speca CLAUDE.md

speca CLAUDE.md is an instructions file for coding agents from NyxFoundation/speca. It costs 2,563 tokens per session, scanned A, original, MIT.

Repository instructions for Claude Code, an AI coding assistant, covering the SPECA security-audit project and its commands. They explain the project and how to run tests and audit phases.

In plain words
What is it for?
Running the test suite, starting one or more audit phases, running phases through a target, forcing a rerun, and checking cleanup without executing it.
Why use it?
They give the assistant the project context and tested commands it needs to work consistently. This reduces guesswork about how to validate changes or run part of the audit pipeline.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/nyxfoundation/speca/claude-md
Clone the repo
git clone --depth 1 https://github.com/NyxFoundation/speca

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for speca CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/nyxfoundation/speca/claude-md.svg)](https://agentmods.dev/instructions/nyxfoundation/speca/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/nyxfoundation/speca/claude-md"><img src="https://agentmods.dev/badge/instructions/nyxfoundation/speca/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 2,563 This file is loaded in full into every session.
When invoked 2,563 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.02563 $0.02563
Opus 5 $0.01282 $0.01282
Sonnet 5 $0.00513 $0.00513
Haiku 4.5 $0.00256 $0.00256

Measured 4d ago against content hash 959fe9bfa7d1, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

speca CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 106 lines

How it starts

The opening of the file, as written. The whole thing — 106 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

Project Overview

SPECA (Specification-to-Property Agentic Auditing) — an automated security audit pipeline that uses Claude Code CLI to analyze codebases for vulnerabilities. The pipeline transforms specifications into formal program graphs, generates security properties, pre-resolves code locations, performs proof-based formal audits against target code, and filters false positives via a recall-safe 3-gate review pipeline (Dead Code, Trust Boundary, Scope Check).

Commands

# Run tests (pre-flight check used in all CI workflows)
uv run python3 -m pytest tests/ -v --tb=short

# Run a single phase
uv run python3 scripts/run_phase.py --phase 01a

# Run multiple phases sequentially
uv run python3 scripts/run_phase.py --phase 01a 01b 01e

# Run all phases up to a target (resolves dependency chain)
uv run python3 scripts/run_phase.py --target 04 --workers 4

# Force re-execution (clears resume state)
uv run python3 scripts/run_phase.py --phase 03 --force --workers 4 --max-concurrent 64

# Dry-run cleanup check
uv run python3 scripts/run_phase.py --phase 03 --cleanup-dry-run

# Register MCP servers
bash scripts/setup_mcp.sh
bash scripts/setup_mcp.sh --verify

Architecture

Orchestrator (scripts/orchestrator/)

The async Python orchestrator manages the full lifecycle of each phase:

  1. config.pyPhaseConfig Pydantic models define each phase (prompt path, queue/output patterns, batch strategy, circuit breaker thresholds, cost limits, MCP servers, tool filters). All phases live in PHASE_CONFIGS dict.
  2. base.pyBaseOrchestrator loads inputs, validates with Pydantic schemas, filters already-processed items (resume), enriches with context, creates batches, executes in parallel via asyncio. Subclasses: Phase01Orchestrator, Phase02cOrchestrator, Phase03Orchestrator, Phase04Orchestrator, Phase05Orchestrator.
  3. runner.pyClaudeRunner invokes claude CLI per batch with --prompt-path, --stream-json. Includes CircuitBreaker (consecutive failures, total retries, empty results) and retry with exponential backoff (max 3).
  4. watchdog.pyLogWatcher tails stream-json logs in real-time via async task; CostTracker enforces per-phase budget (hard stop on BudgetExceeded).
  5. resume.pyResumeManager scans PARTIAL_*.json outputs, extracts processed IDs, enables incremental execution.
  6. collector.pyResultCollector saves partial results immediately after each batch. Validation is lenient (warns but doesn't block) to preserve partial progress. Applies output_fields filtering to keep PARTIALs compact.
  7. schemas.py — Pydantic models for all inter-phase data contracts. Cross-phase validation at boundaries (01a→01b→01e→02c→03→04).

Read the full file on GitHub · 106 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 106 lines · 2,563 tokens per session scan A 959fe9bfa7d1

Subscribe to this mod's changes

speca CLAUDE.md is an instructions file published in the GitHub repository NyxFoundation/speca (454 stars, last pushed 22d ago), licensed MIT. It adds 2,563 tokens to every session, about $0.0128 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens