Agent skill

Spike

by ffroliva in ffroliva/gflow-cli

Gather EVIDENCE from the live Flow surface — DOM, network, HAR — before claiming a feature is broken, missing, or impossible.

MITAuto-check passedMedia & Creative

Install Spike

skills CLI
$ npx skills add ffroliva/gflow-cli --skill spike -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ffroliva/gflow-cli spike --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ffroliva/gflow-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/spike .claude/skills/spike && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spike
GitHub stars
264
Token cost
~2.4k tokens
SKILL.md length
1,366 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Gather EVIDENCE from the live Flow surface — DOM, network, HAR — before claiming a feature is broken, missing, or impossible.

  • Works in 4 steps: Read an existing capture.… → In-process probe —… → HAR + DOM harness —… → …
  • Tasks that involve AI video generation
  • SKILL.md covers The rule this exists to enforce, The ladder — cheapest rung…, What a spike must capture and Cost discipline, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Spike is an agent skill from ffroliva/gflow-cli. Gather EVIDENCE from the live Flow surface — DOM, network, HAR — before claiming a feature is broken, missing, or impossible. The first layer of investigation for any "X does not work on Y" question, and the only thing that can settle one.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Media & Creative, covering AI video generation. The repository describes itself as: Drive Google Flow from the command line: Veo video and Imagen images, scripted, batched and pipeline-ready. Ships an MCP server so coding agents can drive it too, giving you and… The licence is MIT.

When your agent uses it

  • Tasks that involve AI video generation

Example prompts

  • “X does not work on Y”
  • “/spike”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read an existing capture. scripts/dev/_spike_out/ and
  2. In-process probe — scripts/dev/spike_*.py. Playwright driving gflow's own
  3. HAR + DOM harness — scripts/dev/har-spike/.
  4. Only then form a conclusion.

What it can do on your machine

Read from SKILL.md and the folder at commit cb6d501. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spike loads about 2.4k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 1,366 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ffroliva/gflow-cli at commit cb6d501, republished under its MIT licence (© ffroliva). 1,366 words, ~2,396 tokens.

Download SKILL.mdSave it as .claude/skills/spike/SKILL.md (or your agent's skills folder).
name
spike
description
Gather EVIDENCE from the live Flow surface — DOM, network, HAR — before claiming a feature is broken, missing, or impossible. The first layer of investigation for any "X does not work on Y" question, and the only thing that can settle one.
version
1.0

spike — measure the blackbox before you describe it

gflow-cli drives a product it does not own. Every statement about what Flow does is either measured or guessed, and a guess written into code or docs becomes a fact nobody re-checks.

Load this skill before you write, say, or encode any of these:

  • "X is not supported / not available / not rendered on this host"
  • "this surface is labs-only" · "the migrated host cannot do X"
  • "the selector is gone" · "Flow removed it"
  • a raise_if_migrated-style guard, a capability table, or a KNOWN_ISSUES entry asserting an absence
  • an issue reply telling a user a feature cannot work

The rule this exists to enforce

A SELECTOR THAT DOES NOT MATCH IS EVIDENCE ABOUT THE SELECTOR.
IT IS NEVER EVIDENCE ABOUT THE FEATURE.

A wait that times out tells you your anchor missed. It tells you nothing about whether the thing exists. To claim absence you need a positive observation of absence — a DOM inventory that lists what IS there, a network log that shows what was and was not called. "It timed out" is not that.

Written from a two-line failure that cost a day. On 2026-09-06 gflow character create was believed impossible on flow.google.com. The entire chain came from one 20 s readiness timeout: selector missed → gate timed out → "no prompt textbox" → "labs-only surface" → "renders no prompt textbox for it, ever", shipped in a code comment, the CHANGELOG, a release ledger and a test class NAME. #701 then added a guard that aborted before probing the DOM — which made the claim unfalsifiable, because no run could ever look. Reality: the editor was fully present, on the same backend; labs renders React + Slate, the migrated host renders Angular + ProseMirror. Seven selectors changed and it worked. Thirty minutes of DOM reading would have prevented all of it.

Never put a guard in front of a probe. A fail-fast that runs before the evidence is collected deletes the evidence that would correct it. If you must fail fast, fail after looking, and say what you looked at.

The ladder — cheapest rung that answers the question

  1. Read an existing capture. scripts/dev/_spike_out/ and docs/superpowers/spikes/ may already hold the answer. Free.
  2. In-process probe — scripts/dev/spike_*.py. Playwright driving gflow's own transport, so you see exactly what gflow sees. Use when you can already reach the surface, or want to observe the production path's own traffic. $0 unless you submit.
  3. HAR + DOM harness — scripts/dev/har-spike/. CDP-attached real Chrome; a human drives the failing action by hand and you get the complete HAR. Use when the driver cannot get far enough to observe anything, or when an in-process capture is ambiguous. This is the tiebreaker.
  4. Only then form a conclusion.

Start at 1. Escalate only when the rung below cannot answer it.

What a spike must capture

Write a new scripts/dev/spike_<question>.py when none fits. It should record:

  • Structure, not labels. Ligature text, ARIA roles, custom-element tag names, hrefs. Never anchor on display text — see the locale-invariance rule in AGENTS.md. Custom elements (<flow-slot-chip-button>) are the best anchors available: they are component boundaries, not layout accidents.
  • The carrier. labs renders ligatures in <i class="google-symbols">, the migrated host in <mat-icon>. Same ligature, different tag — a mismatch here looks exactly like a missing feature.
  • Both sides of a transition. Snapshot before AND after the click. A signal present in both proves nothing; one that appears only after is a real settle signal.
  • The network. Which hosts, which routes, which batchexecute rpcids. This is how "the backend is shared, only the frontend was rebuilt" gets established instead of assumed.
  • Occlusion. An element can exist, be visible, and still not be clickable. Record what elementFromPoint returns over it.
  • A control. If you are testing a fix, run the same probe with the fix stashed. A result with no control is a coincidence with formatting.

Cost discipline

Navigation, DOM reads, flow.createEntity, batchDeleteAssets and a reCAPTCHA mint are all free. Image generation costs daily quota, zero credits. Video costs credits. Say which in the spike's docstring, and delete anything the spike created.

Profile etiquette — never kill a browser on a profile you do not hold

ProfileLockedError is the lease working, not a stale lock. It means another process owns that profile right now, and the error carries the holder's evidence. Read it. Then wait, or spike on a different profile. Both are cheap; neither can corrupt anything.

Never kill Chrome processes to clear the way. Two Chrome instances on one user_data_dir is the corruption the lease exists to prevent, and a process list cannot tell you which browser belongs to whom — so "these look like my orphans" is a guess made against a fact the lease already gave you.

Written from the incident it prevents. On 2026-09-07 two sessions worked this repo at once. One ran the e2e suite on denon82 and held its lease. The other hit ProfileLockedError, read the resulting Chrome processes as orphans of its own spike, and killed eighteen of them in two batches; nine belonged to the running suite. It then diagnosed the cause as "spike scripts do not take the lease" — but its own spike went through FlowApiClient, which acquires at api/client.py before Chrome starts, so it had held the lease. The tool was correct and was overruled by a process list. A real defect did surface underneath — three scripts launched Chrome outside any lease, fixed with a guard test in #717 — but it was not what caused the incident, and fixing it would not have prevented it. This rule would have.

If you write a spike that launches Chrome itself rather than through FlowApiClient, wrap it: async with ProfileLease(profile_dir), async_playwright() as pw:. Chrome must never start on a profile this process does not own.

Show full SKILL.md (432 more words)Show less

Pre-register the reading before you run

Write down what each possible outcome will mean before the spike executes — in the script's own docstring, where it is timestamped by the commit. Then the result cannot be reinterpreted to suit whatever change the spike was gating.

OutcomeReading
N/Nstable
mixedit flaps
0/Ndoes not reproduce; settles nothing

That last row is the one worth pre-writing, because it is the one you will be tempted to spin. A condition that has stopped reproducing has not been shown to be transient. It is equally consistent with some state having changed underneath it, and a spike that cannot distinguish those has produced one honest result: unmeasured.

Unmeasured is a real finding. Report it as the answer, not as a failed run — and say what would settle it, so the next person who sees the condition live knows what to capture.

Worked example: 2026-09-10-about-redirect-stability.md — asked whether Flow's /about redirect is transient, got 0/5, and shipped "unmeasured" rather than letting a disappearance argue for a retry flag.

Output

  • Evidence → scripts/dev/_spike_out/ (gitignored; captures carry Bearer tokens, cookies and prompts, and *.har is gitignored repo-wide). Never paste a raw capture into an issue — scripts/dev/har-spike/extract_har_summary.py produces the redacted summary that is safe to share.
  • Findings → docs/superpowers/spikes/<date>-<slug>.md. The finding is durable; the bytes that produced it are not.
  • The spike script itself → committed. A question worth asking once gets asked again.

When you are done

State the verdict as what was observed, with the file and line of the evidence — not as what you concluded. Then say plainly what you did NOT measure. An unmeasured gap named is a lead; an unmeasured gap implied is the next day lost.

Feeds: issue-assessment (triage needs evidence, not a hypothesis), predict (persona claims about a live surface must cite a capture), live-verify (proves the fix; this proves the diagnosis), and — for a bug — scenario, where what you observed becomes the Given/When/Then of a test.

A spike is step 0, never the deliverable

A spike answers a question. It does not close an issue, and its script is not the regression test — nothing re-runs it, so nothing notices when Flow changes again.

The observation you just made is the body of a scenario. What you drove is the Given, what you triggered is the When, what the DOM or the wire actually returned is the Then. Carry it into scenario and, if it can only happen in a browser, into tests/e2e/test_<slug>_bdd.py — the route is issue-resolve § The Bug Lane.

A spike whose finding never became a test has bought you one answer, once, at full price.

© ffroliva, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/spike of ffroliva/gflow-cli.

Open the folder on GitHubat commit cb6d501

Compare with similar skills

Spike next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spike compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spike this skillffroliva/gflow-cli264—~2.4kAutomated safety check: PassMIT
Video Generationbytedance/deer-flow83k4 repos~1.4kAutomated safety check: PassMIT
Video Shotseternityspring/reelbench-skills8682 repos~1.8kAutomated safety check: NotesApache-2.0
Video Cover Imageitwanger/toBeBetterJavaer18k—~3.3kAutomated safety check: PassNone
Seedancesongguoxs/seedance-prompt-skill2.9k1 repos~2.5kAutomated safety check: PassNone
HyperFrames Video Entry Pointheygen-com/hyperframes59k3 repos~5.2kAutomated safety check: PassApache-2.0

Similar skills

  • Video Generation

    bytedance/deer-flow

    Generates short videos from a structured JSON prompt, optionally guided by a reference image used as the first or last frame.

    83k GitHub starsUsed in 4 repos~1.4k tokens
    Media & CreativeAuto-check passed
  • Video Shots

    eternityspring/reelbench-skills

    拉片:把一条成片拆成逐镜头的分析表——每个镜头的时长、景别、类别、运镜、画面. An agent skill from eternityspring/reelbench-skills.

    868 GitHub starsUsed in 2 repos~1.8k tokens
    Media & CreativeAuto-check: notes
  • Video Cover Image

    itwanger/toBeBetterJavaer

    Generate matched 3:4, 16:9, and 4:3 short-video cover images from toBeBetterJavaer video scripts or AI/Java technical topics.

    18k GitHub stars~3.3k tokensUpdated today
    Media & CreativeAuto-check passed
  • Seedance

    songguoxs/seedance-prompt-skill

    This skill should be used when the user asks to "generate video prompts", "create Seedance prompts", "write video descriptions", mentions "Seedance", "seedance", "即梦", "即梦平台", "视频提示词", "视频生成"…

    2.9k GitHub starsUsed in 1 repo~2.5k tokens
    Media & CreativeAuto-check passed
  • HyperFrames Video Entry Point

    heygen-com/hyperframes

    Entry point for making, editing and rendering videos from HTML compositions with HyperFrames, routing each request to the right workflow.

    59k GitHub starsUsed in 3 repos~5.2k tokens
    Media & CreativeAuto-check passed
  • Lanshu Create AI Presenter Video

    cclank/lanshu-create-ai-presenter-video

    Turn a topic or finished script into a complete, publish-ready explainer video — led by an AI presenter from an authorized adult presenter image, or performed in one of nine visual explainer styles…

    2.5k GitHub stars~3.6k tokensUpdated 2 days ago
    Media & CreativeAuto-check passed

More from ffroliva/gflow-cli

All 17 skills in this repo
  • Gflow CLI

    ffroliva/gflow-cli

    A skill your agent uses when the user wants to drive Google Flow (Veo image-to-video, Veo text-to-video, Imagen / Nano Banana image generation) from the terminal or a script — including…

    264 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check: notes
  • Issue Assessment

    ffroliva/gflow-cli

    A skill your agent uses when triaging a GitHub issue for gflow-cli — a reporter's bug claim, a freshly-filed issue, or deciding whether and how to act on one.

    264 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Issue Resolve

    ffroliva/gflow-cli

    A skill your agent uses when an assessed gflow-cli issue (verdict CONFIRMED-BUG or LIKELY-BUG) has localized, verifiable scope and should be driven to a fix.

    264 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Live Verify

    ffroliva/gflow-cli

    Two-part gate for gflow-cli feature/fix work. An agent skill from ffroliva/gflow-cli.

    264 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Video Production

    ffroliva/gflow-cli

    A skill your agent uses when the user wants a finished video out of gflow rather than a single clip — a scripted scene, a talking-head or dialogue piece, an explainer, a product montage, a story…

    264 GitHub stars~7k tokensUpdated yesterday
    Auto-check passed
  • Check

    ffroliva/gflow-cli

    Auto-fix lint and formatting, then report types and tests. An agent skill from ffroliva/gflow-cli.

    264 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed

Questions about Spike

What does Spike do?

Gather EVIDENCE from the live Flow surface — DOM, network, HAR — before claiming a feature is broken, missing, or impossible. Spike is an agent skill from ffroliva/gflow-cli. Gather EVIDENCE from the live Flow surface — DOM, network, HAR — before claiming a feature is broken, missing, or impossible.

When should I use Spike?

Spike fits situations like: tasks that involve AI video generation.

How do I install Spike in Claude Code?

Run `npx skills add ffroliva/gflow-cli --skill spike -a claude-code`. Or copy the skill folder (skills/spike in ffroliva/gflow-cli) into .claude/skills/spike in your project. Claude Code loads it when a task matches its description.

How do I install Spike in Codex?

Run `npx skills add ffroliva/gflow-cli --skill spike -a codex`. Or copy the skill folder (skills/spike in ffroliva/gflow-cli) into .agents/skills/spike in your project. Codex loads it when a task matches its description.

Can I use Spike in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ffroliva/gflow-cli --skill spike -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spike, .gemini/skills/spike, .github/skills/spike and .opencode/skills/spike in your project.

What does Spike need to run?

SKILL.md names no scripts, command-line tools or credentials: Spike is instructions for the agent only.

Does Spike access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Spike safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Spike use?

Spike is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spike use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Spike?

Skills that share tags, products or a category with Spike: Video Generation (bytedance/deer-flow, 83k stars), Video Shots (eternityspring/reelbench-skills, 868 stars), Video Cover Image (itwanger/toBeBetterJavaer, 18k stars) and Seedance (songguoxs/seedance-prompt-skill, 2.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spike?

ffroliva (a GitHub user) maintains it in ffroliva/gflow-cli, which has 264 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.

Source: ffroliva/gflow-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.