Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add mgallet92i/waterfall/plugin install waterfallWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mgallet92i/waterfall/wf-new)<a href="https://agentmods.dev/skills/mgallet92i/waterfall/wf-new"><img src="https://agentmods.dev/badge/skills/mgallet92i/waterfall/wf-new/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/mgallet92i/waterfall/wf-new"><img src="https://agentmods.dev/badge/skills/mgallet92i/waterfall/wf-new.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00025 | $0.04404 |
| Opus 5 | $0.00013 | $0.02202 |
| Sonnet 5 | $0.00005 | $0.00881 |
| Haiku 4.5 | $0.00003 | $0.00440 |
Grade A, and why
wf-new scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 320 lines — stays where its author put it; the contents beside it link to each section on GitHub.
wf-new — Bootstrap a new need
This skill is the entry point of the waterfall workflow for a new need. It is invoked by the /waterfall:new slash command. Its sole role: prepare the environment, resolve the name, and hand off to OR.
Flow Z — Bootstrap Agent Teams
Step 1 — Preflight
bash ${CLAUDE_PLUGIN_ROOT}/scripts/wf-check-bash.sh
If exit ≠ 0: display the error to HO and stop. The plugin requires bash (Git Bash on Windows).
bash ${CLAUDE_PLUGIN_ROOT}/scripts/wf-check-teams.sh
If exit ≠ 0: display the error to HO and stop. The flag CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS=1 is required (see README.md Prerequisites).
Step 1.bis — jq verification
jq is used by all wf scripts to parse .wf-state.json, .team-registry.json, etc.
INSTALL_CMD=$(bash ${CLAUDE_PLUGIN_ROOT}/scripts/wf-check-jq.sh) || JQ_RC=$?
- Exit 0 → continue.
- Exit 2 →
jqmissing.$INSTALL_CMDcontains the install command adapted to the detected OS (empty if no known package manager).- If
INSTALL_CMDnon-empty →AskUserQuestion: "jq is required. Install it now via${INSTALL_CMD}?" (Yes / No).- Yes →
bash -c "$INSTALL_CMD"then re-runwf-check-jq.sh. If still missing → display stderr and stop. - No → display the command to HO for manual install and stop.
- Yes →
- If
INSTALL_CMDempty → display stderr (manual instructions + URL) and stop.
- If
Step 2 — Name resolution
The name is resolved by PM (main conversation) before any spawn — PM has the fresh verbal context from HO.
- If
$ARGUMENTSprovided → validate kebab-case, use directly as<name> - If
$ARGUMENTSempty: a.AskUserQuestion(open question): "Describe your need in a few words." b. Generate 3 kebab-case proposals (2-4 words, semantically relevant) c.AskUserQuestionwith the 3 options (HO can also enter a free-form name) d. Validate the chosen name: strict kebab-case - Check non-collision:
ls wf/needs/<name>/→ if it exists, AskUserQuestion to confirm overwrite or pick another name
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 320 lines · 25 tokens per session scan A ce63c6285cc3
wf-new is a skill published in the GitHub repository mgallet92i/waterfall (2 stars, last pushed 1mo ago), licensed MIT. It adds 25 tokens to every session and 4,404 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
plan
Use this skill at the START of every coding task — new builds, bug fixes, and change requests. Classifies the work item, validates it against project scope, produces a high-level estimate, proposes a technology stack, and checks stack compatibility. Writes a plan artifact to .claude/sdlc/plans/ that every downstream…
start
Use this skill when the user runs /start, says "start", "enable the SDLC workflow", "I want to build", "I want to fix", "set up", "get started", or otherwise signals they want to activate or re-enable the SDLC workflow. Handles three distinct paths based on marker state — fresh install (opt-in activation), re-enable…
domain-expert
Use this skill during /plan (between scope validation and writing the plan artifact) to inject domain-specific context, gap questions, and regulatory concerns into the plan. Triggers automatically when the plan skill evaluates the task and scope.md against the domain registry in domains/index.json using semantic…
configure
Use this skill when the user runs /configure, /configure --needs, or /configure --check. Also auto-invoked by env-detect.sh on fresh install (Layer 0) and by skills that find required config missing at runtime (Layer 2). Guides setup of config/tools.json and config/tools.local.json through a question bank; handles…
status
Use this skill when the user asks "where am I", "what's the current task", "what's blocking me", "show status", "what needs sign-off", or "what's next". Prints a snapshot of the active plan, gate, sign-off progress, and next action. Reads only — writes nothing.
analyze
Use this skill after Phase 1 Plan to create or intake requirements for a task. Produces requirements with stable IDs (REQ-001, REQ-002, ...), validates each requirement against the project's scope statement, and — critically — halts and asks for UX designs and brand guidelines whenever the work touches a frontend or…