Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ddddjaak/se-skills --skill spec-authoringgit clone --depth 1 https://github.com/ddddjaak/se-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ddddjaak/se-skills/spec-authoring)<a href="https://agentmods.dev/skills/ddddjaak/se-skills/spec-authoring"><img src="https://agentmods.dev/badge/skills/ddddjaak/se-skills/spec-authoring/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/ddddjaak/se-skills/spec-authoring"><img src="https://agentmods.dev/badge/skills/ddddjaak/se-skills/spec-authoring.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00111 | $0.06512 |
| Opus 5 | $0.00056 | $0.03256 |
| Sonnet 5 | $0.00022 | $0.01302 |
| Haiku 4.5 | $0.00011 | $0.00651 |
Grade A, and why
spec-authoring scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 440 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Spec Authoring
Overview
Architecture design says how the system fits together. Specifications say how to implement each piece. They are the contract between the SE (who designed the system) and the engineers (who build and test it). A specification that is missing a section — error handling, concurrency model, timing budget — silently communicates that those aspects were not designed.
This skill produces three specification types from a common base of requirements and architecture: the Software Outline Design (软件概要设计), the Hardware-Software Interface Specification (软硬件接口规格), and the Test Plan (测试方案). Each has a different audience and a different structure, but all draw from the same upstream artifacts and all enforce the same standard: every claim traces to a requirement, every interface is fully defined, every test case has quantified pass/fail criteria.
Spec authoring is to SE what specification-driven development is to software development — but for chip-vendor specification formats rather than software feature specs.
When to Use
- Architecture design is complete and confirmed, and formal specification documents are needed
- Need to produce the Software Outline Design (软件概要设计) for the firmware team
- Need to produce the Hardware-Software Interface Specification for cross-department alignment
- Need to produce the Test Plan (测试方案) for the validation team
- A specific specification document is requested by a downstream team
- Adding a new module to an existing system that needs its own specification section
When NOT to use:
- Architecture is not yet designed or confirmed (run
architecture-designfirst, or invoke it inline) - The document already exists and needs only a minor text update (edit the document directly)
- Pure documentation formatting (this skill generates content; template styling is a separate concern)
- The request is for a one-page interface memo, not a full formal specification
The Process
SELECT ──→ GATHER ──→ GENERATE ──→ CROSS-CHECK ──→ FINALIZE
│ │ │ │ │
▼ ▼ ▼ ▼ ▼
Choose Collect Author Verify Human
which all input the spec internal review &
spec(s) artifacts content consistency sign-off
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 440 lines · 111 tokens per session scan A 505a47bc0d56
spec-authoring is a skill published in the GitHub repository ddddjaak/se-skills (4 stars, last pushed 1mo ago), licensed MIT. It adds 111 tokens to every session and 6,512 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
gke-compute-classes
Configures, optimizes, and troubleshoots GKE ComputeClasses. Use when configuring Spot VMs with on-demand fallback, targeting specific accelerators (GPUs/TPUs) or machine families, restricting ComputeClass access, or debugging pending pods related to node pool auto-creation. Do not use for cluster-level Node Auto…
jetson-diagnostic
Read-only Jetson health snapshot for identity, memory, GPU, thermal, power, storage, services, and top processes.
doca-socket-relay
Use this skill when the operator is driving the DOCA Socket Relay to bridge a socket-oriented host application onto a BlueField DPU peer without rewriting it — picking the deployment shape (in-process, sidecar, or BlueField service container), configuring the host-side socket and the DPU-side forwarding endpoint…
offensive-z-wave
Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection on unauthenticated nodes, default-key brute-force on test deployments, and home-automation hub pivots. Use when targeting…
hsb-flash
Flash the FPGA on an HSB board connected to an NVIDIA devkit. Supports HSB Lattice boards (FPGA versions 2407, 2412, 2507, 2510) and Leopard Imaging VB1940 "all-in-one" cameras (FPGA versions 2507, 2510). Uses release-specific YAML manifests and board-type-specific program commands. Lattice and VB1940 commands must…
jetson-validate-image
Use after jetson-flash-image to run static BSP checks, on-target smoke/regression tests on a flashed DUT, or both. Not for build or flash steps. Triggers: validate bsp, on-target validation.