Borrowing it
Nothing to install: this file belongs to HazelnutParadise/insyra. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/HazelnutParadise/insyra/main/.github/prompts/opsx-verify.prompt.mdgit clone --depth 1 https://github.com/HazelnutParadise/insyraWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/hazelnutparadise/insyra/opsx-verify)<a href="https://agentmods.dev/commands/hazelnutparadise/insyra/opsx-verify"><img src="https://agentmods.dev/badge/commands/hazelnutparadise/insyra/opsx-verify.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00008 | $0.01560 |
| Opus 5 | $0.00004 | $0.00780 |
| Sonnet 5 | $0.00002 | $0.00312 |
| Haiku 4.5 | $0.00001 | $0.00156 |
Grade A, and why
opsx-verify scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
73% identical to OPSX: Verify — 16 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 165 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Verify that an implementation matches the change artifacts (specs, tasks, design).
Store selection: If the user names a store (a store is a standalone OpenSpec repo registered on this machine) or the work lives in one, run openspec store list --json to discover registered store ids, then pass --store <id> on the commands that read or write specs and changes (new change, status, instructions, list, show, validate, archive, doctor, context). Other commands do not take the flag. Hints printed by commands already carry the flag; keep it on follow-ups. Without a store, commands act on the nearest local openspec/ root.
Input: Optionally specify a change name after /opsx:verify (e.g., /opsx:verify add-auth). If omitted, check if it can be inferred from conversation context. If vague or ambiguous you MUST prompt for available changes.
Steps
-
If no change name provided, prompt for selection
Run
openspec list --jsonto get available changes. Use the AskUserQuestion tool to let the user select.Show changes that have implementation tasks (tasks artifact exists). Include the schema used for each change if available. Mark changes with incomplete tasks as "(In Progress)".
IMPORTANT: Do NOT guess or auto-select a change. Always let the user choose.
-
Check status to understand the schema
openspec status --change "<name>" --jsonParse the JSON to understand:
schemaName: The workflow being used (e.g., "spec-driven")planningHome,changeRoot,artifactPaths, andactionContext: path and scope context- Which artifacts exist for this change
-
Get planning context and load artifacts
openspec instructions apply --change "<name>" --jsonThis returns the change directory and
contextFiles(artifact ID -> array of concrete file paths). Read all available artifacts fromcontextFiles. -
Initialize verification report structure
Create a report structure with three dimensions:
- Completeness: Track tasks and spec coverage
- Correctness: Track requirement implementation and scenario coverage
- Coherence: Track design adherence and pattern consistency
Each dimension can have CRITICAL, WARNING, or SUGGESTION issues.
-
Verify Completeness
Task Completion:
- If
contextFiles.tasksexists, read every file path in it - Parse checkboxes:
- [ ](incomplete) vs- [x](complete) - Count complete vs total tasks
- If incomplete tasks exist:
- Add CRITICAL issue for each incomplete task
- Recommendation: "Complete task: " or "Mark as done if already implemented"
Spec Coverage:
- If delta specs exist in
contextFiles.specs:- Extract all requirements (marked with "### Requirement:")
- For each requirement:
- Search codebase for keywords related to the requirement
- Assess if implementation likely exists
- If requirements appear unimplemented:
- Add CRITICAL issue: "Requirement not found: "
- Recommendation: "Implement requirement X: "
- If
-
Verify Correctness
Requirement Implementation Mapping:
- For each requirement from delta specs:
- Search codebase for implementation evidence
- If found, note file paths and line ranges
- Assess if implementation matches requirement intent
- If divergence detected:
- Add WARNING: "Implementation may diverge from spec: "
- Recommendation: "Review : against requirement X"
Scenario Coverage:
- For each scenario in delta specs (marked with "#### Scenario:"):
- Check if conditions are handled in code
- Check if tests exist covering the scenario
- If scenario appears uncovered:
- Add WARNING: "Scenario not covered: "
- Recommendation: "Add test or implementation for scenario: "
- For each requirement from delta specs:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 165 lines · 8 tokens per session scan A 2f4d02a48844
opsx-verify is a command published in the GitHub repository HazelnutParadise/insyra (56 stars, last pushed today), licensed MIT. It adds 8 tokens to every session and 1,560 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. It is 73% identical to OPSX: Verify, differing in 16 lines, and is treated as a copy.
Other commands, from other repositories
Icon Programming Review
Intelligent programming analysis that automatically selects the right legendary programmers for your code and architecture problems.
gh-triage
GitHub OSS maintainer lifecycle triage, review, and approval management.
execute-parallel-status
Show live status table of all /ai-sdlc execute-parallel sessions. Reads .ai-sdlc/dispatch/sessions/ and renders task | pane | status | step | PR | heartbeat-age columns. AISDLC-462.
discover
Run a full product discovery cycle — from outcome definition through opportunity mapping, prioritisation, and experiment design. Use when the team isn't sure what to build next, or before writing a PRD for a complex feature space.
status
The state of play, computed fresh: branch, dirty files, the active sprint, open work, index freshness.
review
Review current changes for correctness, style, and potential issues.