scaffold-runner

An interactive wrapper around the scaffold command-line tool, which runs project-building steps and manages their state. It shows the choices for a step before running it.

In plain words
What is it for?
It is for checking which scaffold step is next, starting a build, initializing a new project, adopting an existing codebase, and running approved pipeline steps.
Why use it?
It helps developers understand and approve a pipeline step before that step changes the project. For an existing codebase, it uses an adoption flow that prepares a plan before applying it.

Skill for Claude CodeCodex

Part of the scaffold plugin — 5 skills, 1 agent, 1 hook shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/zigrivers/scaffold/scaffold-runner
Any agent
npx skills add zigrivers/scaffold --skill scaffold-runner
Clone the repo
git clone --depth 1 https://github.com/zigrivers/scaffold

Made for: Claude Code, Codex.

Or install scaffold, the plugin that ships this one along with the rest of its 5 skills, 1 agent, 1 hook.

Per session 73 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 10,455 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00073 $0.10455
Opus 5 $0.00036 $0.05228
Sonnet 5 $0.00015 $0.02091
Haiku 4.5 $0.00007 $0.01046

Measured 3d ago against content hash ccf280884abe, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

scaffold-runner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

content/agent-skills/scaffold-runner/SKILL.md · 747 lines

How it starts

The opening of the file, as written. The whole thing — 747 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Scaffold Runner

An interactive layer over the scaffold CLI: when the user asks to run a pipeline step, surface the step's decision points to the user before executing, then run it.

Activates when the user says "run scaffold <step>", "scaffold <step>", "what's next?", "scaffold status", "start building", is working in a project with a .scaffold/ directory, or asks to set scaffold up in a project that has none yet.

Before .scaffold/ exists, pick the bootstrap command from the directory rather than asking:

  • Empty or brand-new directory → scaffold init.
  • Already has source code or docs → scaffold adopt, which initializes the config and state itself and selects the brownfield methodology. It renders a plan and writes nothing until you pass --apply with the approved --plan-key.

Never run scaffold init before scaffold adopt on an existing codebase: init would select the deep methodology and adopt would then replace it.

Core loop: check scaffold next for what's eligible; before running a step, surface its decision points (depth, strictness, optional sections) to the user; then run it. For stateful pipeline steps, record completion with scaffold complete <step>build steps (e.g. single-agent-start) are stateless and have no completion to record. Key commands: scaffold list, scaffold status, scaffold next, scaffold run <step>, scaffold complete <step>.

For the full command surface, run scaffold guides cli (every command grouped by purpose) and scaffold guides pipeline; scaffold next shows what's eligible now.

This skill provides an intelligent interactive layer between the user and the scaffold CLI. It ensures that decision points embedded in scaffold prompts are surfaced to the user before execution, and manages the full step lifecycle.

When This Skill Activates

  • User says "run scaffold ", "scaffold ", or "run the next scaffold step"
  • User asks "what's next?", "where am I in the pipeline?", or "scaffold status"
  • User asks to run any pipeline step by name (e.g., "create the PRD", "set up testing")
  • User asks to run multiple steps: "run all reviews", "run phases 5-8", "finish the pipeline", "run the next 5 steps"
  • User asks to re-run groups: "re-run all reviews", "redo quality gates", "re-run from user-stories onward"
  • User says "start building", "begin implementation", "run agent", "start agent"
  • User asks about tools: "bump version", "create a release", "show version"
  • User says "what can I build?" or "what tools are available?"
  • Working in a project with a .scaffold/ directory

Read the full file on GitHub · 747 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 747 lines · 73 tokens per session scan A ccf280884abe

Subscribe to this mod's changes

scaffold-runner is a skill published in the GitHub repository zigrivers/scaffold (5 stars, last pushed 3d ago), licensed MIT. It adds 73 tokens to every session and 10,455 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.