Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add 45ck/skill-harness --skill spec-writergit clone --depth 1 https://github.com/45ck/skill-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/45ck/skill-harness/spec-writer)<a href="https://agentmods.dev/skills/45ck/skill-harness/spec-writer"><img src="https://agentmods.dev/badge/skills/45ck/skill-harness/spec-writer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/45ck/skill-harness/spec-writer"><img src="https://agentmods.dev/badge/skills/45ck/skill-harness/spec-writer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00022 | $0.00729 |
| Opus 5 | $0.00011 | $0.00365 |
| Sonnet 5 | $0.00004 | $0.00146 |
| Haiku 4.5 | $0.00002 | $0.00073 |
Grade A, and why
spec-writer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 82 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Write a spec document for the feature or component described. Place it in docs/ with a .md extension.
Spec sources: docs/ is the primary directory. specs/ is a legacy fallback.
Required frontmatter fields
---
id: <UPPERCASE-KEBAB-000> # unique ID, e.g. AUTH-001
title: "Human-readable title"
state: draft | proposed | in_progress | accepted | done | deprecated
kind: functional | non_functional | architecture | interface | constraint
required_evidence:
implementation: E0 # minimum evidence strength needed
# add more dimensions as needed: verification, models, apis
# optional:
depends_on: [OTHER-001] # IDs this spec depends on
conflicts_with: [OTHER-002] # IDs this spec conflicts with
owner: "Team or person"
tags: [auth, security]
---
Evidence strength reference
| Level | Name | Source |
|---|---|---|
| E0 | Declarative | @spec/@implements JSDoc annotation |
| E1 | Structural | Beads closed issue; file/symbol reference |
| E2 | Indexed | Stored in specgraph DB; linked artifact |
| E3 | Automated | Passing test suite with @spec annotation |
| E4 | Runtime | CI artifact, coverage report, live probe |
State guidance
| State | Policy | Notes |
|---|---|---|
draft |
Always passes | No evidence required — early exploration |
proposed |
Advisory | Warns if no implementation found |
in_progress |
E1 implementation required | Verification is advisory |
accepted |
E2 impl + E2 verification + E1 models | Full evidence required |
done |
E3 impl + E3 verification + E2 models | High-confidence evidence |
deprecated |
Always passes | No longer enforced |
Evidence dimensions
The required_evidence block accepts any combination of:
| Dimension | What it tracks |
|---|---|
implementation |
Code that implements the spec |
verification |
Tests that verify the spec |
models |
Data models referenced by the spec |
apis |
API endpoints implementing the spec |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 82 lines · 22 tokens per session scan A 08c60cda64b2
spec-writer is a skill published in the GitHub repository 45ck/skill-harness (15 stars, last pushed 2mo ago), licensed MIT. It adds 22 tokens to every session and 729 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
do-it-architecture
Use when authority, ownership, contracts, dependency boundaries, migration, recovery, or structural deletion can change a design.
do-it-review
Use to assess requirements and implementation quality independently, or to resolve a batch of review findings.
do-it-code-quality
Use when designing, changing, or debugging code to locate causal ownership and close the affected behavior.
do-it-core
Use when repository work needs a shared baseline for intent, facts, causal changes, and honest evidence.
do-it-decide
Use when uncertainty about a choice, plan, dependency, or handoff could materially change what gets built.
do-it-skill-authoring
Use when creating or revising a do-it skill so its trigger and unique professional judgment are useful without prescribing ceremony.