cambridge-beer-festival-app: Skill for Claude Code

.claude/skills/research-methodology/SKILL.md

research-methodology is a skill for Claude Code from richardthe3rd/cambridge-beer-festival-app. It costs 0 tokens per session (5,003 once invoked), scanned B, original, MIT.

A research and decision-making method for the Cambridge Beer Festival app. It requires proposed causes, fixes, and architecture decisions to be supported by evidence from the repository's files, issues, history, or data.

In plain words
What is it for?
It helps investigate bugs, check assumptions against production data, review resilience, triage issues, write planning documents, and decide when to create an ADR, or Architecture Decision Record.
Why use it?
It reduces the risk of acting on a plausible explanation that does not account for all observed behavior.

Skill for Claude Code

Written for Claude Code: installed under .claude/. Also seen: reads .claude/ paths; mentions AGENTS.md.

This is richardthe3rd/cambridge-beer-festival-app's own configuration. It tells Claude Code how to work on cambridge-beer-festival-app itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything cambridge-beer-festival-app configures →

Not installable: its command points at a path on the author’s own machine, so it runs nowhere else. The line is /home/user/cambridge-beer-festival-app.

Reuse

Borrowing it

Nothing to install: this file belongs to richardthe3rd/cambridge-beer-festival-app. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/richardthe3rd/cambridge-beer-festival-app/main/.claude/skills/research-methodology/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/richardthe3rd/cambridge-beer-festival-app

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for research-methodology

README.md
[![agentmods](https://agentmods.dev/badge/skills/richardthe3rd/cambridge-beer-festival-app/research-methodology/github.svg)](https://agentmods.dev/skills/richardthe3rd/cambridge-beer-festival-app/research-methodology)
Your own site
<a href="https://agentmods.dev/skills/richardthe3rd/cambridge-beer-festival-app/research-methodology"><img src="https://agentmods.dev/badge/skills/richardthe3rd/cambridge-beer-festival-app/research-methodology/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for research-methodology

Your own site · 80×15
<a href="https://agentmods.dev/skills/richardthe3rd/cambridge-beer-festival-app/research-methodology"><img src="https://agentmods.dev/badge/skills/richardthe3rd/cambridge-beer-festival-app/research-methodology.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 0 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 5,003 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.05003
Opus 5 $0.00000 $0.02501
Sonnet 5 $0.00000 $0.01001
Haiku 4.5 $0.00000 $0.00500

Measured 12d ago against content hash 55deab93e63c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade B, and why

research-methodology scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Enumerates other installed skillsmediumAgent snooping

Other skills' SKILL.md files reveal prompts, capabilities and secrets that should be invisible to peers.

ls .claude/skills/ | grep -E '^(research-frontier|proof-and-analysis-toolkit|change-control|failure-archaeology)$'
.claude/skills/research-methodology/SKILL.md · 320 lines

How it starts

The opening of the file, as written. The whole thing — 320 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Research Methodology

This is not abstract scientific-method advice. Every rule below is reverse-engineered from a specific investigation in this repo's history, cited by issue/PR number. If you cannot point to the file, issue, or commit backing a claim, it does not belong in an issue, a PR description, or this skill.

Jargon: resilience review = a deliberate pass over recently-shipped code looking for latent bugs before they reach users (not a response to an incident). Census = an empirical survey of live/production data to check an assumption before coding against it. ADR = Architecture Decision Record (docs/adr/).


1. The evidence bar

A proposed root cause is not accepted until it clears two hurdles:

1a. It must explain ALL observations, including the negatives

A mechanism that explains the symptom but not a related non-symptom is incomplete — ship the narrower fix and you will be back within the sprint.

Worked example — issue #308 (Future.wait([]) vacuous success):

  • Symptom: a festival with availableBeverageTypes: [] locked the user to stale cache for up to an hour with no error signal.
  • First mechanism proposed: isCompleteFailure (drinksByType.isEmpty && failedTypes.isNotEmpty) is false when both collections are empty, so the provider treats "no work to do" as "refreshed." The first commit fixed this by simply not updating _lastDrinksRefresh on the empty-success path.
  • The negative it didn't explain: switching from an already-loaded festival to an empty one. _lastDrinksRefresh was already set from the previous festival's real load, so leaving it untouched still left isDrinksDataStale false — the switch-to-empty-festival case still locked up.
  • Full-explanation fix: a follow-up commit (1fb41aa, PR #382) explicitly resets _lastDrinksRefresh = null on the empty-success path, so a switch from a loaded festival to an empty one is correctly stale and retriable in both directions.
  • Lesson: when your fix only kills the reproduction case you tested, ask what the first commit's mechanism predicts for the adjacent case (here: switching state, not just cold state). If you can't answer that from the mechanism alone, you don't have the mechanism yet.

Read the full file on GitHub · 320 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 320 lines · 0 tokens per session scan B 55deab93e63c

Subscribe to this mod's changes

research-methodology is a skill published in the GitHub repository richardthe3rd/cambridge-beer-festival-app (2 stars, last pushed yesterday), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 5,003 tokens. A static security scan graded it B with 1 finding (enumerates other installed skills). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

local-ai-agents

Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…

microsoft/ai-agents-for-beginners · 200 tokens

next-cache-components-adoption

Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…

vercel/next.js · 95 tokens

chat-pet-sprite-creation

Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.

microsoft/vscode · 53 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

insight-error-page

Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…

vercel/next.js · 83 tokens