Stage 1 of 7 · Command: /project:research · Artifacts: docs/research-brief.md + docs/research.md
Ground the idea in options, prior art, and risks. Runs in three parts: grill for a research brief (gated on Craig's sign-off) → execute the research → publish to Notion.
What this stage produces
docs/research-brief.md — Objective · Key questions to answer · Constraints · Exit criteria · Out of scope. Craig must approve this before any research begins.
docs/research.md — anchored to the brief's key questions:
- Two or three viable technical approaches with tradeoffs (complexity, maintenance, performance, stack fit).
- Existing libraries/services that already solve part of this, each with last-release/maintenance status.
- Top 5 risks or unknowns, ranked, and what would de-risk each.
- What's needed from Craig to make a recommendation.
- 3–5 open questions, also asked in chat.
{RESEARCH} items carried over from docs/prep-n-research.md
These are the reason this stage exists. The labels produced by flabel become ML training ground truth, so verdict trustworthiness is the dominant quality requirement. Every ruleset and feed selected needs written justification recorded in docs/research.md.
Content/inline detection sources
Encrypted traffic (JA3/JA4)
Cross-cutting
Exit criteria
- Craig signed off on
docs/research-brief.md.
- Every
{RESEARCH} checkbox above is answered or explicitly deferred with a reason.
- Every selected ruleset/feed has a cited justification.
- Sources cited; uncertainty flagged rather than guessed.
- Findings published to the Notion tracker row;
current_stage advanced to prd.
Stage 1 of 7 · Command:
/project:research· Artifacts:docs/research-brief.md+docs/research.mdGround the idea in options, prior art, and risks. Runs in three parts: grill for a research brief (gated on Craig's sign-off) → execute the research → publish to Notion.
What this stage produces
docs/research-brief.md— Objective · Key questions to answer · Constraints · Exit criteria · Out of scope. Craig must approve this before any research begins.docs/research.md— anchored to the brief's key questions:{RESEARCH}items carried over fromdocs/prep-n-research.mdThese are the reason this stage exists. The labels produced by flabel become ML training ground truth, so verdict trustworthiness is the dominant quality requirement. Every ruleset and feed selected needs written justification recorded in
docs/research.md.Content/inline detection sources
Encrypted traffic (JA3/JA4)
labels.jsonschema and how usable the labels are for training.Cross-cutting
Exit criteria
docs/research-brief.md.{RESEARCH}checkbox above is answered or explicitly deferred with a reason.current_stageadvanced toprd.