Cm Refactor
kingxiaozhe/cm-workflow
用户明确要求“只整理结构,不改变行为”时使用。执行边界分流、行为判官、分批重构和独立审查;缺陷修复转交 cm-fix,新增或变化的业务行为转交 cm-prd。
Keeps a change scoped to what was asked. An agent skill from waynesutton/builder-skills.
$ npx skills add waynesutton/builder-skills --skill avoid-feature-creep -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install waynesutton/builder-skills avoid-feature-creep --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/waynesutton/builder-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/avoid-feature-creep .claude/skills/avoid-feature-creep && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "avoid-feature-creep" agent skill from https://github.com/waynesutton/builder-skills/tree/main/skills/avoid-feature-creep into .claude/skills/avoid-feature-creep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avoid-feature-creep", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/waynesutton/builder-skills/tree/main/skills/avoid-feature-creepType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add waynesutton/builder-skills --skill avoid-feature-creep -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install waynesutton/builder-skills avoid-feature-creep --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waynesutton/builder-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/avoid-feature-creep .agents/skills/avoid-feature-creep && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "avoid-feature-creep" agent skill from https://github.com/waynesutton/builder-skills/tree/main/skills/avoid-feature-creep into .agents/skills/avoid-feature-creep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avoid-feature-creep", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add waynesutton/builder-skills --skill avoid-feature-creep -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install waynesutton/builder-skills avoid-feature-creep --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waynesutton/builder-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/avoid-feature-creep .cursor/skills/avoid-feature-creep && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "avoid-feature-creep" agent skill from https://github.com/waynesutton/builder-skills/tree/main/skills/avoid-feature-creep into .cursor/skills/avoid-feature-creep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avoid-feature-creep", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/waynesutton/builder-skills.git --path skills/avoid-feature-creep--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add waynesutton/builder-skills --skill avoid-feature-creep -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install waynesutton/builder-skills avoid-feature-creep --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waynesutton/builder-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/avoid-feature-creep .gemini/skills/avoid-feature-creep && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "avoid-feature-creep" agent skill from https://github.com/waynesutton/builder-skills/tree/main/skills/avoid-feature-creep into .gemini/skills/avoid-feature-creep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avoid-feature-creep", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install waynesutton/builder-skills avoid-feature-creepInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add waynesutton/builder-skills --skill avoid-feature-creep -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/waynesutton/builder-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/avoid-feature-creep .github/skills/avoid-feature-creep && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "avoid-feature-creep" agent skill from https://github.com/waynesutton/builder-skills/tree/main/skills/avoid-feature-creep into .github/skills/avoid-feature-creep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avoid-feature-creep", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add waynesutton/builder-skills --skill avoid-feature-creep -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install waynesutton/builder-skills avoid-feature-creep --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waynesutton/builder-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/avoid-feature-creep .opencode/skills/avoid-feature-creep && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "avoid-feature-creep" agent skill from https://github.com/waynesutton/builder-skills/tree/main/skills/avoid-feature-creep into .opencode/skills/avoid-feature-creep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avoid-feature-creep", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
avoid-feature-creepKeeps a change scoped to what was asked. An agent skill from waynesutton/builder-skills.
Avoid Feature Creep is an agent skill from waynesutton/builder-skills. Keeps a change scoped to what was asked. Flags extra features, refactors, and 'while we are here' edits, and moves them to a suggestions list instead of the diff. Use when a request is small and the agent is about to expand it, when a PRD grows beyond its problem statement, or when the user says 'just do what I asked'.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including assets (for example `agents/openai.yaml`).
It sits in Product & Project Management, covering PRD writing and Refactoring. The repository describes itself as: Builder skills for Convex apps. Convex patterns plus a PRD, task.md, changelog, and files.md workflow for Claude Code, Codex, Cursor, and OpenCode. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 82d1ce2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Avoid Feature Creep loads about 1.3k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 795 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from waynesutton/builder-skills at commit 82d1ce2, republished under its Apache-2.0 licence (© waynesutton). 795 words, ~1,312 tokens.
.claude/skills/avoid-feature-creep/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.The request sets the scope. Everything the diff contains should trace back to a sentence in the ask. Anything else is a suggestion, not a change.
Build what was asked. Not what would be nice, not what a senior engineer would also do, not what the codebase "should" have. If a line of the diff cannot be justified by the request, it does not belong in the diff.
This applies to product scope and to code scope. A PRD that grows past its problem statement has the same disease as a bug fix that ships with a refactor.
Stop when you notice any of these:
Each of these might be a good idea. None of them are in scope unless the user says so.
Suggestions heading, one line eachOut of scope with a one line reasonprds/ folder, append to the relevant PRD's Out of scope sectionSuggestions are cheap to write and free to ignore. Unrequested code costs review time, adds bugs, and blurs what the change was for.
Every feature request has a source: a PM, an exec, a user, a developer scratching an itch, or an AI coding agent. Treat them all the same way. Log the request, weigh it against the current scope, and defer it unless it solves the problem the work was started for.
AI agents are stakeholders now. They have opinions and they push. Common agent driven creep:
If you are the agent, catch yourself doing this and move it to the suggestions list. If you are working with an agent, state the scope at the start of the session and treat its extras like any other stakeholder ask.
Before adding anything, ask:
If the first answer is no, it goes in suggestions.
Request: "Add a deletedAt field to tasks and hide deleted tasks from the list query."
Before, the creeping version:
deletedAt to the schemaby_user_and_deleted indexlist to use the indexsoftDelete, restore, and purgeDeleted mutationslist to listActive and updated three call sitesshowDeleted argument "for the admin view later"After, the scoped version:
deletedAt: v.optional(v.number()) to the schemalist at it so deleted rows never loadSummary sent with the change:
Done: deletedAt field and list query now skips deleted tasks.
Suggestions
- A softDelete mutation to set deletedAt (nothing sets it yet)
- A restore mutation
- A cron to purge rows older than 30 days
- An admin flag on list to include deleted rowsTwo lines of diff answered the request. Four lines of suggestions preserved every idea. The user decides what happens next.
A PRD earns each section by pointing back to its problem statement. When a PRD grows:
Out of scope with one reason each.Suggestions in the summary or Out of scope in the PRD© waynesutton, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (assets) in skills/avoid-feature-creep of waynesutton/builder-skills.
Open the folder on GitHubat commit 82d1ce2
Avoid Feature Creep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Avoid Feature Creep this skillwaynesutton/builder-skills | 404 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Cm Refactorkingxiaozhe/cm-workflow | 104 | 1 repos | ~2.7k | Automated safety check: Pass | MIT | |
| Securability EngineeringOWASP/secure-agent-playbook | 187 | — | ~5.8k | Automated safety check: Pass | CC-BY-4.0 | |
| Grilling Ideasopsmill/infrahub | 531 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Create Specbastani-inc/atomic | 846 | — | ~9.5k | Automated safety check: Pass | MIT | |
| Experience Lwc Design Generateforcedotcom/sf-skills | 1.1k | — | ~4k | Automated safety check: Pass | Apache-2.0 |
kingxiaozhe/cm-workflow
用户明确要求“只整理结构,不改变行为”时使用。执行边界分流、行为判官、分批重构和独立审查;缺陷修复转交 cm-fix,新增或变化的业务行为转交 cm-prd。
OWASP/secure-agent-playbook
Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary…
opsmill/infrahub
Stress-tests a fuzzy or vague feature idea before any PRD, spec, or ticket is written.
bastani-inc/atomic
Create a detailed execution plan/spec/PRD for implementing features or refactors in a codebase, designed around the program's entrypoints, the doors that carry domain intent, by leveraging existing…
forcedotcom/sf-skills
A skill your agent uses when you need to create a brand new Lightning Web Component from a Figma design, a Product Requirements Document, or another design artifact — orchestrating the five-phase…
forcedotcom/sf-skills
A skill your agent uses to analyze a Salesforce Aura component bundle (.cmp, .app, .evt, .intf, Controller.js, Helper.js, Renderer.js) and produce a framework-agnostic migration blueprint (PRD.yaml…
waynesutton/builder-skills
Builds AI agents on the Convex agent component: threads, messages, tools that call queries and mutations, streaming, RAG with vector search, and workflows for multi step jobs.
waynesutton/builder-skills
Production patterns for Convex apps and the rules the @convex-dev/eslint-plugin enforces: validators, indexes, idempotent mutations, avoiding OCC conflicts, thin function wrappers, error handling.
waynesutton/builder-skills
Creates reusable Convex components with defineComponent, a clean client wrapper, their own schema, and an npm publish setup.
waynesutton/builder-skills
Schedules work in Convex: cron jobs in convex/crons.ts, one off scheduled functions with runAfter and runAt, batching large jobs, and cancelling or inspecting the queue.
waynesutton/builder-skills
Adds HTTP endpoints in convex/http.ts: webhook receivers with signature checks, REST style routes, CORS, auth headers, streaming responses, and file uploads over HTTP.
waynesutton/builder-skills
Changes a live Convex schema without downtime: make a field optional, backfill in batches, flip the validator, then clean up.
Categories
Keeps a change scoped to what was asked. An agent skill from waynesutton/builder-skills. Avoid Feature Creep is an agent skill from waynesutton/builder-skills. Keeps a change scoped to what was asked.
Avoid Feature Creep fits situations like: A request is small and the agent is about to expand it; A PRD grows beyond its problem statement; the user says just do what I asked.
Run `npx skills add waynesutton/builder-skills --skill avoid-feature-creep -a claude-code`. Or copy the skill folder (skills/avoid-feature-creep in waynesutton/builder-skills) into .claude/skills/avoid-feature-creep in your project. Claude Code loads it when a task matches its description.
Run `npx skills add waynesutton/builder-skills --skill avoid-feature-creep -a codex`. Or copy the skill folder (skills/avoid-feature-creep in waynesutton/builder-skills) into .agents/skills/avoid-feature-creep in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add waynesutton/builder-skills --skill avoid-feature-creep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/avoid-feature-creep, .gemini/skills/avoid-feature-creep, .github/skills/avoid-feature-creep and .opencode/skills/avoid-feature-creep in your project.
SKILL.md names no scripts, command-line tools or credentials: Avoid Feature Creep is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Avoid Feature Creep is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Avoid Feature Creep: Cm Refactor (kingxiaozhe/cm-workflow, 104 stars), Securability Engineering (OWASP/secure-agent-playbook, 187 stars), Grilling Ideas (opsmill/infrahub, 531 stars) and Create Spec (bastani-inc/atomic, 846 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
waynesutton (a GitHub user) maintains it in waynesutton/builder-skills, which has 404 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 28, 2026.
Source: waynesutton/builder-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.