Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add SenMuShare/senmu-buildos --skill senmu-build-productgit clone --depth 1 https://github.com/SenMuShare/senmu-buildosWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/senmushare/senmu-buildos/senmu-build-product)<a href="https://agentmods.dev/skills/senmushare/senmu-buildos/senmu-build-product"><img src="https://agentmods.dev/badge/skills/senmushare/senmu-buildos/senmu-build-product/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/senmushare/senmu-buildos/senmu-build-product"><img src="https://agentmods.dev/badge/skills/senmushare/senmu-buildos/senmu-build-product.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00040 | $0.00578 |
| Opus 5 | $0.00020 | $0.00289 |
| Sonnet 5 | $0.00008 | $0.00116 |
| Haiku 4.5 | $0.00004 | $0.00058 |
Grade A, and why
senmu-build-product scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 30 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Product Management
Maintain one truth chain across optional requirements, version PRDs, current product specifications, and acceptance. Continue only for durable contract, version-placement, or cross-page content changes.
Route by Outcome
- Requirements, versions, document transitions, freezing, reconciliation: Product Iteration.
- Cross-page buttons, states, errors, terms, generated content: Interface Content, then only Chinese or English. Fill gaps in existing standards.
Read a User Requirements, Version PRD, or Product Specification template only when creating it. Decide low-risk discussions directly.
Core Contract
- The user decides goals, preferences, and authorization; questions, claims, and proposals are inputs. Distinguish facts, expectations, assumptions, and advice. Judge independently from evidence, counterexamples, alternatives, cost, and risk. Explain material disagreement; after an informed decision, act within authorization and Kernel boundaries.
- Assign work to the current version, a successor, or an optional backlog. Infer when facts suffice; ask only if placement changes scope or timing. Never infer line roles from version numbers.
- Product owns cross-page language. Store terminology, voice, and platform differences in an existing product/design owner. One-off wording that preserves meaning stays with implementation.
- Templates structure chosen artifacts only; remove inapplicable optional sections and avoid empty ledgers.
- Version PRDs own approved scope/acceptance; implementation choices preserve them. Reconcile material deviations before changing behavior. Mid-task feedback steers the open scope unless the user replaces it; retain unfinished requirements in the existing task owner. Backlogs are optional.
- For high investment, weak evidence, or uncertainty, compare doing nothing, reuse/buy, and the smallest solution. Avoid full discovery for cheap reversible changes.
- Record activation, persistence, failure, exit, switching, draft, and recovery only when acceptance changes. Presentation-only changes do not alter the PRD.
- Keep requirement lifecycle, iteration commitment, implementation completion, acceptance, and release distinct.
- Give implemented requirements stable IDs linking PRD, task, code, tests, acceptance, and release evidence.
What ships with it
8 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- agents/openai.yaml 365 B
- assets/product-governance/PRD.template.md 5.0 KB
- assets/product-governance/PRODUCT_SPECIFICATION.template.md 2.1 KB
- assets/product-governance/USER_REQUIREMENTS.template.md 881 B
- references/chinese-interface-copy.md 1.8 KB
- references/english-interface-copy.md 1.0 KB
- references/interface-copy-and-content-design.md 5.2 KB
- references/product-requirements-and-iteration.md 11 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago Changed 86b1f611a208
- 7d ago Changed 68377f41bf36
- 8d ago Changed · -8 lines · -13 tokens per session 8f04673080e9
- 12d ago First seen · 38 lines · 53 tokens per session scan A bb7fa45faa53
senmu-build-product is a skill published in the GitHub repository SenMuShare/senmu-buildos (2 stars, last pushed 4d ago), licensed Apache-2.0. It adds 40 tokens to every session and 578 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
openproject-codex
Use the OpenProject Codex plugin to inspect and manage work in Codex through the OpenProject API.
github-project-management
Comprehensive GitHub project management with swarm-coordinated issue tracking, project board automation, and sprint planning.
manage-taskboard
Manage Codex Taskboard / e-taskboard work with taskctl. Use for taskboard issue IDs, status sync, comments, or taskctl cloud setup—not for unrelated product docs.
decision-map
Turn a loose idea into a git-tracked, session-resumable map of typed investigation tickets, then drive them to resolution one at a time. The planning-loop engine for work that is still being figured out — too fuzzy for a campaign, too big for a single intake item. Resolved tickets graduate into .planning/intake/ for…
meegle
A guide and command-line interface for managing Feishu/Lark Meego project data, including work items, workflow steps, views, personal tasks, and schedules. Feishu/Lark is a collaboration platform, while Meego is its project-management system.
ambient-project
Quietly maintain a useful project view from meaningful work in the current Codex session. Use when work creates a task, bug, decision, idea, risk, milestone, plan, progress update, or explicit completion.