Agent skill

Plan

by guardana in guardana/guardana

Turn a development task into one work file in docs/work/ — goal, decisions, lanes with exact files and verification, done-criteria.

Apache-2.0Auto-check passedSecurity

Install Plan

skills CLI
$ npx skills add guardana/guardana --skill plan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install guardana/guardana plan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/guardana/guardana.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/plan .claude/skills/plan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plan
GitHub stars
129
Token cost
~1k tokens
SKILL.md length
538 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Turn a development task into one work file in docs/work/ — goal, decisions, lanes with exact files and verification, done-criteria.

  • Works in 3 steps: Find out, cheaply. Send scout for "where… → Ask only what is the user's to decide… → Name the blast radius. Which of these…
  • M and L tasks before writing code
  • SKILL.md covers Before you write, Design — only for a new…, Lanes and Done-criteria (copy into the…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Plan is an agent skill from guardana/guardana. Turn a development task into one work file in docs/work/ — goal, decisions, lanes with exact files and verification, done-criteria. Use for M and L tasks before writing code, and whenever a task needs a design decision, touches a persisted schema, an exit code, the extension contract or the collector, or will be split across subagents.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Architecture decision records and Prompt injection and agent security. The repository describes itself as: Open-source AI security verification for model artifacts, live endpoints, MCP servers, and recorded agent traces. Reproducible evidence for release decisions. The licence is Apache-2.0.

When your agent uses it

  • M and L tasks before writing code
  • Whenever a task needs a design decision
  • Touches a persisted schema
  • The extension contract

Example prompts

  • “/plan”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Find out, cheaply. Send scout for "where does X live / who calls Y"; read yourself only
  2. Ask only what is the user's to decide (product behaviour, what a user's CI will see, what
  3. Name the blast radius. Which of these does the change touch? Each one adds a done-criterion

What it can do on your machine

Read from SKILL.md and the folder at commit ae7ee8b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Plan loads about 1k tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 538 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from guardana/guardana at commit ae7ee8b, republished under its Apache-2.0 licence (© guardana). 538 words, ~1,011 tokens.

Download SKILL.mdSave it as .claude/skills/plan/SKILL.md (or your agent's skills folder).
name
plan
description
Turn a development task into one work file in docs/work/ — goal, decisions, lanes with exact files and verification, done-criteria. Use for M and L tasks before writing code, and whenever a task needs a design decision, touches a persisted schema, an exit code, the extension contract or the collector, or will be split across subagents.
argument-hint
[task description]

Plan — one file, spec and plan together

Task: $ARGUMENTS

Write docs/work/<yyyy-mm-dd>-<slug>.md from docs/work/TEMPLATE.md. One file replaces the spec, the plan, the task briefs and the progress ledger. Target: under 150 lines. English.

Before you write

  1. Find out, cheaply. Send scout for "where does X live / who calls Y"; read yourself only what the design turns on. Check docs/work/BACKLOG.md, ROADMAP.md and docs/design/ — the design may already exist, accepted and waiting.
  2. Ask only what is the user's to decide (product behaviour, what a user's CI will see, what is paid). Everything the code or the docs can answer, answer yourself. Put open questions at the top of the file and keep working on what does not depend on them.
  3. Name the blast radius. Which of these does the change touch? Each one adds a done-criterion:
    • a persisted document (run manifest, report envelope, baseline, lock file, profile, pack manifest, schemas/) → schema_version moves, a migration exists, the round-trip test covers the new field;
    • an exit code → docs/exit-codes.md and the design table say the same thing;
    • a CLI command or flag → its docs/usage-*.md, docs/index.md, FEATURES.md;
    • the extension contract (Rule / Evaluator / Target, an entry-point group, the pack manifest, the trace format) → every isolated example suite, run with --no-cache;
    • the collector → tenancy and authorization stated per route, PostgreSQL tests that refuse to skip in CI, the envelope still versioned;
    • a rule, evaluator or target → the add-a-rule checklist, docs/generated/ regenerated;
    • a count or a capability claim in prose → generated by a script or cited with a source;
    • a script → a row in docs/maintainers/ops-catalogue.md;
    • reader-facing wording → text-broker, never written here.

Design — only for a new capability or an L task

Before lanes, put two or three real alternatives in "Decisions", one line of trade-off each, and pick one against the product principles in CLAUDE.md. When the design carries risk (a schema, a contract, the collector, a milestone exit criterion), spawn reviewer on the WORK FILE as a challenger — "what breaks, what is missing, is this the simplest thing that works, where could it report clean about something it never examined" — and answer its findings in the file before any code. A design nobody tried to break is a draft.

Show full SKILL.md (175 more words)Show less

Lanes

Split only where files are disjoint. A lane is sized for one coder run: a behaviour, its files, its tests, its verification command. For each lane give: files (exact paths, with anchors where it helps), change (behaviour, not implementation diary), tests (what proves it — including the negative case), verify (the scoped command), owner (main for cross-cutting or subtle work, coder otherwise), depends on. Order lanes so the suite is green after each one.

Wording a reader sees is never a coding lane: mark it text-broker and say which page or prompt receives it.

Done-criteria (copy into the file, delete what does not apply)

  • full gate green, verdict lines read: scripts/ci_local.sh --quiet
  • the documented command run against a real or faked target, its artifact read
  • reviewed (/review), findings fixed or answered
  • the five documentation places answered in the same change (/docs)
  • work file deleted in the shipping commit; leftovers moved to docs/work/BACKLOG.md

Show the user the goal, the decisions and the lane list in a few lines, then continue unless a decision is genuinely theirs.

© guardana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/plan of guardana/guardana.

Open the folder on GitHubat commit ae7ee8b

Compare with similar skills

Plan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Plan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Plan this skillguardana/guardana129—~1kAutomated safety check: PassApache-2.0
Securitytelagod/code-abyss243—~907Automated safety check: PassMIT
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0
Agent Security AuditOWASP/secure-agent-playbook187—~542Automated safety check: PassCC-BY-4.0
Nw Agent TestingnWave-ai/nWave617—~882Automated safety check: PassMIT

Similar skills

  • Security

    telagod/code-abyss

    Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…

    243 GitHub stars~907 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Agent Security Audit

    OWASP/secure-agent-playbook

    Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.

    187 GitHub stars~542 tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Nw Agent Testing

    nWave-ai/nWave

    5-layer testing approach for agent validation including adversarial testing, security validation, and prompt injection resistance

    617 GitHub stars~882 tokensUpdated 22 days ago
    SecurityAuto-check passed
  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub starsUsed in 1 repo~1.8k tokens
    SecurityAuto-check passed

More from guardana/guardana

All 16 skills in this repo
  • Content Model

    guardana/guardana

    Route wording work to GPT (codex CLI) or Gemini (agy CLI) instead of writing it with Claude — landing-page copy, a readability rewrite of a README or docs page, attack and judge prompts for a rule…

    129 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Ship

    guardana/guardana

    Commit and push a finished change the way this repo requires — explicit paths, one commit per logical change, no attribution, the five documentation places answered, the site checks before a push (a…

    129 GitHub stars~836 tokensUpdated yesterday
    Auto-check: notes
  • Add A Rule

    guardana/guardana

    Add security coverage to Guardana the way this repository requires — as a rule, evaluator or target, never by patching the engine — with the fixtures, the framework mapping and the documentation…

    129 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Auto

    guardana/guardana

    Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions.

    129 GitHub stars~792 tokensUpdated yesterday
    Auto-check passed
  • Docs

    guardana/guardana

    Documentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass…

    129 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • False Green Audit

    guardana/guardana

    Hunt for the failure this project exists to prevent — code that compiles, types, tests green, and quietly reports "all clear" about something it never examined.

    129 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Questions about Plan

What does Plan do?

Turn a development task into one work file in docs/work/ — goal, decisions, lanes with exact files and verification, done-criteria. Plan is an agent skill from guardana/guardana. Turn a development task into one work file in docs/work/ — goal, decisions, lanes with exact files and verification, done-criteria.

When should I use Plan?

Plan fits situations like: M and L tasks before writing code; whenever a task needs a design decision; touches a persisted schema; the extension contract.

How do I install Plan in Claude Code?

Run `npx skills add guardana/guardana --skill plan -a claude-code`. Or copy the skill folder (.claude/skills/plan in guardana/guardana) into .claude/skills/plan in your project. Claude Code loads it when a task matches its description.

How do I install Plan in Codex?

Run `npx skills add guardana/guardana --skill plan -a codex`. Or copy the skill folder (.claude/skills/plan in guardana/guardana) into .agents/skills/plan in your project. Codex loads it when a task matches its description.

Can I use Plan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add guardana/guardana --skill plan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plan, .gemini/skills/plan, .github/skills/plan and .opencode/skills/plan in your project.

What does Plan need to run?

SKILL.md names no scripts, command-line tools or credentials: Plan is instructions for the agent only.

Does Plan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Plan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Plan use?

Plan is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Plan use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Plan?

Skills that share tags, products or a category with Plan: Security (telagod/code-abyss, 243 stars), Forensify (alexgreensh/repo-forensics, 188 stars), Plugin Scanner (iflytek/skillhub, 5.2k stars) and Agent Security Audit (OWASP/secure-agent-playbook, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Plan?

guardana (a GitHub organization) maintains it in guardana/guardana, which has 129 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 7, 2026.

Source: guardana/guardana on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.