plan-executor

plan-executor is a skill for Claude Code, Codex from nguyenvanphituoc/shapeup-sdlc-plugin. It costs 221 tokens per session (3,016 once invoked), scanned C, original, MIT.

A skill that carries out a staged plan from start to finish. It turns the plan into explicit acceptance checks, implements each stage, and verifies the result in a new copy of the code repository.

In plain words
What is it for?
Use it for architecture plans, review recommendations, decision records, and other documents that describe ordered implementation stages.
Why use it?
It prevents work from being declared complete based only on notes or an uncommitted local change. When a check fails, it preserves the evidence, investigates the failure, applies an allowed fix, and checks again.

Skill for Claude CodeCodex

Part of the shapeup-sdlc-plugin plugin — 17 skills, 11 commands, 4 hooks shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/nguyenvanphituoc/shapeup-sdlc-plugin/plan-executor
Any agent
npx skills add nguyenvanphituoc/shapeup-sdlc-plugin --skill plan-executor
Clone the repo
git clone --depth 1 https://github.com/nguyenvanphituoc/shapeup-sdlc-plugin

Made for: Claude Code, Codex.

Or install shapeup-sdlc-plugin, the plugin that ships this one along with the rest of its 17 skills, 11 commands, 4 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for plan-executor

README.md
[![agentmods](https://agentmods.dev/badge/skills/nguyenvanphituoc/shapeup-sdlc-plugin/plan-executor.svg)](https://agentmods.dev/skills/nguyenvanphituoc/shapeup-sdlc-plugin/plan-executor)
Your own site
<a href="https://agentmods.dev/skills/nguyenvanphituoc/shapeup-sdlc-plugin/plan-executor"><img src="https://agentmods.dev/badge/skills/nguyenvanphituoc/shapeup-sdlc-plugin/plan-executor.svg" alt="Measured on agentmods" height="20"></a>
Per session 221 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,016 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00221 $0.03016
Opus 5 $0.00111 $0.01508
Sonnet 5 $0.00044 $0.00603
Haiku 4.5 $0.00022 $0.00302

Measured 4d ago against content hash 28cb79f53bb2, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade C, and why

plan-executor scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

The scan reads SKILL.md. This mod also ships 3 executable files (scripts/parse-contract.mjs, tests/execute-plan.gate.mjs, workflows/execute-plan.js), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Recursive force deletehighDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

rm -rf "$CLONE" && git clone --local --no-hardlinks --quiet . "$CLONE" && cd "$CLONE"
.claude/skills/plan-executor/SKILL.md · 217 lines

How it starts

The opening of the file, as written. The whole thing — 217 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Plan executor

A plan of this kind — an architecture-research-report with a staged §6, a review with a recommendation, an ADR with a migration sequence — is already most of a machine-executable specification. It has ordered stages, an exit criterion per stage, and usually a section saying what not to do. What it lacks is a runtime that will not let itself be talked out of the exit criteria. That is what this skill adds.

The one rule everything else serves

Progress is derived by re-running acceptance, never claimed by whoever did the work.

A stage is done because a command exited as the contract said it would, in a clone that has never seen this run's working tree. Not because an agent said so, not because a prior session's notes say so. Everything else here — why the contract is a separate file, why the clean room is a fresh clone, why a fix that edits a test is rejected, why resuming is cheap — follows from that one rule.

It is also the rule these plans were written about. Day 1's finding was a repository that read green while a clone of it failed four checks, because the fix lived in an uncommitted working tree. Day 2's was a register that would happily accept a fabricated reduction, because the rule against it was prose. A harness that executes those plans and then reports success on its own say-so has learned nothing from either.

Phase 0 — Find the plan, or make one

You need a document with a staged recommendation. If the user named one, read it whole before anything else — the stages, the exit criteria, the "what not to do" section, and the falsifiers.

If there is no such document, stop and produce one with architecture-research-report first. It writes exactly the shape this skill consumes: a §6 that is staged, sequenced and costed, a §5 of prohibitions, a §7 of what would change the answer. Executing an unstaged wish is how a run ends up optimising something nobody agreed to.

If the document exists but its recommendation is one undifferentiated paragraph, say so and offer to stage it. Do not silently invent stage boundaries; the ordering in these plans is usually load-bearing.

Read the full file on GitHub · 217 lines

Files

What ships with it

6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 217 lines · 221 tokens per session scan C 28cb79f53bb2

Subscribe to this mod's changes

plan-executor is a skill published in the GitHub repository nguyenvanphituoc/shapeup-sdlc-plugin (2 stars, last pushed 14d ago), licensed MIT. It adds 221 tokens to every session and 3,016 once invoked, about $0.0011 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

agent-code-analyzer

Agent skill for code-analyzer - invoke with $agent-code-analyzer.

ruvnet/ruflo · 19 tokens

agui-dotnet-streaming-chat

Get started with the AG-UI .NET SDK: bootstrap and run your first streaming-chat app (client + server) with the AG-UI .NET NuGet packages (AGUI.Client, AGUI.Server, AGUI.Formatting, AGUI.Abstractions). USE FOR: which packages to install and how to wire them; constructing an AGUIChatClient against an endpoint and…

ag-ui-protocol/ag-ui · 223 tokens

agui-dotnet-sample-step

Add a GettingStarted sample Step (a Server/Client pair) to the AG-UI .NET SDK that demonstrates one protocol feature the way we want users to write it. USE FOR: adding a new samples/GettingStarted/StepNN Server+Client pair, wiring it into AGUI.slnx and the integration-test project, giving it a deterministic…

ag-ui-protocol/ag-ui · 168 tokens

agui-dotnet-protobuf

Use the protobuf wire transport (instead of the default Server-Sent Events) for an AG-UI connection with the AG-UI .NET SDK — a compact binary event stream negotiated via the Accept header. USE FOR: making an AGUIChatClient prefer protobuf by wiring an AGUIEventStreamHandler with ProtobufEventStreamFormatter (then…

ag-ui-protocol/ag-ui · 162 tokens

revdiff-plan

Review the last Codex assistant message (plan, analysis, or proposal) with inline annotations in a TUI overlay. Extracts the most recent response from Codex rollout files and opens it in revdiff for review and annotation. Activates on "revdiff-plan", "review plan with revdiff", "annotate plan", "review last response"…

umputun/revdiff · 84 tokens

moai-ref-ui-polish

UI polish and interface-completion reference: the small visual details — concentric border radius, optical alignment, shadow-vs-border, motion easing, typography smoothing, tabular numbers, icon stroke weight, hit areas — that separate polished interfaces from generic ones. Agent-extending skill that amplifies…

modu-ai/moai-adk · 98 tokens