Claude Octopus is an orchestration project that sends research, design, and coding tasks to Claude Code and other AI model providers so their results can be compared. Developers use it for multi-model work, disagreement detection, reviews, persistent context, and an optional workflow that moves from discovery through delivery. The catalogue entries are its commands, skills, agents, instructions, hooks, plugins, and settings.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/nyldn/claude-octopusWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/nyldn/claude-octopus/spec)<a href="https://agentmods.dev/commands/nyldn/claude-octopus/spec"><img src="https://agentmods.dev/badge/commands/nyldn/claude-octopus/spec.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00012 | $0.00430 |
| Opus 5 | $0.00006 | $0.00215 |
| Sonnet 5 | $0.00002 | $0.00086 |
| Haiku 4.5 | $0.00001 | $0.00043 |
Grade A, and why
spec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
88% identical to octo-spec — 6 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
Spec - NLSpec Authoring
INSTRUCTIONS FOR CLAUDE
When the user invokes this command (e.g., /octo:spec <arguments>):
CORRECT - Read the explicit workflow source:
Read ${HOME}/.claude-octopus/plugin/.claude/skills/flow-spec/SKILL.md, then execute it with <user's arguments>
INCORRECT:
Skill(skill: "flow-spec", ...) ❌ Wrong! Octopus skills are model-invocation disabled
Task(subagent_type: "octo:spec", ...) ❌ Wrong! This is a skill, not an agent type
Auto-loads the spec skill for NLSpec authoring.
Quick Usage
Just describe what you want to specify:
"Specify a user authentication system"
"Create a spec for real-time chat"
"Define requirements for payment processing"
What Is Spec?
NLSpec (Natural Language Specification) authoring:
- Structured specification from multi-AI research
- Question-first approach to understand scope
- Probe-based research for domain context
- Validated completeness checking
What You Get
- Multi-AI research (Claude + Antigravity + Codex) on the domain
- Structured NLSpec with behaviors, actors, constraints
- Adversarial completeness challenge from a second provider (surfaces missing requirements and overlooked edge cases)
- Completeness validation with scoring
- Saved specification file for downstream workflows
When To Use
- Starting a new project from scratch
- Defining requirements before implementation
- Creating a specification for handoff
- Establishing acceptance criteria upfront
Natural Language Examples
"Specify an OAuth 2.0 authentication system"
"Create a spec for a REST API gateway"
"Define the requirements for a CI/CD pipeline"
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 70 lines · 12 tokens per session scan A 6c831b44ad6c
spec is a command published in the GitHub repository nyldn/claude-octopus (4,054 stars, last pushed today), licensed MIT. It adds 12 tokens to every session and 430 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 88% identical to octo-spec, differing in 6 lines, and is treated as a copy.
Other commands, from other repositories
zizmor
Audit GitHub Actions workflows, composite actions, Dependabot configs, and pre-commit configs for security findings using zizmor — template injection, credential persistence, unpinned uses, over-broad permissions, impostor commits. Covers local CLI, auto-fix, zizmor.yml policy, severity-based CI gates, SARIF upload…
gitops
Flux CD and Argo CD — two modes. debug: five structured debug workflows for live clusters (installation, source, HelmRelease, Kustomization, ResourceSet) producing a five-section report. audit: six-phase read-only repo analysis (discovery, validation, API compliance, best practices, security) producing a prioritised…
secrets
Secrets strategy, External Secrets Operator scaffolding, Sealed Secrets seal/rotate/backup, rotation runbooks, and Kubernetes-side secrets audit.
azure
Azure identity (Workload Identity, OIDC, Entra ID), resource tagging, AKS platform patterns, RBAC scoping, and production-readiness review — with Terraform generation.
openshift
OpenShift SCC diagnosis and hardening, Route TLS patterns, OpenShift GitOps app delivery, and cluster upgrade validation.
kyverno
Generate, test, audit, debug, and migrate Kyverno policies using the new CEL-based policy types (ValidatingPolicy, MutatingPolicy, GeneratingPolicy, ImageValidatingPolicy — all apiVersion policies.kyverno.io/v1). Covers matchConstraints, matchConditions, CEL validations/mutations, generator.Apply(), Audit→Deny…