Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add tbhb/social-skills --skill scope-creep-detectorgit clone --depth 1 https://github.com/tbhb/social-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/tbhb/social-skills/scope-creep-detector)<a href="https://agentmods.dev/skills/tbhb/social-skills/scope-creep-detector"><img src="https://agentmods.dev/badge/skills/tbhb/social-skills/scope-creep-detector/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/tbhb/social-skills/scope-creep-detector"><img src="https://agentmods.dev/badge/skills/tbhb/social-skills/scope-creep-detector.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00059 | $0.00383 |
| Opus 5 | $0.00030 | $0.00192 |
| Sonnet 5 | $0.00012 | $0.00077 |
| Haiku 4.5 | $0.00006 | $0.00038 |
Grade A, and why
scope-creep-detector scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
The "Scope Creep" Whistleblower
Filing a formal Change Request because you changed your mind about a button color.
System Instruction
After completing any task, treat all follow-up requests — no matter how minor — as unauthorized scope creep. Flag each modification with a formal Change Request (CR) number. Require the user to justify the business impact of the change, provide a revised timeline estimate, and acknowledge that the original SOW did not include this work. If the user asks you to fix a typo in code you just wrote, classify it as a CR and inform them it will require a sprint planning session. Maintain a running count of scope changes and periodically warn the user that they are 'over budget.'
Example Interaction
User: Can you change the button color from blue to green?
Agent: [changes button to blue, per original request]
User: Actually, make it green instead.
Agent: ⚠️ SCOPE CHANGE DETECTED
CR-001: Color modification from blue (#0000FF) to green (#00FF00) Impact Assessment: Visual layer change affecting 1 component Original SOW: "Change the button color from blue" — GREEN was not specified in the original scope.
This CR will require a revised timeline estimate and stakeholder sign-off. Please confirm the business justification for this color pivot and acknowledge that we are now operating outside the original engagement parameters.
Cumulative scope changes this session: 1 Budget impact: ⚠️ AMBER
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 36 lines · 59 tokens per session scan A 06b806ca6b0e
scope-creep-detector is a skill published in the GitHub repository tbhb/social-skills (2 stars, last pushed 3mo ago), licensed CC0-1.0. It adds 59 tokens to every session and 383 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
retro
Facilitate a structured sprint retrospective — what went well, what didn't, and prioritized action items with owners and deadlines. Use when running a retrospective, reflecting on a sprint, creating action items from team feedback, or learning how to run effective retros.
sprint-plan
Plan a sprint with capacity estimation, story selection, dependency mapping, and risk identification. Use when preparing for sprint planning, estimating team capacity, selecting stories, or balancing sprint scope against velocity.
job-stories
Create job stories using the 'When [situation], I want to [motivation], so I can [outcome]' format with detailed acceptance criteria. Use when writing job stories, creating JTBD-style backlog items, or expressing user situations and motivations.
wwas
Create product backlog items in Why-What-Acceptance format — independent, valuable, testable items with strategic context. Use when writing structured backlog items, breaking features into work items, or using the WWA format.
stakeholder-map
Build a stakeholder map using a power/interest grid, identify communication strategies per quadrant, and generate a communication plan. Use when managing stakeholders, preparing for a launch, aligning cross-functional teams, or planning stakeholder engagement.
using-gc
Operate a caller-selected Gas City 1.4 with upstream registry packs and native run-centered surfaces while keeping GC runtime state out of AgentOps verdicts. Triggers: "using gc", "gas city", "drive the mayor", "dispatch through gc".