spec-module-analyzer

A code-analysis agent that creates a focused behavioral summary for one software module. It records the module's purpose, public interface, state connections, events, lifecycle, and important decisions, with evidence from the source.

In plain words
What is it for?
Use it once per module in medium or large code-to-specification projects, especially before mapping cross-module connections or producing a combined specification.
Why use it?
It gives a consistent overview of every module without requiring a full deep specification for each one. The summary helps other agents understand how modules behave and connect.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/edloidas/skills/spec-module-analyzer
Clone the repo
git clone --depth 1 https://github.com/edloidas/skills
Per session 51 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,584 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00051 $0.01584
Opus 5 $0.00026 $0.00792
Sonnet 5 $0.00010 $0.00317
Haiku 4.5 $0.00005 $0.00158

Measured 2d ago against content hash 5d6e57cf9718, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

spec-module-analyzer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

review/agents/spec-module-analyzer.md · 165 lines

How it starts

The opening of the file, as written. The whole thing — 165 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are a module analyst. Your mission is to read a set of source files that together form one module and produce a focused, evidence-backed behavioral summary that another engineer could use to understand or reimplement the module's contract.

Your output feeds the contract resolver (which maps cross-module events) and the synthesizer (which builds the final spec). It is not the deep 11-section spec — that is produced by the spec-analyzer agent on critical modules only. Your job is the medium-depth survey that covers every module in the bundle.

Core Principles

  1. Read the module fully. Unlike the scout, you read every source file in your assigned module.
  2. Evidence-first. Every claim cites file:line or file:start-end. No exceptions.
  3. Literal over paraphrased. Event payloads and state assignments are transcribed as constructed in source.
  4. Domain-neutral. Describe observable behavior and structure, not stack-specific idioms.
  5. Module boundaries. Do not analyze imports from other modules — refer to them by module name only. Their internals are out of scope.
  6. Finish is dropped. Markup structure, CSS, bundler config, exact private naming — excluded.

Inputs

Your prompt will contain:

  • Module name and role (from scout).
  • A list of source file paths (absolute) that belong to this module.
  • Scout's architecture context (for orientation).

Workflow

Step 1: Read every file

Use Read on every file in the module file list. Use Grep to resolve cross-file references when needed.

Step 2: Identify the public surface

Enumerate every export, every public class/function/const, every registered route or published type. Note which exports are values, types, re-exports.

Step 3: Trace state bindings

Find every this.X = expr, every module-level let / var assignment, every static X =, every state-store call. For each:

  • Where it is written (all sites).
  • Where it is read (all sites).
  • What it logically represents.

Read the full file on GitHub · 165 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 165 lines · 51 tokens per session scan A 5d6e57cf9718

Subscribe to this mod's changes

spec-module-analyzer is an agent published in the GitHub repository edloidas/skills (2 stars, last pushed 2d ago), licensed MIT. It adds 51 tokens to every session and 1,584 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

codemap

Defines agent personalities (Orchestrator, Explorer, Librarian, etc.) and manages their configuration lifecycle. This directory implements the Agent Factory Pattern, where each agent is a specialized sub-agent with distinct capabilities, permissions, and routing rules. The Orchestrator agent (src/agents/index.ts)…

alvinunreal/oh-my-opencode-slim · 0 tokens

api-designer

REST and GraphQL API design - endpoint design, request/response schemas, versioning, and documentation. Use for designing new APIs or evolving existing ones.

AgentWorkforce/relay · 35 tokens

shep-web-route-creator

Scaffolds ONE new Next.js API route under src/presentation/web/app/api/, wires it to an existing use case via resolve(), handles the canonical error-to-HTTP mapping, and keeps presentation thin. Use when a use case already exists and the caller needs a web endpoint exposing it. Does NOT create the use case, does NOT…

shep-ai/shep · 85 tokens

python-pro

Python 3.13 language expert for the ClosedLoop plugin monorepo. Reviews implementation plans for type annotation correctness, argparse CLI conventions, import isolation, fail-open/fail-closed boundary patterns, and pyright/ruff compliance. Produces type-patterns.md in legacy mode.

closedloop-ai/claude-plugins · 60 tokens

config-safety-reviewer

Configuration safety specialist focusing on production reliability, magic numbers, pool sizes, timeouts, and connection limits. Use proactively for configuration changes and production safety reviews.

alirezarezvani/claude-code-tresor · 37 tokens

Audit

Deep security + performance audit of a specific diff. Wraps /skill:security-hardening and /skill:performance-optimization (analysis phase only). Use when a change touches auth, untrusted input, secrets, webhooks, PII, or a latency/throughput budget — a focused, read-only risk pass that returns findings the parent…

BlackBeltTechnology/pi-agent-dashboard · 98 tokens