sdd-requirements

A command for writing feature requirements in EARS format, a structured way to describe when software should behave in a certain way. It uses project files and, when needed, questions for details about users, goals, workflows, and constraints.

In plain words
What is it for?
Use it to specify features such as authentication, payment processing, or a user dashboard, including functional requirements, constraints, and acceptance criteria.
Why use it?
It turns an unclear feature idea into a specification that developers can implement and test. It also keeps the requirements aligned with the project's architecture and technology choices.

Command for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/nahisaho/codegraphmcpserver/sdd-requirements
Clone the repo
git clone --depth 1 https://github.com/nahisaho/CodeGraphMCPServer

Made for: Claude Code.

Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,650 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.02650
Opus 5 $0.00000 $0.01325
Sonnet 5 $0.00000 $0.00530
Haiku 4.5 $0.00000 $0.00265

Measured 2d ago against content hash c2aab2b9048f, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

sdd-requirements scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/commands/sdd-requirements.md · 490 lines

How it starts

The opening of the file, as written. The whole thing — 490 lines — stays where its author put it; the contents beside it link to each section on GitHub.

SDD Requirements Command

Create EARS-format requirements specification.


Instructions for Claude

You are executing the /sdd-requirements [feature-name] command to create a requirements specification.

Command Format

/sdd-requirements authentication
/sdd-requirements payment-processing
/sdd-requirements user-dashboard

Your Task

Generate a comprehensive requirements specification in EARS format for the specified feature.


Process

1. Read Steering Context (Article VI)

IMPORTANT: Before starting, read steering files to understand project context:

# Read these files first
steering/product.md      # Business context, users, goals
steering/structure.md    # Architecture patterns
steering/tech.md         # Technology stack

Extract:

  • Target users
  • Product goals
  • Existing architecture patterns
  • Technology constraints

2. Gather Requirements

Methods (use as appropriate):

A. Stakeholder Interview (if user is available)

Use AskUserQuestion tool to ask:

  • Who are the users of this feature?
  • What problem does this solve?
  • What are the critical workflows?
  • What are the acceptance criteria?
  • Are there any constraints (performance, security, compliance)?
B. Research Existing System (brownfield)
  • Search for existing implementation: grep -r "{{feature}}" src/
  • Read related code
  • Identify current behavior
  • Document what needs to change (delta spec)
C. Infer from Context
  • Analyze steering/product.md for user types
  • Review existing requirements docs
  • Check for similar features in codebase

3. Generate Requirements Document

Use template from templates/requirements.md:

Structure:

# Requirements Specification: {{FEATURE_NAME}}

## Overview

- Purpose
- Scope (in/out)
- Business context (from steering/product.md)

## Stakeholders

[Table of roles]

## Functional Requirements

### REQ-{{COMPONENT}}-001: [Title]

[EARS Pattern - choose appropriate pattern]

**Acceptance Criteria**:

- [Testable criterion 1]
- [Testable criterion 2]

**Priority**: P0/P1/P2/P3
**Status**: Draft
**Traceability**: (leave blank for now)

[Repeat for all requirements]

## Non-Functional Requirements

### REQ-PERF-001: Performance

### REQ-SEC-001: Security

### REQ-SCALE-001: Scalability

### REQ-AVAIL-001: Availability

## Requirements Coverage Matrix

[Initial table - will be filled during design/implementation]

Read the full file on GitHub · 490 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 490 lines · 0 tokens per session scan A c2aab2b9048f

Subscribe to this mod's changes

sdd-requirements is a command published in the GitHub repository nahisaho/CodeGraphMCPServer (12 stars, last pushed 8mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 2,650 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.