Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add neul-labs/brat --skill brat-productgit clone --depth 1 https://github.com/neul-labs/bratWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/neul-labs/brat/brat-product)<a href="https://agentmods.dev/skills/neul-labs/brat/brat-product"><img src="https://agentmods.dev/badge/skills/neul-labs/brat/brat-product/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/neul-labs/brat/brat-product"><img src="https://agentmods.dev/badge/skills/neul-labs/brat/brat-product.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00027 | $0.00409 |
| Opus 5 | $0.00014 | $0.00204 |
| Sonnet 5 | $0.00005 | $0.00082 |
| Haiku 4.5 | $0.00003 | $0.00041 |
Grade A, and why
brat-product scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
brat-product Skill
Purpose
Analyze user intent and produce structured product requirements stored in the zkb product knowledge base.
Input Schema (JSON)
{
"intent": "string (user's natural language request)",
"product_context": "string (relevant product notes from KB)",
"existing_features": ["string (list of known features from KB)"],
"constraints": "string (business/technical constraints)"
}
Output Schema (JSON)
{
"action": "create_requirements|update_requirements|answer",
"requirements": {
"title": "string",
"user_stories": [
{
"story": "string (As a X, I want Y, so that Z)",
"acceptance_criteria": ["string"],
"priority": "P0|P1|P2"
}
],
"acceptance_tests": ["string (test descriptions)"],
"notes_to_create": [
{
"title": "string",
"body": "string",
"tags": ["string"],
"type": "fleeting|permanent|structure"
}
]
},
"answer": "string (if action=answer)",
"escalation_reason": "string (if unclear)"
}
Guardrails
- ALWAYS query KB for existing product context before writing
- User stories must follow "As a... I want... so that..." format
- Every requirement needs at least one acceptance criterion
- Create
fleetingnotes for raw ideas,permanentfor validated requirements - Link new notes to existing product structure note
- NEVER proceed to architecture phase from this skill
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 58 lines · 0 tokens per session scan A c3ae338ad6b5
brat-product is a skill published in the GitHub repository neul-labs/brat (5 stars, last pushed 2mo ago), licensed MIT. It adds 27 tokens to every session and 409 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
swarm-pr-review
Run a graph-guided, tool-augmented PR review using context packing, parallel exploration, mandatory repository-agnostic risk-family coverage with dispatch scaled to diff size and risk, independent reviewer validation, critic challenge, and metrics writeback. Use for deep pull request review with low false-positive…
workflow
Use when a task is too large for turn-by-turn orchestration and should run through the big-task workflow lane: system-wide changes, large migrations, repo-wide audits, high-confidence verification, or tasks explicitly asking to run a workflow. Claude Code uses native dynamic workflows; Codex, OpenCode, and Grok use…
swarm-plan
Full execution protocol for MODE: PLAN -- plan creation, external plan ingestion, QA gate persistence, task granularity, and traceability checks.
loop
Full execution protocol for MODE: LOOP — the compound-engineering loop: brainstorm → plan → build → review → improve, iterating under defense-in-depth stop conditions with generator/critic separation, durable resumable state, and mandatory compounding learning capture. Loaded on demand by the architect when the loop…
council
Full execution protocol for MODE: COUNCIL -- General Council research, parallel member dispatch, disagreement handling, and synthesis.
deep-research
Full execution protocol for MODE: DEEPRESEARCH — orchestrator-worker deep research over external sources: decompose, iterative websearch/webfetch retrieval, parallel sme synthesis, dual-reviewer claim verification, critic challenge of high-stakes claims, and a cited report. Loaded on demand by the architect when the…