Dependency Scanning
sickn33/agentic-awesome-skills
Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.
Prepare a proportionate work plan with outcomes, steps, dependencies and acceptance evidence.
$ npx skills add AlpacaLabsLLC/skills-for-architects --skill workplan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install AlpacaLabsLLC/skills-for-architects workplan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/AlpacaLabsLLC/skills-for-architects.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workplan .claude/skills/workplan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "workplan" agent skill from https://github.com/AlpacaLabsLLC/skills-for-architects/tree/main/skills/workplan into .claude/skills/workplan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workplan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/AlpacaLabsLLC/skills-for-architects/tree/main/skills/workplanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add AlpacaLabsLLC/skills-for-architects --skill workplan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install AlpacaLabsLLC/skills-for-architects workplan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlpacaLabsLLC/skills-for-architects.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/workplan .agents/skills/workplan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "workplan" agent skill from https://github.com/AlpacaLabsLLC/skills-for-architects/tree/main/skills/workplan into .agents/skills/workplan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workplan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AlpacaLabsLLC/skills-for-architects --skill workplan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install AlpacaLabsLLC/skills-for-architects workplan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlpacaLabsLLC/skills-for-architects.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/workplan .cursor/skills/workplan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "workplan" agent skill from https://github.com/AlpacaLabsLLC/skills-for-architects/tree/main/skills/workplan into .cursor/skills/workplan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workplan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/AlpacaLabsLLC/skills-for-architects.git --path skills/workplan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add AlpacaLabsLLC/skills-for-architects --skill workplan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install AlpacaLabsLLC/skills-for-architects workplan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlpacaLabsLLC/skills-for-architects.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/workplan .gemini/skills/workplan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "workplan" agent skill from https://github.com/AlpacaLabsLLC/skills-for-architects/tree/main/skills/workplan into .gemini/skills/workplan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workplan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install AlpacaLabsLLC/skills-for-architects workplanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add AlpacaLabsLLC/skills-for-architects --skill workplan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/AlpacaLabsLLC/skills-for-architects.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/workplan .github/skills/workplan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "workplan" agent skill from https://github.com/AlpacaLabsLLC/skills-for-architects/tree/main/skills/workplan into .github/skills/workplan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workplan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AlpacaLabsLLC/skills-for-architects --skill workplan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install AlpacaLabsLLC/skills-for-architects workplan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AlpacaLabsLLC/skills-for-architects.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/workplan .opencode/skills/workplan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "workplan" agent skill from https://github.com/AlpacaLabsLLC/skills-for-architects/tree/main/skills/workplan into .opencode/skills/workplan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workplan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
workplanPrepare a proportionate work plan with outcomes, steps, dependencies and acceptance evidence.
Workplan is an agent skill from AlpacaLabsLLC/skills-for-architects. Prepare a proportionate work plan with outcomes, steps, dependencies and acceptance evidence. Use to plan substantial work or coordinate an approved team; a plan-only request does not authorize implementation.
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `README.md`, `host-contract.json` and `templates/plan.md`).
The repository describes itself as: Claude Code skills for architecture, real estate, and workplace strategy. Type /skill-name and go. The licence is MIT.
Read from SKILL.md and the folder at commit 657bfd5. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditGlobGrepBashAskUserQuestionFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Workplan loads about 1.2k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 578 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Write, Edit, Glob, Grep, Bash, AskUserQuestionAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from AlpacaLabsLLC/skills-for-architects at commit 657bfd5, republished under its MIT licence (© AlpacaLabsLLC). 578 words, ~1,233 tokens.
.claude/skills/workplan/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Before acting, read the host contract, this component's declaration (skill:workplan), and applicable workspace semantics. Load only the required modes from the shared catalog.
<!-- architecture-studio:harness-compatibility -->
Use the host adapter and available native tools or ordinary task-specific code. Apply the receive-owned semantic document rules directly; no installed library, nested skill invocation, runner or executable reconstruction is required. Resolve context before durable work. Existing exact authorization persists; ask only for material missing information or missing permission.
Plan work, not a building/site/floor design. Route regulated/domain analysis to its proper owner. Inspect only enough evidence to make the plan reliable; distinguish facts from assumptions. Use applicable originals for external claims.
Quick straightforward tasks proceed within existing authorization. Meaningful multistep work that benefits from advance review receives a concise inline plan: intended result, concrete steps/outputs, relevant dependencies and checks. A durable plan is needed only when requested or useful for project continuity; do not create a file as an invocation tax. No rigid time threshold or compulsory Norma hop applies.
When parallel work benefits the task, state team size, roles, bounded assignments, concurrent work/dependencies, exclusive file ownership and integrator. Obtain only missing approval of that concrete work/team. Plan-only requests end at the plan. Prior exact approval survives resume. The main harness creates approved agents through actual exposed tools, verifies their identities and integrates results; workers return questions to the main loop. Unavailable/failed delegation is disclosed; only a material unapproved fallback needs further approval.
Resolve one project and read relevant PROJECT.md facts, registered decisions/source documents and the Agreement section when present. Compare scope advisory findings without creating commercial gates. Choose enough detail for the task; the plan template is a useful structure, not a required heading/word quota.
Each work unit names its result, owner, affected surface, inputs/dependencies and meaningful acceptance evidence. Include known risks/unknowns that change execution. Never inflate a small task with a committee, duplicate registry, blanket benchmark or mandatory deterministic validator.
Before persistent changes, follow the native mutation sequence: Inspect → Prepare → Verify preparation → Apply → Verify result → Complete. Inspect pending work first. Finish and verify preparation before the first canonical write: separately reread every saved original and prepared file, check its complete actual bytes, establish durable saving, and inspect actual permissions, ownership and ACLs. Merely writing recovery files does not finish verification. Apply only that verified set. Mark complete only after fresh readback validates the entire affected result and its relationships. Read-only requests and inline drafts need no publication sequence.
Saving a plan affects the complete plan document plus DOCUMENTS.csv and any explicitly authorized attachment registrations. Prepare and verify that full set before writing the first member. Selected source records remain read guards. Plan publication does not include task import or implementation of the planned work.
Prepare Markdown; resolve confirmed document coordinates using documents.resolve; receive with kind plan. Paths follow the firm template. A revision is a new registered document with explicit supersedes, preserving the earlier plan. Reopen and report the actual document ID/path and remaining decisions.
Task register entries, project facts and durable decisions are separate promotions. Offer only useful selected handoffs; a saved plan does not silently import tasks or execute the work. Inline planning does not imply durable archival of conversation.
workplan.prepare means the authored preparation procedure above; it may produce an inline draft without a workspace write. Persistence uses the shared native document contract, restricted here to kind plan and authorized attachments. A saved record does not authorize its proposed actions or promote facts/decisions automatically.
© AlpacaLabsLLC, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files in skills/workplan of AlpacaLabsLLC/skills-for-architects.
Open the folder on GitHubat commit 657bfd5
Workplan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Workplan this skillAlpacaLabsLLC/skills-for-architects | 373 | — | ~1.2k | Automated safety check: Notes | MIT | |
| Dependency Scanningsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Dependency Checkruvnet/ruflo | 74k | — | ~258 | Automated safety check: Pass | MIT | |
| Dependency Updatecodewhale-hq/Codewhale | 41k | — | ~142 | Automated safety check: Pass | MIT | |
| Os Step By Stepkharmanskyi/open-steps | 1.2k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Bump Sentry Dependencygetsentry/sentry | 46k | — | ~815 | Automated safety check: Pass | Custom licence |
sickn33/agentic-awesome-skills
Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.
ruvnet/ruflo
Scan project dependencies for known vulnerabilities and CVEs.
codewhale-hq/Codewhale
Read release notes/changelogs, update a defined dependency scope, handle breaking changes, and verify.
kharmanskyi/open-steps
ALWAYS invoke this skill when you need the user to act - run a command, paste a secret, click, approve - and whenever they ask how to do something or say they do not know what to do: "step by step"…
getsentry/sentry
Bumps an existing Python dependency in getsentry/sentry through the repository's self-serve GitHub Actions workflow.
logseq/logseq
Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions…
AlpacaLabsLLC/skills-for-architects
Register received or authored project documents by confirmed coordinates, preserve their filenames and provenance, and find or verify registered documents.
AlpacaLabsLLC/skills-for-architects
Create an HTML color palette from a mood, description, or image, with swatches, color codes, pairings, and contrast checks.
AlpacaLabsLLC/skills-for-architects
Research population, income, age, housing, and employment around a site.
AlpacaLabsLLC/skills-for-architects
Research climate, sun, flood, seismic, soil, contamination, and topography for a site.
AlpacaLabsLLC/skills-for-architects
Research transit, walking, cycling, pedestrian infrastructure, and airport access for a site.
AlpacaLabsLLC/skills-for-architects
Clean a local FF&E CSV schedule by normalizing casing, dimensions, units, language, materials, and formatting.
Prepare a proportionate work plan with outcomes, steps, dependencies and acceptance evidence. Workplan is an agent skill from AlpacaLabsLLC/skills-for-architects. Prepare a proportionate work plan with outcomes, steps, dependencies and acceptance evidence.
Workplan fits situations like: plan substantial work; coordinate an approved team; A plan-only request does not authorize implementation.
Run `npx skills add AlpacaLabsLLC/skills-for-architects --skill workplan -a claude-code`. Or copy the skill folder (skills/workplan in AlpacaLabsLLC/skills-for-architects) into .claude/skills/workplan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add AlpacaLabsLLC/skills-for-architects --skill workplan -a codex`. Or copy the skill folder (skills/workplan in AlpacaLabsLLC/skills-for-architects) into .agents/skills/workplan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AlpacaLabsLLC/skills-for-architects --skill workplan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/workplan, .gemini/skills/workplan, .github/skills/workplan and .opencode/skills/workplan in your project.
SKILL.md names no scripts, command-line tools or credentials: Workplan is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Glob, Grep, Bash, AskUserQuestion.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Workplan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Workplan: Dependency Scanning (sickn33/agentic-awesome-skills, 47k stars), Dependency Check (ruvnet/ruflo, 74k stars), Dependency Update (codewhale-hq/Codewhale, 41k stars) and Os Step By Step (kharmanskyi/open-steps, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
AlpacaLabsLLC (a GitHub organization) maintains it in AlpacaLabsLLC/skills-for-architects, which has 373 GitHub stars. The repository holds 60 skills in this directory. The repository was last updated on October 5, 2026.
Source: AlpacaLabsLLC/skills-for-architects on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.