Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/cloudposse/atmos/speckit-git-validatenpx skills add cloudposse/atmos --skill speckit-git-validategit clone --depth 1 https://github.com/cloudposse/atmosWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00016 | $0.00493 |
| Opus 5 | $0.00008 | $0.00246 |
| Sonnet 5 | $0.00003 | $0.00099 |
| Haiku 4.5 | $0.00002 | $0.00049 |
Grade A, and why
speckit-git-validate scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to speckit-git-validate — 1 line differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
Validate Feature Branch
Validate that the current Git branch follows the expected feature branch naming conventions.
Prerequisites
- Check if Git is available by running
git rev-parse --is-inside-work-tree 2>/dev/null - If Git is not available, output a warning and skip validation:
[specify] Warning: Git repository not detected; skipped branch validation
Validation Rules
Get the current branch name:
git rev-parse --abbrev-ref HEAD
The branch name must match one of these patterns:
- Sequential:
^[0-9]{3,}-(e.g.,001-feature-name,042-fix-bug,1000-big-feature) - Timestamp:
^[0-9]{8}-[0-9]{6}-(e.g.,20260319-143022-feature-name)
Execution
If on a feature branch (matches either pattern):
- Output:
✓ On feature branch: <branch-name> - Check if the corresponding spec directory exists under
specs/:- For sequential branches, look for
specs/<prefix>-*where prefix matches the numeric portion - For timestamp branches, look for
specs/<prefix>-*where prefix matches theYYYYMMDD-HHMMSSportion
- For sequential branches, look for
- If spec directory exists:
✓ Spec directory found: <path> - If spec directory missing:
⚠ No spec directory found for prefix <prefix>
If NOT on a feature branch:
- Output:
✗ Not on a feature branch. Current branch: <branch-name> - Output:
Feature branches should be named like: 001-feature-name or 20260319-143022-feature-name
Graceful Degradation
If Git is not installed or the directory is not a Git repository:
- Check the
SPECIFY_FEATUREenvironment variable as a fallback - If set, validate that value against the naming patterns
- If not set, skip validation with a warning
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 55 lines · 16 tokens per session scan A 5bc31670a01c
speckit-git-validate is a skill published in the GitHub repository cloudposse/atmos (1,367 stars, last pushed today), licensed Apache-2.0. It adds 16 tokens to every session and 493 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to speckit-git-validate, differing in 1 line, and is treated as a copy.
Other skills, from other repositories
python-feature-lifecycle
Guidance for package and feature lifecycle in the Agent Framework Python codebase, including stage meanings, feature-stage decorators, feature enums, and how to move APIs from one stage to the next.
python-development
Coding standards, conventions, and patterns for developing Python code in the Agent Framework repository. Use this when writing or modifying Python source files in the python/ directory.
foundry-config-setup
Resolve missing setup caused by a hardcoded Foundry project endpoint or model in a sample. Use when a sample fails because it uses a placeholder/hardcoded projectendpoint (for example "https://your-project.services.ai.azure.com") or a hardcoded model instead of reading them from the environment.
reflect
Review recent work, find repeated workflow patterns, and suggest reusable skills, agents, commands, config changes, or playbooks. Use when the user asks to learn from past sessions, improve recurring workflows, or identify what should be turned into reusable agent instructions.
codemap
Generate comprehensive hierarchical codemaps for UNFAMILIAR repositories. Expensive operation - only use when explicitly asked for codebase documentation or initial repository mapping.
length-converter
Convert between common length units (miles, km, feet, meters) using a multiplication factor.