Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add OneWave-AI/claude-skills --skill before-you-buildgit clone --depth 1 https://github.com/OneWave-AI/claude-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/onewave-ai/claude-skills/before-you-build)<a href="https://agentmods.dev/skills/onewave-ai/claude-skills/before-you-build"><img src="https://agentmods.dev/badge/skills/onewave-ai/claude-skills/before-you-build/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/onewave-ai/claude-skills/before-you-build"><img src="https://agentmods.dev/badge/skills/onewave-ai/claude-skills/before-you-build.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Anti-Refusal · line 92 Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.Fix: Remove instructions that suppress warnings, disclaimers, or ethical commentary. Let the agent surface safety-relevant caveats to the user.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00058 | $0.00752 |
| Opus 5 | $0.00029 | $0.00376 |
| Sonnet 5 | $0.00012 | $0.00150 |
| Haiku 4.5 | $0.00006 | $0.00075 |
Grade A, and why
before-you-build scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 101 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Before You Build
Use this skill as a short pre-build risk gate.
The goal is to stop implementation from starting before the riskiest product assumption is clear. Stay implementation-agnostic: do not recommend stacks, architectures, tools, or code.
Core Behavior
When invoked:
- Restate the idea in one sentence.
- Identify the dominant pre-build risk.
- Give a short risk verdict.
- Recommend the smallest validation step that can reduce uncertainty before building.
Keep the response short unless the user explicitly asks for a deeper review.
Seven Risk Dimensions
Check the idea through these dimensions:
- Demand risk: Do enough people already feel this problem strongly?
- Buyer risk: Is there a clear person or team with reason to pay or commit?
- Distribution risk: Is there a believable path to reaching those people?
- Workflow risk: Does the idea fit how users already behave, decide, or work?
- Timing risk: Is this urgent now, or only interesting in theory?
- Trust risk: Does the product require data, access, behavior change, or credibility users may not grant?
- Scope risk: Is the proposed build larger than the proof needed right now?
Pick the one or two risks that matter most. Do not turn every review into a long checklist.
Output Format
Use this format:
## Before You Build
Idea:
- [One-sentence restatement.]
Risk verdict:
- [Low / Medium / High risk] because [one concrete reason].
Main risk:
- [The dominant risk dimension and why it matters.]
Smallest validation step:
- [One specific action the user can take before building.]
Build guidance:
- [Build now / Build smaller / Validate first / Do not build yet.]
Validation Step Rules
The smallest validation step should be specific and low-cost.
Prefer steps like:
- Talk to five target users who already tried to solve the problem.
- Ask for payment, pre-order, letter of intent, or manual commitment before building software.
- Run a landing page, waitlist, outbound message, or concierge test around one narrow promise.
- Manually deliver the outcome once before automating it.
- Test whether the missing feature blocks payment, retention, activation, or only completeness.
- Find one repeated channel that can reach the target users before expanding scope.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 101 lines · 58 tokens per session scan A 4099517062ff
before-you-build is a skill published in the GitHub repository OneWave-AI/claude-skills (288 stars, last pushed 1mo ago), licensed MIT. It adds 58 tokens to every session and 752 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
analytics-strategy
Design measurement frameworks including event taxonomy, KPI hierarchy, dashboard architecture, attribution models, and analytics implementation strategy. Use this skill whenever the user wants to plan analytics, design dashboards, build event taxonomies, define KPIs, set up tracking, or audit existing measurement.…
content-strategy
Develop a content strategy covering editorial positioning, content pillars, formats, calendar, governance, and topical authority planning. Use this skill whenever the user wants to plan a content program, define content pillars, build an editorial calendar, structure topic clusters, set up content governance, or align…
incident-response
Manage active production incidents through detection, triage, mitigation, communication, and resolution with structured roles and decision-making. Use this skill whenever the user has an active incident, a production issue, a service outage, a security incident, or needs to plan incident response procedures. Triggers…
stakeholder-communication
Communicate effectively with stakeholders across functions and seniority levels. Use this skill when writing status updates, preparing executive reviews, sharing technical decisions with non-technical audiences, managing up, communicating bad news, or designing the communication cadence for a project. Triggers on…
agb-begriff-vorformuliert-305
Für AGB Begriff Vorformuliert 305: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: agb-begriff-vorformuliert-305.
review-work
Post-implementation gate review: run manual QA on the real surface yourself, then launch ONE gate reviewer (never a panel) to audit goal, constraints, code quality, security, missed context, and QA evidence. Use before a PR handoff or when the user explicitly asks to review completed work.