practices covering ownership, error handling, async patterns, testing, and project structure.
cache_patterns
Instruction set for enabling and operating the Spring Cache abstraction in Spring Boot when implementing application-level caching for performance-sensitive workloads.
event_driven
Structure systems around asynchronous, event-based communication to decouple producers and consumers for improved scalability and resilience. Use when building loosely coupled systems with asynchronous message-based communication.
clean-code
Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments.