project-sizing-guide skill
Software project effort estimation assistant. Outputs three-point estimates (optimistic/most-likely/pessimistic values with confidence intervals), T-shirt sizes, or Function Point Analysis (FPA) counts. Triggered when users ask 'how long will this feature take,' need to assess project workload, perform PERT estimation, T-shirt sizing, FPA, sprint planning, or quote-based effort breakdowns.
Is the project-sizing-guide skill safe?
Clean: nothing in its files matched our rules. We read 3 files in the folder on 2026-09-28.
No findings.
Install the project-sizing-guide skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/zebbern/claude-code-guide.git /tmp/claude-code-guide mkdir -p ~/.claude/skills cp -r /tmp/claude-code-guide/skills/project-sizing-guide ~/.claude/skills/project-sizing-guide
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Project Sizing Guide — Software Project Effort Estimation
Helps teams produce scientifically grounded effort estimates for software projects, based on three major methodologies: Three-Point Estimation (PERT), T-shirt Sizing, and Function Point Analysis (FPA). Outputs optimistic, most-likely, and pessimistic values along with risk intervals.
Quick Start
- User provides a requirements description → Agent identifies functional modules and breaks them into a Work Breakdown Structure (WBS)
- Select an estimation method → Choose the best-fit approach based on project stage and available information
- Estimate each item → Assign O/M/P (Optimistic / Most Likely / Pessimistic) values to every work package
- Aggregate and report → Generate an estimation report with risk analysis and confidence intervals
A calculation helper is available:
python3 scripts/estimate_calculator.py --method pert --tasks '[{"name":"User Login","O":2,"M":3,"P":8}]'Method Selection Guide
Method 1: Three-Point Estimation (PERT)
Core Formulas
Where:
- O (Optimistic): Shortest duration assuming everything goes smoothly
- M (Most Likely): Duration under normal circumstances
- P (Pessimistic): Longest duration when significant difficulties arise
Confidence Intervals
Steps
- Build the WBS: Decompose requirements into the smallest independently estimable units (recommended ≤ 5 person-days each)
- Three-point estimation: For each work package, provide O / M / P values (use consistent units: person-hours or person-days)
- Calculate per-task expected value and standard deviation
- Aggregate project-level metrics: Total Expected = ΣE, Total Std Dev = √(Σσ²)
- Output confidence intervals: Choose a confidence level based on risk appetite
O/M/P Estimation Rules of Thumb
- O should not be less than 30% of M (overly optimistic suggests essential steps were overlooked)
- P should not exceed 5× M (overly pessimistic suggests unclear requirements that need clarification first)
- If O ≈ M ≈ P, the task is either extremely well-understood or the estimator hasn't seriously considered risks
- The P/O ratio (spread ratio) reflects uncertainty: < 2 = low risk, 2–4 = medium risk, > 4 = high risk
Method 2: T-shirt Sizing
Size Reference Table
Converting T-shirt Sizes to Three-Point Estimates
When more precise numbers are needed, T-shirt sizes can be converted to three-point estimates:
Steps
- Team alignment: Confirm what each size means (the table above is a reference; teams may customize)
- Independent assessment: Each person assigns a size independently to avoid anchoring bias
- Discuss discrepancies: When estimates differ by more than 2 sizes, a discussion is mandatory
- Reach consensus: Adopt the team consensus value
- Convert to numbers (optional): Use the table above to derive O/M/P values
Method 3: Function Point Analysis (FPA)
Five Function Component Types
Complexity Weight Matrix
Complexity Assessment Rules
ILF / EIF Complexity (based on DET – Data Element Types and RET – Record Element Types):
EI Complexity (based on DET and FTR – File Types Referenced):
EO / EQ Complexity (based on DET and FTR):
Converting Function Points to Effort
After calculating Unadjusted Function Points (UFP):
- Calculate the Value Adjustment Factor (VAF) (optional; deprecated since IFPUG 4.3+ but still used by some teams)
- 14 General System Characteristics (GSC), each scored 0–5
- VAF = 0.65 + 0.01 × Σ(GSC)
- Adjusted Function Points AFP = UFP × VAF
- Function points to person-hours
- Industry benchmark: 8–15 person-hours per function point (varies by language and team maturity)
Steps
- Identify function components: List all ILFs, EIFs, EIs, EOs, and EQs
- Assess complexity: Rate each component as Low / Medium / High
- Calculate UFP: Sum (count × weight) for all components
- Select conversion factor: Choose person-hours per FP based on technology stack
- Compute total effort: UFP × conversion factor
- Add buffer: A 15–30% management and risk buffer is recommended
Estimation Adjustment Factor Checklist
After completing the estimation, verify that the following factors have been accounted for:
Technical Factors
- [ ] Technology stack familiarity (Is the team experienced? If unfamiliar, add 30–50%)
- [ ] Technical debt (Poor legacy code quality? Add 20–40%)
- [ ] Third-party dependencies (Unstable APIs? Missing documentation? Add 10–30%)
- [ ] Performance / security requirements (Special non-functional requirements? Add 15–25%)
Team Factors
- [ ] Team size (Communication overhead increases significantly above 5 people; add ~5% per person)
- [ ] Personnel turnover risk (Key members may leave? Add 15–25%)
- [ ] Parallel projects (Team context-switching across multiple projects? Add 20–30%)
- [ ] Onboarding new members (New hires? Expect ~50% reduced efficiency for the first 2 weeks)
Process Factors
- [ ] Requirements stability (Requirements likely to change? Add 20–50%)
- [ ] Approval processes (Multiple layers of approval needed? Add 10–20%)
- [ ] Deployment complexity (Multi-environment, multi-region deployments? Add 10–15%)
- [ ] Compliance requirements (Audit or compliance processes? Add 15–30%)
Commonly Underestimated Work
- [ ] Code review: +10–15%
- [ ] Unit test authoring: +15–25%
- [ ] Integration / E2E testing: +10–20%
- [ ] Documentation: +5–15%
- [ ] Bug fixing and regression: +10–20%
- [ ] Environment setup and DevOps: +5–10%
- [ ] Meetings and communication: +10–15%
Estimation Output Template
After the Agent completes the estimation, it should produce output in the following format:
## Estimation Report: [Project / Feature Name]
### Estimation Method: [PERT / T-shirt / FPA]
### Work Package Breakdown
| # | Work Package | O (person-days) | M (person-days) | P (person-days) | E (person-days) | σ |
|---|-------------|-----------------|-----------------|-----------------|-----------------|---|
| 1 | xxx | x | x | x | x.x | x.x |
| 2 | xxx | x | x | x | x.x | x.x |
### Summary
- Total expected effort: X person-days
- Total standard deviation: X person-days
- 68% confidence interval: X – X person-days
- 90% confidence interval: X – X person-days
- 95% confidence interval: X – X person-days
### Adjustment Factors
- [Factors considered and adjustments applied]
### Final Recommendation
- For internal planning: X person-days (90% confidence)
- For external quotes: X person-days (95% confidence)
### Risk Alerts
- [Key risk items and mitigation suggestions]Calculation Tool
The scripts/estimate_calculator.py script supports numerical calculations for all three estimation methods:
# Three-Point Estimation (PERT)
python3 scripts/estimate_calculator.py --method pert \
--tasks '[{"name":"Login Module","O":2,"M":3,"P":8},{"name":"Payment Module","O":5,"M":10,"P":20}]'
# T-shirt Size Conversion
python3 scripts/estimate_calculator.py --method tshirt \
--tasks '[{"name":"Login Module","size":"M"},{"name":"Payment Module","size":"L"}]'
# Function Point Analysis
python3 scripts/estimate_calculator.py --method fpa \
--components '[{"type":"ILF","complexity":"medium","count":3},{"type":"EI","complexity":"low","count":5}]' \
--hours-per-fp 10References
- IFPUG (International Function Point Users Group) CPM 4.3.1
- PMI PMBOK Guide — 6th Edition, Section 6.4: Estimate Activity Durations
- Steve McConnell, Software Estimation: Demystifying the Black Art
- Mike Cohn, Agile Estimating and Planning
More skills from zebbern/claude-code-guide
- Aacademic-paper-reviewerSimulates academic peer review, evaluating papers across Originality, Methodology, Results, and Writing to provide Major/Minor Revision recommendations with actionable feedback. Triggers when a user asks to \"review my paper,\" \"simulate peer review,\" or \"give my paper a peer review.
- Aactive-directory-attacksThis skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", "Silver Ticket", "AS-REP roasting", "NTLM relay", or needs guidance on Windows domain penetration testing.
- Capi-fuzzing-bug-bountyThis skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
- Aapi-shape-explorerGenerate multiple radically different interface designs for a module using parallel sub-agents. Use when user wants to design an API, explore interface options, compare module shapes, or mentions "design it twice".
- Aaudit-flowInteractive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on audit, trace flow, document flow, security review, debug flow, brainstorm, architecture review, post-mortem, incident review.
- Aauthentication-patternsAuthentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.
- Aaws-penetration-testingThis skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.
- Abroken-authenticationThis skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password policies", "test for session fixation", or "identify authentication bypass flaws". It provides comprehensive techniques for identifying authentication and session management weaknesses in web applications.
- Cburp-suite-testingThis skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using Burp Suite's core features for web application security testing.
- AcachingCaching strategies — invalidation, TTL guidelines, cache keys, cache layers, and when not to cache. Use when implementing or reviewing caching logic.
- Achart-imageGenerate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts. Triggers when the user asks to visualize data, create a graph, plot a time series, or generate a chart for a report, alert, or dashboard. Runs as a lightweight, headless Node.js process without a browser.
- Dcloud-penetration-testingThis skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud resources", "exploit cloud misconfigurations", "test O365 security", "extract secrets from cloud environments", or "audit cloud infrastructure". It provides comprehensive techniques for security assessment across major cloud platforms.