Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/dshakes/compass/specgit clone --depth 1 https://github.com/dshakes/compassWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00044 | $0.00661 |
| Opus 5 | $0.00022 | $0.00331 |
| Sonnet 5 | $0.00009 | $0.00132 |
| Haiku 4.5 | $0.00004 | $0.00066 |
Grade A, and why
spec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 40 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Draft a spec / intent for: ${ARGUMENTS:-the task we're about to do}.
The point: give the loop a ground truth. Tests prove the code works; the spec proves it does what was asked. The Builder implements against it; the Reviewer and QA verify against its acceptance criteria. Keep it short and honest — a spec that rots is worse than none.
Do
- Read the relevant code,
CLAUDE.md, and any linked issue first (don't spec in a vacuum). - Write
specs/<kebab-slug>.mdwith exactly these sections, tight:- Intent — 1–3 sentences: what outcome, for whom, why now.
- Acceptance criteria — a numbered, verifiable checklist (each item testable; prefer "given/when/then" where it helps). This is the contract.
- Non-goals — what this explicitly does NOT do (prevents scope creep).
- Constraints / invariants — perf, security/tenancy, back-compat, dependencies.
- Verification plan — how each acceptance criterion will be checked (test, manual, metric).
- Open questions — anything needing a human decision before/while building.
- If a load-bearing invariant changes, say "needs ADR" and stop short (use
/adr). - Keep it under ~1 page. Commit it (
git add specs/… && git commit). Report the path.
Then (spec-driven loop)
Hand the spec to implementation: ~/compass/sdlc/orchestrate.sh "<task>" with
SDLC_SPEC=specs/<slug>.md set — the Planner plans to the spec, the Builder implements it,
and the Reviewer is told to verify the diff against the acceptance criteria (flag any
unmet or out-of-scope). The human approves the spec (intent), not just the diff.
End to end (cloud loop too): commit the spec in the same PR (it lives under specs/),
or add a Spec: specs/<slug>.md line to the PR description. The GitHub Reviewer
(sdlc-review.yml) detects the spec, verifies the diff against its Acceptance Criteria, and
marks unmet criteria or out-of-scope changes as Blocking — so the auto-fix loop converges on
intent, not just "tests pass." Same human merge gate.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 40 lines · 44 tokens per session scan A a603ce512696
spec is a command published in the GitHub repository dshakes/compass (19 stars, last pushed 8d ago), licensed MIT. It adds 44 tokens to every session and 661 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
checklist
Generate a custom checklist for the current feature based on user requirements.
clarify
Identify underspecified areas in the current feature spec by asking up to 5 highly targeted clarification questions and encoding answers back into the spec.
specify
Create or update the feature specification from a natural language feature description.
analyze
Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.
converge
Assess the current codebase against the feature's spec, plan, and tasks, then append any remaining unbuilt work as new tasks to tasks.md so implement can complete it.
implement
Execute the implementation plan by processing and executing all tasks defined in tasks.md.