Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/loiane/specs-driven-development-spring-angular/validategit clone --depth 1 https://github.com/loiane/specs-driven-development-spring-angularWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00018 | $0.00639 |
| Opus 5 | $0.00009 | $0.00319 |
| Sonnet 5 | $0.00004 | $0.00128 |
| Haiku 4.5 | $0.00002 | $0.00064 |
Grade A, and why
validate scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 52 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/validate
Phase: 5 — validate (run the harness)
Owning agent: .claude/agents/spring-validator.md
Skills used: harness-report-parsing, jacoco-coverage-policy, pit-mutation-tuning, requirements-traceability, archunit-rules
Stack routing
| Changed source | Agent |
|---|---|
| Java/Kotlin only | spring-validator (this agent) |
Angular (.ts, .html, .scss) only |
angular-validator |
| Both | Run both validators; merge results into a single 07-validation-report.md |
Determine scope from 04-tasks.md file lists or git diff --name-only. If only frontend files changed, delegate entirely to angular-validator.
Purpose
Run the full 10-layer harness, parse the output, and write 07-validation-report.md with a single PASS / FAIL verdict.
Inputs
<feature-id>(optional; if omitted, reports across all changes sinceorigin/main).
Reads
.github/scripts/harness.sh,.github/scripts/check-new-code-coverage.sh,.github/scripts/traceability.sh.target/harness-summary.json(after the run).01-spec.md,04-tasks.md,06-test-plan.md(for AC mapping).
Writes
.specs/<feature-id>/07-validation-report.md.specs/<feature-id>/07a-traceability.md(regenerated)target/harness-summary.json,target/new-code-coverage.json
Process
- Run
.github/scripts/harness.sh --report > /dev/null(writestarget/harness-summary.json). - Run
.github/scripts/check-new-code-coverage.sh(must be ≥ 95% on changed lines). - Run
.github/scripts/traceability.sh <feature-id>. Any AC with zero tests = FAIL. - Aggregate the 10 gates plus the new-code-coverage and traceability checks. Verdict is
PASSonly if every gate ispass(mutation may bewarnif explicitly justified in the report). - Write
07-validation-report.mdwith: verdict, gate table, top failing items, links to artifacts, recommended next action.
Refuse if
04-tasks.mdshows any task notdone.- The harness was bypassed (e.g. local cache showed stale results) — always re-run.
forbid-skip-flags.shwould have blocked the underlying Maven invocation.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 52 lines · 18 tokens per session scan A 12564d4fdb23
validate is a command published in the GitHub repository loiane/specs-driven-development-spring-angular (57 stars, last pushed 2mo ago), licensed MIT. It adds 18 tokens to every session and 639 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
spec-kitty.analyze
Spec-Driven Development for serious software developers. Spec Coding with with Claude, Cursor, Gemini, Codex. Kanban dashboard, git worktrees, auto-merge and more.
devkit.github.review-pr
Provides comprehensive GitHub pull request review with code quality, security, and best practices analysis. Use when reviewing a PR before merging.
devkit.prompt-optimize
Provides expert prompt optimization using advanced techniques (CoT, few-shot, constitutional AI) for LLM performance enhancement. Use when you need to improve prompt quality or optimize LLM interactions.
sdd-plan
Turn a spec into a persisted baby-step plan file — research, resume, impact analysis.
sdd-architecture-update
Detect architecture drift and sync the snapshot + Memory Bank (with confirmation).
sdd-clarify
Adversarial pass over a finished spec — contradictions, ambiguity, untestable criteria, implementation posing as intent, missing failure modes.