spec-checkpoint

A skill for creating a checkpoint commit, which is a saved group of the current project changes in version control. It first checks the code with linting, type checking, and a build.

In plain words
What is it for?
Use it when saving all current work, creating a commit, or responding to a checkpoint request. It reviews changes, runs quality checks, stages files, and prepares the commit.
Why use it?
It prevents unfinished or failing code, and possible secret files, from being included in a progress commit.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/benjaminthomas/spec-driven-dev/spec-checkpoint
Any agent
npx skills add benjaminthomas/spec-driven-dev --skill spec-checkpoint
Clone the repo
git clone --depth 1 https://github.com/benjaminthomas/spec-driven-dev

Made for: Claude Code, Codex.

Per session 98 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 896 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00098 $0.00896
Opus 5 $0.00049 $0.00448
Sonnet 5 $0.00020 $0.00179
Haiku 4.5 $0.00010 $0.00090

Measured yesterday against content hash 1c1ea2858bb2, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

spec-checkpoint scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/spec-checkpoint/SKILL.md · 95 lines

How it starts

The opening of the file, as written. The whole thing — 95 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Checkpoint Commit

Create a checkpoint commit that captures all current changes — but only after the code passes lint, type check, and build.

Instructions

Step 1: Analyze Changes

Run these commands to understand the full picture:

  1. git status — see all tracked and untracked files
  2. git diff — see detailed changes in tracked files
  3. git diff --cached — see already-staged changes
  4. git log -5 --oneline — understand this repo's commit message style

Step 2: Quality Checks

Run all three checks. If any fail, fix the issues before proceeding — do not skip or ignore failures.

  1. npm run lint — fix any lint errors
  2. npm run type-check — fix any type errors (if the script doesn't exist, try npx tsc --noEmit)
  3. npm run build — fix any build errors

Iterate until all three pass cleanly. Only then move to the next step.

Step 3: Stage Everything

Stage all changes — tracked modifications, deletions, and new untracked files:

git add -A

Then review git status again. If anything staged looks like it could hold secrets — .env*, *.pem, *_rsa, credentials.json, secrets.*, or an unfamiliar filename that might contain an API key — unstage it (git restore --staged <file>) and tell the user what was excluded and why, rather than committing it silently. Don't rely on the filename alone for anything you don't recognize; skim its diff if you're unsure.

Step 4: Craft the Commit Message

Write a commit message following the project's existing conventions (observed from git log). Structure:

  • First line: clear, concise summary in imperative mood (50-72 chars)
    • Use conventional commit prefixes where the project uses them: feat:, fix:, refactor:, docs:, chore:, etc.
  • Body (separated by blank line): a short TL;DR of the changes — 1-3 sentences max. No bullet lists, no file-by-file breakdowns, no lengthy explanations.
  • Footer: co-author attribution, naming whichever agent/model is actually running this skill — never hardcode a specific vendor or model name, since this skill runs under many different hosts

Read the full file on GitHub · 95 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 95 lines · 98 tokens per session scan A 1c1ea2858bb2

Subscribe to this mod's changes

spec-checkpoint is a skill published in the GitHub repository benjaminthomas/spec-driven-dev (1 stars, last pushed 28d ago), licensed MIT. It adds 98 tokens to every session and 896 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

academic-paper

12-agent academic paper writing pipeline. 11 modes (full/plan/outline/revision/revision-coach/abstract/lit-review/format-convert/citation-check/disclosure/rebuttal-audit). 6 paper types, 5 citation formats, bilingual abstracts, LaTeX/DOCX-via-Pandoc/PDF output. Style Calibration + Writing Quality Check + Anti-Patterns…

hamzabellouch/agent-skills · 184 tokens

academic-paper-reviewer

Multi-perspective academic paper review with dynamic reviewer personas. Simulates 5 independent reviewers (EIC + 3 peer reviewers + Devil's Advocate) with field-specific expertise. Supports full review, re-review (verification), quick assessment, methodology focus, Socratic guided, and calibration modes. Triggers on…

hamzabellouch/agent-skills · 187 tokens

agent-platform-alert-configuration

Configures best-practice alerting policies for Google Cloud Vertex AI / Agent Platform agents on Agent Runtime. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, and quality metrics (response quality, tool use, hallucination). Also use when provisioning online monitors…

hamzabellouch/agent-skills · 106 tokens

agent-platform-eval-flywheel

Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results before and after a fix, or when guidance is needed on…

hamzabellouch/agent-skills · 108 tokens

agent-platform-inference

Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when you need to generate code for calling Gemini or OpenMaaS models, authenticate with GenAI SDK, OpenAI SDK, or legacy Agent…

hamzabellouch/agent-skills · 125 tokens

gemini-omni-flash-api

Use this skill for generative video editing, text-to-video, image-referenced video generation, and first-frame-to-video transition animations using the official google-genai SDK. Includes workflows for pre-processing/optimizing high-resolution or long source videos with ffmpeg, stripping audio for full sound…

hamzabellouch/agent-skills · 79 tokens