Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/benjaminthomas/spec-driven-dev/spec-checkpointnpx skills add benjaminthomas/spec-driven-dev --skill spec-checkpointgit clone --depth 1 https://github.com/benjaminthomas/spec-driven-devWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00098 | $0.00896 |
| Opus 5 | $0.00049 | $0.00448 |
| Sonnet 5 | $0.00020 | $0.00179 |
| Haiku 4.5 | $0.00010 | $0.00090 |
Grade A, and why
spec-checkpoint scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 95 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Checkpoint Commit
Create a checkpoint commit that captures all current changes — but only after the code passes lint, type check, and build.
Instructions
Step 1: Analyze Changes
Run these commands to understand the full picture:
git status— see all tracked and untracked filesgit diff— see detailed changes in tracked filesgit diff --cached— see already-staged changesgit log -5 --oneline— understand this repo's commit message style
Step 2: Quality Checks
Run all three checks. If any fail, fix the issues before proceeding — do not skip or ignore failures.
npm run lint— fix any lint errorsnpm run type-check— fix any type errors (if the script doesn't exist, trynpx tsc --noEmit)npm run build— fix any build errors
Iterate until all three pass cleanly. Only then move to the next step.
Step 3: Stage Everything
Stage all changes — tracked modifications, deletions, and new untracked files:
git add -A
Then review git status again. If anything staged looks like it could hold secrets —
.env*, *.pem, *_rsa, credentials.json, secrets.*, or an unfamiliar filename that might
contain an API key — unstage it (git restore --staged <file>) and tell the user what was
excluded and why, rather than committing it silently. Don't rely on the filename alone for
anything you don't recognize; skim its diff if you're unsure.
Step 4: Craft the Commit Message
Write a commit message following the project's existing conventions (observed from git log). Structure:
- First line: clear, concise summary in imperative mood (50-72 chars)
- Use conventional commit prefixes where the project uses them:
feat:,fix:,refactor:,docs:,chore:, etc.
- Use conventional commit prefixes where the project uses them:
- Body (separated by blank line): a short TL;DR of the changes — 1-3 sentences max. No bullet lists, no file-by-file breakdowns, no lengthy explanations.
- Footer: co-author attribution, naming whichever agent/model is actually running this skill — never hardcode a specific vendor or model name, since this skill runs under many different hosts
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 95 lines · 98 tokens per session scan A 1c1ea2858bb2
spec-checkpoint is a skill published in the GitHub repository benjaminthomas/spec-driven-dev (1 stars, last pushed 28d ago), licensed MIT. It adds 98 tokens to every session and 896 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
academic-paper
12-agent academic paper writing pipeline. 11 modes (full/plan/outline/revision/revision-coach/abstract/lit-review/format-convert/citation-check/disclosure/rebuttal-audit). 6 paper types, 5 citation formats, bilingual abstracts, LaTeX/DOCX-via-Pandoc/PDF output. Style Calibration + Writing Quality Check + Anti-Patterns…
academic-paper-reviewer
Multi-perspective academic paper review with dynamic reviewer personas. Simulates 5 independent reviewers (EIC + 3 peer reviewers + Devil's Advocate) with field-specific expertise. Supports full review, re-review (verification), quick assessment, methodology focus, Socratic guided, and calibration modes. Triggers on…
agent-platform-alert-configuration
Configures best-practice alerting policies for Google Cloud Vertex AI / Agent Platform agents on Agent Runtime. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, and quality metrics (response quality, tool use, hallucination). Also use when provisioning online monitors…
agent-platform-eval-flywheel
Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results before and after a fix, or when guidance is needed on…
agent-platform-inference
Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when you need to generate code for calling Gemini or OpenMaaS models, authenticate with GenAI SDK, OpenAI SDK, or legacy Agent…
gemini-omni-flash-api
Use this skill for generative video editing, text-to-video, image-referenced video generation, and first-frame-to-video transition animations using the official google-genai SDK. Includes workflows for pre-processing/optimizing high-resolution or long source videos with ffmpeg, stripping audio for full sound…