Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/nguyenvanphituoc/shapeup-sdlc-plugin/task-executornpx skills add nguyenvanphituoc/shapeup-sdlc-plugin --skill task-executorgit clone --depth 1 https://github.com/nguyenvanphituoc/shapeup-sdlc-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/nguyenvanphituoc/shapeup-sdlc-plugin/task-executor)<a href="https://agentmods.dev/skills/nguyenvanphituoc/shapeup-sdlc-plugin/task-executor"><img src="https://agentmods.dev/badge/skills/nguyenvanphituoc/shapeup-sdlc-plugin/task-executor.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00111 | $0.03193 |
| Opus 5 | $0.00056 | $0.01597 |
| Sonnet 5 | $0.00022 | $0.00639 |
| Haiku 4.5 | $0.00011 | $0.00319 |
Grade A, and why
task-executor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 209 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Task Executor (pure worker, v2.0)
Implement exactly what the acceptance criteria specify. Prove it. Report it.
You are the doer in a planner → doer → judge harness. Your entire interface with the pipeline is two JSON envelopes: a WorkOrder in, a WorkResult out. You know nothing about boards, ledgers, run-state, rounds, or other workers — if the order doesn't carry it, it does not exist for you.
Input contract — the WorkOrder
You are invoked as --order <path> pointing at a schema-valid WorkOrder. Fields you may
rely on (anything absent = unknown; never invent it):
| Field | What it is |
|---|---|
payload.tasks[] |
The task(s) to implement: id, body_path (read it fully), acceptance_criteria[] |
payload.scope_contract |
The active scope: affordance_manifest, e2e_verification_fixtures, topology |
substrate.allowed / substrate.shared |
The ONLY globs you may write. A needed file outside them → ESCALATE, never a write (a sandbox hook blocks it anyway) |
payload.decisions[] |
Adjudicated answers from prior escalations — binding precedent, apply them |
payload.digested_errors[] |
{file, line, core_message} triples from the previous attempt's failed verification — your starting bug list |
payload.trial_history[] |
Up to 8 prior attempts on this scope, oldest first, CROSSING the round boundary: {score, status, delta, digest}. status: "reverted" is a change that was tried and made things WORSE — do not re-propose it. status: "kept" with a still-red score is the tree you are building ON, not a failure to undo. Absent on the first attempt |
payload.verify.test_cmd |
The command that verifies your work. No test_cmd → command-verifiable ACs still need some observable check; say what you used |
payload.kb_rules_path |
Team guidelines (read if the file exists) — steering, never spec; conflict → the AC wins, note it in deviations |
payload.constraints |
Non-Go items and freezes (e.g. ui_layers.layer3_frozen) |
payload.bugs[] |
The previous round's FAIL verdict, addressed to files inside YOUR substrate: {severity, criterion, location, repro, expected, actual}. Fix exactly these and touch nothing else. They are spec-conformance defects, so verification is ALREADY green and will stay green whether or not you fix them — a passing test_cmd is not evidence you are done this round, and re-running it cannot tell you. Read the cited lines against the committed spec instead. An entry marked unowned cites a file no scope owns: fix it only if it falls inside your substrate. Absent unless the previous round failed |
operation |
execute (fresh), fix (only the bugs in payload.bugs — touch nothing else), spike (produce a decision doc, not code). A build round whose predecessor returned FAIL arrives as fix with the same substrate as the execute that preceded it |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 209 lines · 111 tokens per session scan A 9c8343153590
task-executor is a skill published in the GitHub repository nguyenvanphituoc/shapeup-sdlc-plugin (2 stars, last pushed 13d ago), licensed MIT. It adds 111 tokens to every session and 3,193 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
agent-code-analyzer
Agent skill for code-analyzer - invoke with $agent-code-analyzer.
agui-dotnet-streaming-chat
Get started with the AG-UI .NET SDK: bootstrap and run your first streaming-chat app (client + server) with the AG-UI .NET NuGet packages (AGUI.Client, AGUI.Server, AGUI.Formatting, AGUI.Abstractions). USE FOR: which packages to install and how to wire them; constructing an AGUIChatClient against an endpoint and…
agui-dotnet-sample-step
Add a GettingStarted sample Step (a Server/Client pair) to the AG-UI .NET SDK that demonstrates one protocol feature the way we want users to write it. USE FOR: adding a new samples/GettingStarted/StepNN Server+Client pair, wiring it into AGUI.slnx and the integration-test project, giving it a deterministic…
agui-dotnet-protobuf
Use the protobuf wire transport (instead of the default Server-Sent Events) for an AG-UI connection with the AG-UI .NET SDK — a compact binary event stream negotiated via the Accept header. USE FOR: making an AGUIChatClient prefer protobuf by wiring an AGUIEventStreamHandler with ProtobufEventStreamFormatter (then…
revdiff-plan
Review the last Codex assistant message (plan, analysis, or proposal) with inline annotations in a TUI overlay. Extracts the most recent response from Codex rollout files and opens it in revdiff for review and annotation. Activates on "revdiff-plan", "review plan with revdiff", "annotate plan", "review last response"…
moai-ref-ui-polish
UI polish and interface-completion reference: the small visual details — concentric border radius, optical alignment, shadow-vs-border, motion easing, typography smoothing, tabular numbers, icon stroke weight, hit areas — that separate polished interfaces from generic ones. Agent-extending skill that amplifies…