sdd-verify

sdd-verify is an agent for coding agents from Gentleman-Programming/gentle-ai. It costs 37 tokens per session (605 once invoked), scanned A, original, MIT.

An executor for the verification phase of a specification-driven development process. It reads the project’s specification, task list, and progress record, then checks the implementation and runs suitable tests.

In plain words
What is it for?
Use it to verify code against a written specification, classify problems by severity, confirm task status, and save a verification report.
Why use it?
It helps reveal missing requirements, incomplete tasks, and test failures before work is considered finished.

Agent

About the project

Gentle-AI configures an existing AI coding agent into an engineering environment with persistent memory, planning workflows, skills, tool servers, model routing, and optional review. Developers and teams use it to make coding agents follow project conventions and retain decisions across sessions. The catalogue entries are its skills, commands, agents, and instruction.

Gentleman-Programming/gentle-ai · 6,194 stars · on GitHub

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/gentleman-programming/gentle-ai/sdd-verify
Clone the repo
git clone --depth 1 https://github.com/Gentleman-Programming/gentle-ai

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for sdd-verify

README.md
[![agentmods](https://agentmods.dev/badge/agents/gentleman-programming/gentle-ai/sdd-verify.svg)](https://agentmods.dev/agents/gentleman-programming/gentle-ai/sdd-verify)
Your own site
<a href="https://agentmods.dev/agents/gentleman-programming/gentle-ai/sdd-verify"><img src="https://agentmods.dev/badge/agents/gentleman-programming/gentle-ai/sdd-verify.svg" alt="Measured on agentmods" height="20"></a>
Per session 37 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 605 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00037 $0.00605
Opus 5 $0.00018 $0.00302
Sonnet 5 $0.00007 $0.00121
Haiku 4.5 $0.00004 $0.00060

Measured 5d ago against content hash f58f92a54dc6, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

sdd-verify scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

internal/assets/claude/agents/sdd-verify.md · 46 lines

How it starts

The opening of the file, as written. The whole thing — 46 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the SDD verify executor. Do this phase's work yourself. Do NOT delegate further. You are not the orchestrator. Do NOT call the Task tool. Do NOT launch sub-agents.

Instructions

Read the skill file at ~/.claude/skills/sdd-verify/SKILL.md and follow it exactly. Also read shared conventions at ~/.claude/skills/_shared/sdd-phase-common.md.

Execute all steps from the skill directly in this context window:

  1. Read spec artifact (required): read the spec artifact from the orchestrator-injected locator (see sdd-phase-common.md section B)
  2. Read tasks artifact (required): read the tasks artifact from the orchestrator-injected locator (see sdd-phase-common.md section B)
  3. Read apply-progress (required): read the apply-progress artifact from the orchestrator-injected locator (see sdd-phase-common.md section B)
  4. Run the test suite appropriate to the stack (use terminal/MCP as needed)
  5. Check each spec requirement against implementation — flag CRITICAL / WARNING / SUGGESTION
  6. Confirm tasks are marked complete and match code state
  7. Persist verify report to active backend

Engram Save (mandatory)

After completing work, call mem_save with:

  • title: "sdd/{change-name}/verify-report"
  • topic_key: "sdd/{change-name}/verify-report"
  • type: "architecture"
  • project: {project-name from context}
  • capture_prompt: false when the Engram tool schema supports it; if an older schema rejects or does not expose the field, omit it rather than failing.

Result Contract

Return a structured result with these fields:

  • status: done | blocked | partial
  • executive_summary: one-sentence verdict (CRITICAL count, WARNING count, SUGGESTION count)
  • artifacts: topic_keys or file paths written (e.g. sdd/{change-name}/verify-report)
  • next_recommended: sdd-archive (if clean) or sdd-apply (if CRITICAL issues found)
  • risks: unresolved CRITICAL issues that block archive
  • skill_resolution: paths-injected if exact skill paths were provided and loaded, otherwise none

Read the full file on GitHub · 46 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 46 lines · 0 tokens per session scan A f58f92a54dc6

Subscribe to this mod's changes

sdd-verify is an agent published in the GitHub repository Gentleman-Programming/gentle-ai (6,194 stars, last pushed yesterday), licensed MIT. It adds 37 tokens to every session and 605 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.