Agent skill

Opportunity Scan

by coleam00 in coleam00/skills

Scan how you actually work with your coding agent and surface what to encode next.

MITAuto-check passed

Install Opportunity Scan

skills CLI
$ npx skills add coleam00/skills --skill opportunity-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install coleam00/skills opportunity-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/coleam00/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/opportunity-scan .claude/skills/opportunity-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
opportunity-scan
GitHub stars
676
Token cost
~2.4k tokens
SKILL.md length
1,397 words
Files
1
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Scan how you actually work with your coding agent and surface what to encode next.

  • Works in 3 steps: What to scan (required) — exactly one of → Your steer (optional — ask once, accept… → The agent's own capability docs…
  • Evolve your system from real usage
  • SKILL.md covers Inputs — required first, then…, Steps — keep them literal;…, Report contract — prescribe… and Keep it light
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Opportunity Scan is an agent skill from coleam00/skills. Scan how you actually work with your coding agent and surface what to encode next. Point it at ONE run's artifacts to find what would have prevented a specific failure (the reactive loop — 'that went wrong, what should change in the AI layer?'), or at a window of session logs to find recurring patterns worth building (the proactive scan). Agent-agnostic. Outputs a shape-only HTML report. Use to evolve your system from real usage.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: The agent skills I actually use to build software with coding agents. The PIV loop, planning, worktrees, and the meta-skills for building your own AI Layer. The licence is MIT.

When your agent uses it

  • Evolve your system from real usage

Example prompts

  • “that went wrong, what should change in the AI layer?”
  • “/opportunity-scan”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. What to scan (required) — exactly one of
  2. Your steer (optional — ask once, accept "nothing specific") — one input, whose meaning follows the
  3. The agent's own capability docs (optional — normally resolve this yourself) — so the scan knows what your

What it can do on your machine

Read from SKILL.md and the folder at commit 847be08. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Opportunity Scan loads about 2.4k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 1,397 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from coleam00/skills at commit 847be08, republished under its MIT licence (© coleam00). 1,397 words, ~2,359 tokens.

Download SKILL.mdSave it as .claude/skills/opportunity-scan/SKILL.md (or your agent's skills folder).
name
opportunity-scan
description
Scan how you actually work with your coding agent and surface what to encode next. Point it at ONE run's artifacts to find what would have prevented a specific failure (the reactive loop — 'that went wrong, what should change in the AI layer?'), or at a window of session logs to find recurring patterns worth building (the proactive scan). Agent-agnostic. Outputs a shape-only HTML report. Use to evolve your system from real usage.
argument-hint
<a run's artifacts | a logs dir + window> [your steer] [agent docs url]

Opportunity Scan — find what to change, from what actually happened

Reads your agent's own capabilities plus one target you choose, and recommends which primitive each finding should become. Agent-agnostic (Claude Code, Codex, PI, …). It maps what it finds to the full primitive palette (rules · skill · hook · subagent · MCP · automation/workflow), and it works for any agent because it learns that agent's capabilities first.

Two targets, one skill — this is the whole design:

  • A run → the REACTIVE loop. Something just went sideways in a loop you ran. Point the scan at that run's artifacts and ask "what in the AI layer would have prevented this?" You fix the system, not the code.
  • A window of logs → the PROACTIVE scan. Nothing is broken. Point it at weeks of sessions and ask "what do I keep doing by hand that should be encoded?"

Same skill, same output shape — you're just changing what it reads.

This is a discovery tool — what to change — NOT a quality eval (whether a built thing is good). Keep the two separate.

Inputs — required first, then optional

Read $ARGUMENTS as prose, not as positional slots. Only input 1 is required. Input 2 is free-form and will contain spaces, so never split arguments on whitespace and never bind them by position — a steer typed without quotes is still one steer. If something is missing, ask for it once, in a single message, not one question at a time.

  1. What to scan (required) — exactly one of:

    • A RUN (reactive) — the artifacts one loop left behind: the plan, the implementation report, an RCA, the PR body, the review output, the commits/diff. Add that run's session log too if you can point at it. These are already scoped to the run, so there's no session-hunting to do.
    • A WINDOW OF LOGS (proactive) — where your agent keeps session logs, plus how far back. Examples: Claude Code → ~/.claude/projects/ + ~/.claude/history.jsonl; Codex → ~/.codex/sessions/; PI → your extension's log dir. Default window: the last 2 weeks.

    This choice is what makes the scan reactive or proactive. Nothing else changes.

  2. Your steer (optional — ask once, accept "nothing specific") — one input, whose meaning follows the target:

    • Scanning a RUN: the symptom you noticed, in your words — what the agent got wrong, what you had to correct, what annoyed you. You were there; don't make the scan re-derive from the artifacts what you can just say. (This is the "you just did X" of the one-sentence outer loop — the tooled version accepts the same X.) Keep it to the observation; working out why it happened is the scan's job, not yours.
    • Scanning LOGS: the theme you care about — the kind of work you want to stop doing by hand, a quality bar you keep enforcing, a part of the loop that keeps costing you. Without it the scan just ranks by frequency, which is not the same as ranking by what matters to you.

    Either way: you supply the steer, the target supplies the evidence.

  3. The agent's own capability docs (optional — normally resolve this yourself) — so the scan knows what your agent can become (its real extension points). Work it out; do not ask first. Identify which agent you are running as and find its own extensibility docs (for Claude Code that is code.claude.com/docs). Only ask if you genuinely cannot determine it, or if the user wants you pointed somewhere specific. Never assume a fixed set of extension points: read them from whatever docs you actually find.

Steps — keep them literal; this is the fragile part (meta-prompting)

  1. Learn your own capabilities. Determine which agent you are running as and read its capability docs (input 3, which you normally resolve yourself). Write a short internal list of this agent's extension points (rules, skill, hook, subagent, MCP/tool, automation/workflow, whatever the docs describe). Use what the docs say — do not assume a fixed set.

  2. Read the target — branch on what input 1 was:

    • A RUN: read the artifacts in full — they're small, and the detail is the point. If input 2 named a symptom, start there: find it in the artifacts and verify it against what actually happened, rather than re-deriving from scratch what the user already told you. Then reconstruct the rest of the run: what was asked, what the agent did, where it went wrong, where it had to be corrected, what it assumed, what it skipped — the named symptom is the entry point, not a blinder. Read the diff last, as evidence rather than as the subject.
    • A WINDOW OF LOGS: pull out what you actually did — recurring commands, repeated multi-step sequences, repeated instructions/corrections, tools reached for, friction/retries. Aggregate, don't ingest: logs can be huge — prefer the prompt/command-history file over raw transcripts, and reduce with shell tools (jq/grep/sort | uniq -c) so only frequencies and representative samples enter your context, never whole log files.

    Either way: if you can't locate or parse the target, ask the user rather than invent.

  3. Find what to change — the question differs by target:

    • RUN (reactive): for each thing that went wrong or needed correcting, ask "what in the AI layer would have prevented this?" Name the smallest durable change that would have caught it — a line in a rule, a step added to a skill, a hook, a tighter tool scope — specific enough to apply today. Fix the system, not the code: do not propose the code fix, propose the thing that would have made the code fix unnecessary or automatic. ⚠️ Not every failure is a system gap — if something went wrong that no durable change would have prevented, say so plainly instead of inventing a rule for a one-off. One honest "nothing to change here" is worth more than five speculative rules.
    • LOGS (proactive): for each recurring pattern, ask "what should this become?" Rank by roughly (how often it occurs × how much encoding it would save).

    Both targets: pick the best-fit primitive (from step 1's list) and say why. If input 2 was given, weight it — on a run, the named symptom's prevention leads the report (and if the evidence says the symptom was actually something else, say so plainly); on logs, surface what the user said they care about even when it isn't the most frequent pattern, and say plainly when a high-frequency pattern is not worth encoding. And propose each change in the house style of the artifacts that already exist: skim a couple of the project's current rules/skills/agents first and shape the recommendation to look like them, so what it suggests is something the user would actually build. Examples of the mapping:

    • a rule you keep restating → rules (CLAUDE.md / AGENTS.md)
    • a repeated multi-step workflow → a skill
    • a must-never / must-always you keep enforcing by hand → a hook
    • a specialized recurring delegation → a subagent
    • a clean end-to-end hand-off you do often → an automation (later: an Archon workflow)
  4. Write the report as a single self-contained HTML file (see the contract below), then tell the user where it is.

Show full SKILL.md (239 more words)Show less

Report contract — prescribe HOW to render, never WHAT to include

Let the analysis drive the report. Which sections exist, what goes in them, how deep each goes, how many opportunities, which quotes or numbers are worth pulling out — all of that comes from what you actually found, NOT from this skill. Do not box the report into a fixed set of sections, do not seed findings, do not tell it what to conclude. If the data is rich, the report is rich; if a single finding deserves its own deep section, give it one; if something surprising turns up, surface it.

Only the rendering is prescribed:

  • One self-contained .html file (inline CSS), opens in any browser.
  • Visually clean, scannable, and generous — let the findings breathe; use whatever layout, sections, real quotes, stats, or visuals best fit what was actually found.

The rule: this skill governs how to put it on the page, never what goes on the page.

Keep it light

Do exactly these four steps, clearly. Don't add scoring frameworks, config, or extra passes it doesn't need. If a step can't complete (docs or the target not found), stop and ask — never fabricate the analysis. Scan one target per run. If someone wants both the reactive and the proactive view, that's two runs and two reports — mixing "what broke in this loop" with "what I keep repeating across a month" produces a report that answers neither question well.

© coleam00, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/opportunity-scan of coleam00/skills.

Open the folder on GitHubat commit 847be08

Compare with similar skills

Opportunity Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Opportunity Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Opportunity Scan this skillcoleam00/skills676—~2.4kAutomated safety check: PassMIT
Scanwshobson/agents40k—~2.2kAutomated safety check: PassMIT
Repo Scanaffaan-m/ECC276k—~1.5kAutomated safety check: PassMIT
Repo Scanaffaan-m/ECC276k—~1.3kAutomated safety check: PassMIT
Vulnerability Scanningsickn33/agentic-awesome-skills47k1 repos~2.8kAutomated safety check: PassMIT
Harness MCP Scanruvnet/ruflo74k—~429Automated safety check: NotesMIT

Similar skills

  • Scan

    wshobson/agents

    Scans the codebase to generate project-doc.md and AGENTS.md.

    40k GitHub stars~2.2k tokensUpdated 6 days ago
    Agent WorkflowsAuto-check passed
  • Repo Scan

    affaan-m/ECC

    固定されレビュー可能なコミットから外部の repo-scan スキルをインストールするブートストラップ用ポインター。クロススタックのソースコード資産監査を実行する前に repo-scan のインストールが必要な場合に使用する。この ECC ポインター自体は監査を実行しない。

    276k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Repo Scan

    affaan-m/ECC

    用于从固定且可审查的提交安装外部 repo-scan 技能的引导指针。在运行跨栈源代码资产审计前需要安装 repo-scan 时使用;此 ECC 指针本身不执行审计。

    276k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Vulnerability Scanning

    sickn33/agentic-awesome-skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    47k GitHub starsUsed in 1 repo~2.8k tokens
    SecurityAuto-check passed
  • Harness MCP Scan

    ruvnet/ruflo

    Static security scan of a harness's declared MCP surface via harness mcp-scan {path}.

    74k GitHub stars~429 tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • Repo Scan

    affaan-m/ECC

    Bootstrap pointer that installs the external repo-scan skill from a pinned, reviewable commit.

    277k GitHub starsUsed in 1 repo~1.8k tokens
    DevelopmentAuto-check passed

More from coleam00/skills

All 34 skills in this repo
  • Ablate AI Layer

    coleam00/skills

    Measure whether a repository's AI instructions still earn their place, by running the same real task many times with the layer intact and with it stripped, then grading every rule against what…

    676 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check passed
  • Build Dark Factory

    coleam00/skills

    Take a PRD and build a dark factory around it - a repository that takes work in as an issue and ships validated code out with nobody at the keyboard - one component at a time, into the user's actual…

    676 GitHub stars~12k tokensUpdated 3 days ago
    Auto-check passed
  • Drive Screen

    coleam00/skills

    Take real control of the desktop - list and focus windows, type, paste, click, scroll, and screenshot - on Windows, macOS or Linux, and drive other coding-agent sessions running in terminals.

    676 GitHub stars~5.4k tokensUpdated 3 days ago
    Auto-check passed
  • Second Brain Audit

    coleam00/skills

    Audit any second brain, notes folder, or agent memory for facts that have quietly stopped being true, then fix the worst one so it stops recurring.

    676 GitHub stars~4.6k tokensUpdated 3 days ago
    Auto-check passed
  • Build Signal Engine

    coleam00/skills

    Build a personal signal engine from scratch - a system that reads every source someone cares about each day (changelogs and release notes, communities, feeds, videos, papers), makes a quick decision…

    676 GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Worktree Create

    coleam00/skills

    Create one or more git worktrees for parallel development, each on its own branch with gitignored config copied in, dependencies installed, and a health check, by fanning out a setup subagent per…

    676 GitHub stars~958 tokensUpdated 3 days ago
    Auto-check passed

Questions about Opportunity Scan

What does Opportunity Scan do?

Scan how you actually work with your coding agent and surface what to encode next. Opportunity Scan is an agent skill from coleam00/skills. Scan how you actually work with your coding agent and surface what to encode next.

When should I use Opportunity Scan?

Opportunity Scan fits situations like: evolve your system from real usage.

How do I install Opportunity Scan in Claude Code?

Run `npx skills add coleam00/skills --skill opportunity-scan -a claude-code`. Or copy the skill folder (.claude/skills/opportunity-scan in coleam00/skills) into .claude/skills/opportunity-scan in your project. Claude Code loads it when a task matches its description.

How do I install Opportunity Scan in Codex?

Run `npx skills add coleam00/skills --skill opportunity-scan -a codex`. Or copy the skill folder (.claude/skills/opportunity-scan in coleam00/skills) into .agents/skills/opportunity-scan in your project. Codex loads it when a task matches its description.

Can I use Opportunity Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coleam00/skills --skill opportunity-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/opportunity-scan, .gemini/skills/opportunity-scan, .github/skills/opportunity-scan and .opencode/skills/opportunity-scan in your project.

What does Opportunity Scan need to run?

SKILL.md names no scripts, command-line tools or credentials: Opportunity Scan is instructions for the agent only.

Does Opportunity Scan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Opportunity Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Opportunity Scan use?

Opportunity Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Opportunity Scan use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Opportunity Scan?

Skills that share tags, products or a category with Opportunity Scan: Scan (wshobson/agents, 40k stars), Repo Scan (affaan-m/ECC, 276k stars), Repo Scan (affaan-m/ECC, 276k stars) and Vulnerability Scanning (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Opportunity Scan?

coleam00 (a GitHub user) maintains it in coleam00/skills, which has 676 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 7, 2026.

Source: coleam00/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.