Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/tomzx/agents/create-requirementsnpx skills add tomzx/agents --skill create-requirementsgit clone --depth 1 https://github.com/tomzx/agentsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/tomzx/agents/create-requirements)<a href="https://agentmods.dev/skills/tomzx/agents/create-requirements"><img src="https://agentmods.dev/badge/skills/tomzx/agents/create-requirements.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00022 | $0.01236 |
| Opus 5 | $0.00011 | $0.00618 |
| Sonnet 5 | $0.00004 | $0.00247 |
| Haiku 4.5 | $0.00002 | $0.00124 |
Grade A, and why
create-requirements scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 94 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Create Requirements
Drafts a structured requirements document from a feature brief, user story, or GitHub issue, capturing functional requirements, non-functional requirements, constraints, and acceptance criteria.
When the feature has a CLI surface, it delegates to /create-cli-design so the commands and options are designed alongside the requirements they serve.
Prerequisites
- Apply the shared SDLC conventions in
skills/sdlc/references/shared.md. - If no argument is provided, use
$ISSUE_TITLEand$ISSUE_BODYas the feature brief (and$ISSUE_NUMBERto link the feature). - A feature brief, user story, or issue description provided in context or as
$1 - Stakeholder goals and constraints, if known
Steps
- Read and understand the input (feature brief, issue, or user story).
- Identify the goal: what problem is being solved and for whom.
- List functional requirements: behaviors the system must exhibit.
- List non-functional requirements: quality attributes (performance, security, availability, etc.).
- Identify constraints: technology choices, regulatory requirements, compatibility needs.
- Write acceptance criteria: testable conditions that confirm each requirement is met.
- Flag any open questions where requirements are unclear or missing.
- Derive the feature directory name
N-<slug>following the Feature Directory Naming convention inskills/sdlc/references/shared.md: use the issue number asNwhen one is available, otherwise ap-prefixed sequence number (p1,p2, ...) marking the feature as pending a placeholder issue. Record the related issue number in the frontmatterissuefield only when an issue exists. - Write the output to
.sdlc/features/N-<slug>/requirements.md, creating the directory if it does not exist. - Detect a CLI surface: when the feature adds or changes CLI commands or options, load the
create-cli-designskill with theskilltool and run it to design the interface from the requirements just drafted, producing.sdlc/features/N-<slug>/cli-design.md.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 94 lines · 22 tokens per session scan A d734098a3394
create-requirements is a skill published in the GitHub repository tomzx/agents (5 stars, last pushed today), licensed MIT. It adds 22 tokens to every session and 1,236 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
instrument-data-to-allotrope
Convert laboratory instrument output files (PDF, CSV, Excel, TXT) to Allotrope Simple Model (ASM) JSON format or flattened 2D CSV. Use this skill when scientists need to standardize instrument data for LIMS systems, data lakes, or downstream analysis. Supports auto-detection of instrument types. Outputs include full…
exploratory-data-analysis
Perform bounded, local exploratory analysis of explicitly supported scientific files. Use for redacted CSV/TSV/JSON profiles; optional NumPy, HDF5, FASTA/FASTQ, and basic image metadata inspection; missingness/leakage audits; outlier and transformation sensitivity; and rigorous EDA report scaffolds. Other domain…
feishu
Work with Feishu or Lark bots, docs, sheets, bitables, approval flows, and OpenAPI/MCP setup without hardcoding credentials.
read
Reads URLs and PDFs by fetching source content, defaulting to concise summaries for plain read requests and clean Markdown when asked to convert, save, quote, cite, or feed downstream work. Use when users ask in any language to read, fetch, check, summarize, quote, cite, convert, or save a URL or PDF. Not for local…
docx-comment-reply
Reply to comments (批注) in Word .docx/.doc files: extract comment context, draft replies, write threaded replies back, and validate OOXML.
file-forensics
Examine what a file claims about itself and what it actually contains — powered by Apache Tika. True content-based type detection (extensions lie), provenance claims (authors, dates, creating application), revision and tamper signals (PDF incremental updates, tracked changes, hidden slides, zip integrity), hidden and…