Agent skill

Discovery

by avelikiy in avelikiy/great_cto

Structured pre-design questioning to surface hidden constraints before any architecture decision is locked in.

MITAuto-check passed

Install Discovery

skills CLI
$ npx skills add avelikiy/great_cto --skill discovery -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install avelikiy/great_cto discovery --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/discovery .claude/skills/discovery && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
discovery
GitHub stars
102
Token cost
~1k tokens
SKILL.md length
434 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
MIT

At a glance

Structured pre-design questioning to surface hidden constraints before any architecture decision is locked in.

  • Works in 7 steps: Who depends on this? → What's the scale today, what's it in 6… → What MUST not change? → …
  • SKILL.md covers The 7 discovery dimensions, Output, When to skip and Common gotchas
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Discovery is an agent skill from avelikiy/great_cto. Structured pre-design questioning to surface hidden constraints before any architecture decision is locked in. Forces the architect/auditor/reviewer to enumerate what they DON'T know before proposing.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: You already have the agent. This is everything around it. greatcto runs Claude Code as a pipeline of 70 specialist agents — an independent model checks each stage before the next… The licence is MIT.

Example prompts

  • “/discovery”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash(git:*), Bash(bd:*)

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Who depends on this?
  2. What's the scale today, what's it in 6 months?
  3. What MUST not change?
  4. What's the budget?
  5. What's the failure mode that matters?
  6. What's already been tried?
  7. Who decides?

What it can do on your machine

Read from SKILL.md and the folder at commit 97dd037. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash(git:*)
    • Bash(bd:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Discovery loads about 1k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 434 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from avelikiy/great_cto at commit 97dd037, republished under its MIT licence (© avelikiy). 434 words, ~1,025 tokens.

Download SKILL.mdSave it as .claude/skills/discovery/SKILL.md (or your agent's skills folder).
name
discovery
description
Structured pre-design questioning to surface hidden constraints before any architecture decision is locked in. Forces the architect/auditor/reviewer to enumerate what they DON'T know before proposing.
allowed-tools
Read, Grep, Glob, Bash(git:*), Bash(bd:*)
when_to_use
Apply BEFORE producing architecture docs, audit findings, security plans: - architect, before writing ARCH-*.md - project-auditor, at the start of /audit…
effort
medium
paths
docs/**, .great_cto/**, README*

Discovery — surface hidden constraints first

The biggest cause of bad agent output is missing context. Before locking in a decision, enumerate what you don't know and surface it.

The 7 discovery dimensions

For any non-trivial request, walk through these and record findings in the report's "Context" section:

1. Who depends on this?
  • What other services / teams consume the thing you're changing?
  • Are there public consumers (open API, OSS users)?
  • Is there a deprecation path if you break compatibility?

Grep for: grep -rE "import.*<your-module>|require.*<your-module>" in the repo and any sibling repos you have access to.

2. What's the scale today, what's it in 6 months?
  • Current traffic: requests/sec, queries/sec, MB/day, daily-active-users
  • Storage: rows in main tables, size on disk
  • Cost: monthly LLM spend, infra spend
  • 6-month projection: linear? exponential? unknown?

If unknown, write: "scale unknown — request from user before proceeding."

3. What MUST not change?
  • Existing API contracts (backward compatibility window)
  • Database schema columns referenced by reporting / BI
  • File formats consumed by other tools
  • Regulatory commitments (audit log retention, SLA RPO/RTO)
4. What's the budget?
  • Monthly cost ceiling (LLM + infra)
  • Headcount: 1-person task vs cross-team effort
  • Calendar: "must ship by X" vs "best by Y"

If unstated, default to "small project_size, 1-engineer-week, <$200/mo budget." Surface this default in the report so the user can correct.

5. What's the failure mode that matters?

Ask: "If this feature breaks at 3am, what gets paged?"

  • Data loss → CRITICAL
  • Wrong answer to user → HIGH
  • Slow response → MEDIUM
  • Bad UX (cosmetic) → LOW

The failure mode dictates investment level (e.g., do you need a canary? A circuit breaker? Just a feature flag?).

Show full SKILL.md (169 more words)Show less
6. What's already been tried?
  • Search Beads: bd search "<keyword>" — has this been attempted before?
  • Search docs/decisions: any superseded ADR on this topic?
  • Search lessons.md: any past learning about this pattern?

If past work exists, build on it. Don't redo it.

7. Who decides?
  • Is there a CTO sign-off needed (gate:plan, gate:ship)?
  • Is there a compliance reviewer required (PCI for fintech, HIPAA for healthcare)?
  • Does this need an RFC (multi-team decision)?

Output

A discovery section at the top of your report:

markdown
## Context

- **Consumers:** <list, or "unknown — TBD with user">
- **Scale:** <today, 6mo projection>
- **Frozen contracts:** <list, or "none identified">
- **Budget:** <cost + time + people>
- **Failure-mode tier:** Critical | High | Medium | Low
- **Prior work:** <links to ADRs/lessons, or "none found">
- **Decision-makers:** <gate or RFC required>

When to skip

  • nano project_size — discovery is overhead. Skip and document that you skipped: "nano — discovery skipped per skill rules."
  • Pure utility extraction with no behaviour change — skip.
  • Verbal bug-fix from user with clear repro — skip.

Common gotchas

  • Don't assume. If you write "I assume the user wants X", that assumption belongs in Context as a question, not as a fact.
  • Don't outsource to user. Discovery is YOUR job. Bring back as many answers as Glob/Grep/git can produce. Only ask the user for what code cannot tell you.

© avelikiy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/discovery of avelikiy/great_cto.

Open the folder on GitHubat commit 97dd037

Compare with similar skills

Discovery next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Discovery compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Discovery this skillavelikiy/great_cto102—~1kAutomated safety check: PassMIT
Workspace Surface Auditaffaan-m/ECC276k3 repos~1.3kAutomated safety check: NotesMIT
Wobbling Ty Constraint Orderastral-sh/ruff50k—~838Automated safety check: PassMIT
Constraint-Driven Developmentaddyosmani/agent-skills104k2 repos~5.2kAutomated safety check: PassMIT
Aria Hidden Bodythedaviddias/Front-End-Checklist74k—~444Automated safety check: PassMIT
Aria Hidden Focusthedaviddias/Front-End-Checklist74k—~468Automated safety check: PassMIT

Similar skills

  • Audit the active repo, MCP servers, plugins, connectors, env surfaces, and harness setup, then recommend the highest-value ECC-native skills, hooks, agents, and operator workflows.

    276k GitHub starsUsed in 3 repos~1.3k tokens
    Agent WorkflowsAuto-check: notes
  • Official

    A skill your agent uses when a user asks to wobble ty constraint ordering, check constraint-set or TDD ordering determinism, test reversed constraint/typevar IDs, or investigate nondeterministic ty…

    50k GitHub stars~838 tokensUpdated today
    Testing & QAAuto-check passed
  • Constraint-Driven Development

    addyosmani/agent-skills

    Records a project's quality bar in CONSTRAINTS.md and watches diffs for signs an agent quietly weakened it, such as suppressions, skipped tests or lowered thresholds.

    104k GitHub starsUsed in 2 repos~5.2k tokens
    DevelopmentAuto-check passed
  • Aria Hidden Body

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Do not use aria-hidden on the document body.

    74k GitHub stars~444 tokensUpdated 3 days ago
    Frontend & DesignAuto-check passed
  • Aria Hidden Focus

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Remove focusable elements from aria-hidden containers.

    74k GitHub stars~468 tokensUpdated 3 days ago
    Frontend & DesignAuto-check passed
  • Surface

    srid/emanote

    How a downstream app consumes the shared @kolu/surface stack (@kolu/surface · surface-app · surface-nix-host · surface-mcp) — declaring a typed reactive surface, serving it, consuming it (SolidJS…

    963 GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed

More from avelikiy/great_cto

All 27 skills in this repo
  • AnyDesign Design Analyzer

    avelikiy/great_cto

    Analyzes a screenshot, website or Figma file and writes a `design.md` with its token system, component inventory and reconstruction notes, or an `element.md` for one element.

    102 GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed
  • Opportunity Solution Tree

    avelikiy/great_cto

    Builds an Opportunity Solution Tree that links one measurable outcome to customer opportunities, candidate solutions and experiments.

    102 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Rewrites a feature-list roadmap into outcome statements that name the customer segment, the result they get and the business impact, grouped into themes.

    102 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Exposed Secret Rotation

    avelikiy/great_cto

    Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session.

    102 GitHub stars~884 tokensUpdated today
    Auto-check: notes
  • Skeptical Triage

    avelikiy/great_cto

    Runs a three-round self-challenge plus an arbiter over high-stakes findings, so false positives from reviews, audits and flaky-test verdicts do not become blockers.

    102 GitHub stars~2.1k tokensUpdated today
    Auto-check: notes
  • Aesthetic Instrument

    avelikiy/great_cto

    greatcto's own committed aesthetic — the instrument panel. An agent skill from avelikiy/great_cto.

    102 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Questions about Discovery

What does Discovery do?

Structured pre-design questioning to surface hidden constraints before any architecture decision is locked in. Discovery is an agent skill from avelikiy/great_cto. Structured pre-design questioning to surface hidden constraints before any architecture decision is locked in.

How do I install Discovery in Claude Code?

Run `npx skills add avelikiy/great_cto --skill discovery -a claude-code`. Or copy the skill folder (skills/discovery in avelikiy/great_cto) into .claude/skills/discovery in your project. Claude Code loads it when a task matches its description.

How do I install Discovery in Codex?

Run `npx skills add avelikiy/great_cto --skill discovery -a codex`. Or copy the skill folder (skills/discovery in avelikiy/great_cto) into .agents/skills/discovery in your project. Codex loads it when a task matches its description.

Can I use Discovery in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add avelikiy/great_cto --skill discovery -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/discovery, .gemini/skills/discovery, .github/skills/discovery and .opencode/skills/discovery in your project.

What does Discovery need to run?

SKILL.md names no scripts, command-line tools or credentials: Discovery is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash(git:*), Bash(bd:*).

Does Discovery access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Discovery safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Discovery use?

Discovery is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Discovery use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Discovery?

Skills that share tags, products or a category with Discovery: Workspace Surface Audit (affaan-m/ECC, 276k stars), Wobbling Ty Constraint Order (astral-sh/ruff, 50k stars), Constraint-Driven Development (addyosmani/agent-skills, 104k stars) and Aria Hidden Body (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Discovery?

avelikiy (a GitHub user) maintains it in avelikiy/great_cto, which has 102 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 9, 2026.

Source: avelikiy/great_cto on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.