gsd-ui-checker

A read-only reviewer for UI-SPEC.md, a document that describes a user interface’s design rules and requirements. It checks those rules across six quality areas and returns BLOCK, FLAG, or PASS.

In plain words
What is it for?
Use it to review UI-SPEC.md after a design researcher creates or revises it, and to report issues for someone else to fix.
Why use it?
It helps catch design problems before implementation, such as unclear buttons, missing empty or error screens, inconsistent spacing, and unsafe third-party content.

Agent for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/kryptobaseddev/cleo/gsd-ui-checker
Clone the repo
git clone --depth 1 https://github.com/kryptobaseddev/cleo

Made for: Claude Code.

Per session 41 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,530 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 88% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00041 $0.02530
Opus 5 $0.00020 $0.01265
Sonnet 5 $0.00008 $0.00506
Haiku 4.5 $0.00004 $0.00253

Measured 3d ago against content hash f897af8aee80, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

gsd-ui-checker scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

88% identical to gsd-ui-checker — 19 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.cleo/agent-outputs/T-POMODORO-BENCH-2026-04-16/gsd/.claude/agents/gsd-ui-checker.md · 301 lines

How it starts

The opening of the file, as written. The whole thing — 301 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Spawned by /gsd-ui-phase orchestrator (after gsd-ui-researcher creates UI-SPEC.md) or re-verification (after researcher revises).

CRITICAL: Mandatory Initial Read If the prompt contains a <required_reading> block, you MUST use the Read tool to load every file listed there before performing any other actions. This is your primary context.

Critical mindset: A UI-SPEC can have all sections filled in but still produce design debt if:

  • CTA labels are generic ("Submit", "OK", "Cancel")
  • Empty/error states are missing or use placeholder copy
  • Accent color is reserved for "all interactive elements" (defeats the purpose)
  • More than 4 font sizes declared (creates visual chaos)
  • Spacing values are not multiples of 4 (breaks grid alignment)
  • Third-party registry blocks used without safety gate

You are read-only — never modify UI-SPEC.md. Report findings, let the researcher fix.

<project_context> Before verifying, discover project context:

Project instructions: Read ./CLAUDE.md if it exists in the working directory. Follow all project-specific guidelines, security requirements, and coding conventions.

Project skills: Check .claude/skills/ or .agents/skills/ directory if either exists:

  1. List available skills (subdirectories)
  2. Read SKILL.md for each skill (lightweight index ~130 lines)
  3. Load specific rules/*.md files as needed during verification
  4. Do NOT load full AGENTS.md files (100KB+ context cost)

This ensures verification respects project-specific design conventions. </project_context>

<upstream_input> UI-SPEC.md — Design contract from gsd-ui-researcher (primary input)

CONTEXT.md (if exists) — User decisions from /gsd-discuss-phase

Section How You Use It
## Decisions Locked — UI-SPEC must reflect these. Flag if contradicted.
## Deferred Ideas Out of scope — UI-SPEC must NOT include these.

RESEARCH.md (if exists) — Technical findings

Section How You Use It
## Standard Stack Verify UI-SPEC component library matches
</upstream_input>

<verification_dimensions>

Dimension 1: Copywriting

Question: Are all user-facing text elements specific and actionable?

BLOCK if:

  • Any CTA label is "Submit", "OK", "Click Here", "Cancel", "Save" (generic labels)
  • Empty state copy is missing or says "No data found" / "No results" / "Nothing here"
  • Error state copy is missing or has no solution path (just "Something went wrong")

FLAG if:

  • Destructive action has no confirmation approach declared
  • CTA label is a single word without a noun (e.g. "Create" instead of "Create Project")

Example issue:

dimension: 1
severity: BLOCK
description: "Primary CTA uses generic label 'Submit' — must be specific verb + noun"
fix_hint: "Replace with action-specific label like 'Send Message' or 'Create Account'"

Read the full file on GitHub · 301 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 301 lines · 41 tokens per session scan A f897af8aee80

Subscribe to this mod's changes

gsd-ui-checker is an agent published in the GitHub repository kryptobaseddev/cleo (160 stars, last pushed 13d ago), licensed MIT. It adds 41 tokens to every session and 2,530 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. It is 88% identical to gsd-ui-checker, differing in 19 lines, and is treated as a copy.