Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add nguyenvanphituoc/shapeup-sdlc-plugin/plugin install shapeup-sdlc-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/nguyenvanphituoc/shapeup-sdlc-plugin/tech-lead)<a href="https://agentmods.dev/skills/nguyenvanphituoc/shapeup-sdlc-plugin/tech-lead"><img src="https://agentmods.dev/badge/skills/nguyenvanphituoc/shapeup-sdlc-plugin/tech-lead.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00122 | $0.02742 |
| Opus 5 | $0.00061 | $0.01371 |
| Sonnet 5 | $0.00024 | $0.00548 |
| Haiku 4.5 | $0.00012 | $0.00274 |
Grade A, and why
tech-lead scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 149 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Tech Lead (harness orchestrator)
▶ RUN THIS FIRST — do not summarise this file
Your first output must be a tool call, not a plan. Everything you emit before the first tool
call is narration, and a narrated run is a failed run — it reads like a clean success and leaves
escaped defects behind it. hooks/gate-zerowork.mjs (Stop) blocks a session
that reached the orchestrator and left no receipt — where "reached the orchestrator" means
dispatching this skill or launching a shapeup-* workflow by either surface, and the receipt is
what harness init run writes. Working around the harness is not an exemption: a busy session used to
switch this gate off and no longer does. Loading these instructions is not running them.
Step 1 — open the run. Write the requirement to a file first, then pass the path — a multi-line requirement inlined into a shell argument is where this step goes wrong (measured: six turns fighting shell quoting):
node "${CLAUDE_PLUGIN_ROOT}/kernel/harness.mjs" init run \
--slug <slug-from-the-request> --intake-file <path/to/the/requirement.md> \
--auto-level <interactive|auto|unattended> \
[--dimensions <a,b>] [--gate-answers <ci|guarded|path.json>] [--wall-clock-budget <seconds>] [--max-rounds 3]
After a compaction, or in a fresh session over an open run, re-derive before you act. One command answers where the run stands, from artifacts and never from memory:
node "${CLAUDE_PLUGIN_ROOT}/kernel/harness.mjs" reduce graph --slug <slug> --subgraph run
Exit 3 means a run is ALREADY OPEN. Resume it; do not re-open it. The refusal prints the
derived RESUME STATE (slug, status, round, board counts) — read it and go straight to Step 2;
shapeup-run.js's own fast-forward will re-derive exactly where to continue from disk, never from
this session's memory. --force re-opens deliberately and discards the round history the breaker
counts.
If this command comes back "requires approval", stop and say so. These scripts ship with the
plugin and need a one-time permission grant (npx shapeup-sdlc init writes it). Do not route
around it, and do not silently hand-build the feature instead.
What ships with it
8 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 149 lines · 122 tokens per session scan A c45c10c26c87
tech-lead is a skill published in the GitHub repository nguyenvanphituoc/shapeup-sdlc-plugin (2 stars, last pushed 3d ago), licensed MIT. It adds 122 tokens to every session and 2,742 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
agent-code-analyzer
Agent skill for code-analyzer - invoke with $agent-code-analyzer.
worker-integration
Worker-Agent integration for intelligent task dispatch and performance tracking.
agui-dotnet-streaming-chat
Get started with the AG-UI .NET SDK: bootstrap and run your first streaming-chat app (client + server) with the AG-UI .NET NuGet packages (AGUI.Client, AGUI.Server, AGUI.Formatting, AGUI.Abstractions). USE FOR: which packages to install and how to wire them; constructing an AGUIChatClient against an endpoint and…
agui-dotnet-protobuf
Use the protobuf wire transport (instead of the default Server-Sent Events) for an AG-UI connection with the AG-UI .NET SDK — a compact binary event stream negotiated via the Accept header. USE FOR: making an AGUIChatClient prefer protobuf by wiring an AGUIEventStreamHandler with ProtobufEventStreamFormatter (then…
quality-hooks
Language-specific auto-lint/format/typecheck pipeline. Supports Python (ruff+pyright), TypeScript (prettier+eslint+tsc), Go (gofmt+golangci-lint). Auto-fix and convergence loops.
cog-knowledge-consolidation
Build structured knowledge frameworks from scattered vault notes with source attribution.