Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/nguyenvanphituoc/shapeup-sdlc-plugin/plan-executornpx skills add nguyenvanphituoc/shapeup-sdlc-plugin --skill plan-executorgit clone --depth 1 https://github.com/nguyenvanphituoc/shapeup-sdlc-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/nguyenvanphituoc/shapeup-sdlc-plugin/plan-executor)<a href="https://agentmods.dev/skills/nguyenvanphituoc/shapeup-sdlc-plugin/plan-executor"><img src="https://agentmods.dev/badge/skills/nguyenvanphituoc/shapeup-sdlc-plugin/plan-executor.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00221 | $0.03016 |
| Opus 5 | $0.00111 | $0.01508 |
| Sonnet 5 | $0.00044 | $0.00603 |
| Haiku 4.5 | $0.00022 | $0.00302 |
Grade C, and why
plan-executor scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
rm -rf "$CLONE" && git clone --local --no-hardlinks --quiet . "$CLONE" && cd "$CLONE" How it starts
The opening of the file, as written. The whole thing — 217 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Plan executor
A plan of this kind — an architecture-research-report with a staged §6, a review with a recommendation, an ADR with a migration sequence — is already most of a machine-executable specification. It has ordered stages, an exit criterion per stage, and usually a section saying what not to do. What it lacks is a runtime that will not let itself be talked out of the exit criteria. That is what this skill adds.
The one rule everything else serves
Progress is derived by re-running acceptance, never claimed by whoever did the work.
A stage is done because a command exited as the contract said it would, in a clone that has never seen this run's working tree. Not because an agent said so, not because a prior session's notes say so. Everything else here — why the contract is a separate file, why the clean room is a fresh clone, why a fix that edits a test is rejected, why resuming is cheap — follows from that one rule.
It is also the rule these plans were written about. Day 1's finding was a repository that read green while a clone of it failed four checks, because the fix lived in an uncommitted working tree. Day 2's was a register that would happily accept a fabricated reduction, because the rule against it was prose. A harness that executes those plans and then reports success on its own say-so has learned nothing from either.
Phase 0 — Find the plan, or make one
You need a document with a staged recommendation. If the user named one, read it whole before anything else — the stages, the exit criteria, the "what not to do" section, and the falsifiers.
If there is no such document, stop and produce one with architecture-research-report first. It writes exactly the shape this skill consumes: a §6 that is staged, sequenced and costed, a §5 of prohibitions, a §7 of what would change the answer. Executing an unstaged wish is how a run ends up optimising something nobody agreed to.
If the document exists but its recommendation is one undifferentiated paragraph, say so and offer to stage it. Do not silently invent stage boundaries; the ordering in these plans is usually load-bearing.
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 217 lines · 221 tokens per session scan C 28cb79f53bb2
plan-executor is a skill published in the GitHub repository nguyenvanphituoc/shapeup-sdlc-plugin (2 stars, last pushed 14d ago), licensed MIT. It adds 221 tokens to every session and 3,016 once invoked, about $0.0011 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
agent-code-analyzer
Agent skill for code-analyzer - invoke with $agent-code-analyzer.
agui-dotnet-streaming-chat
Get started with the AG-UI .NET SDK: bootstrap and run your first streaming-chat app (client + server) with the AG-UI .NET NuGet packages (AGUI.Client, AGUI.Server, AGUI.Formatting, AGUI.Abstractions). USE FOR: which packages to install and how to wire them; constructing an AGUIChatClient against an endpoint and…
agui-dotnet-sample-step
Add a GettingStarted sample Step (a Server/Client pair) to the AG-UI .NET SDK that demonstrates one protocol feature the way we want users to write it. USE FOR: adding a new samples/GettingStarted/StepNN Server+Client pair, wiring it into AGUI.slnx and the integration-test project, giving it a deterministic…
agui-dotnet-protobuf
Use the protobuf wire transport (instead of the default Server-Sent Events) for an AG-UI connection with the AG-UI .NET SDK — a compact binary event stream negotiated via the Accept header. USE FOR: making an AGUIChatClient prefer protobuf by wiring an AGUIEventStreamHandler with ProtobufEventStreamFormatter (then…
revdiff-plan
Review the last Codex assistant message (plan, analysis, or proposal) with inline annotations in a TUI overlay. Extracts the most recent response from Codex rollout files and opens it in revdiff for review and annotation. Activates on "revdiff-plan", "review plan with revdiff", "annotate plan", "review last response"…
moai-ref-ui-polish
UI polish and interface-completion reference: the small visual details — concentric border radius, optical alignment, shadow-vs-border, motion easing, typography smoothing, tabular numbers, icon stroke weight, hit areas — that separate polished interfaces from generic ones. Agent-extending skill that amplifies…