Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add drivestream-lab/prayog-skills --skill spec-technical-reviewgit clone --depth 1 https://github.com/drivestream-lab/prayog-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/drivestream-lab/prayog-skills/spec-technical-review)<a href="https://agentmods.dev/skills/drivestream-lab/prayog-skills/spec-technical-review"><img src="https://agentmods.dev/badge/skills/drivestream-lab/prayog-skills/spec-technical-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/drivestream-lab/prayog-skills/spec-technical-review"><img src="https://agentmods.dev/badge/skills/drivestream-lab/prayog-skills/spec-technical-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00134 | $0.04186 |
| Opus 5 | $0.00067 | $0.02093 |
| Sonnet 5 | $0.00027 | $0.00837 |
| Haiku 4.5 | $0.00013 | $0.00419 |
Grade A, and why
spec-technical-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 283 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Spec technical review
Resolve all engineering decisions that block the implementation plan. Do not implement. Produce a Technical Design Document (TDD) and draft ADRs.
Runs while the Draft spec PR is open — write TDD and ADR files locally and
emit Forge readiness for the spec branch. Gate 2 label remains spec-pending.
PE architecture acceptance is recorded in artifact metadata
(Draft → Accepted); spec-lgtm is set only after the full spec package
(including plan) is on head.
Benchmarked against: Stripe/Cloudflare/Oxide RFC process, Sentry design-first
gate, agentic_development_workflow multi-role review, GitHub Spec Kit
/speckit.plan architectural artifact pattern.
NON-NEGOTIABLE
- Never skip a check in references/checks.md. Mark SKIPPED with reason.
- Every engineering decision in the output must be resolved (recommendation recorded) or explicitly deferred with a named risk and default assumption.
- Do not ask PM to choose architecture. Route only product-scope and user-visible behaviour questions to the meta PRD PR. See references/governance.md for the routing rubric.
- Every
NEW-ADRfrom feasibility maps to exactly one disposition:ADR_REQUIREDwith a Draft file underadr_dir,TDD_ONLYwith rationale, orDEFERRED_WITH_DEFAULTwith risk and revisit trigger. - Dual output: chat summary + saved TDD file (local persistence + Forge readiness).
- Run T0–T5 control loop (Gather → Understand → Analyze → Design → Execute → Verify).
- Human PE acceptance is required before the implementation plan runs.
Technical review creates Draft ADR files first; planning consumes only
Accepted files in
{adr_dir}. Mid-lane PE work updates files on the spec branch — it does not setspec-lgtm. - Verify light freshness: product-spec H1–H3 citations, tip continuity,
and G1 when applicable agree with live handoff. Stop on authority drift.
Do not fail closed solely on feasibility
artifact.digestmismatch — feas/TDD digests are walk-time (PURGE at initiative closure). - Product/architecture boundary. PE may frame options and draft ADRs
against approved
REQ-*constraints. An ADR must not becomeAcceptedwhen it depends on user-visible behavior not already represented by an approvedREQ-*— amend and re-approve the spec first. ReferenceREQ-*by id only in Context/Recommendation/Consequences — never quote or paraphrase the REQ's behavioral sentence; that restates the feature instead of stating the engineering decision. T12 enforces this as an independent re-read pass, not a same-pass self-grade (seereferences/checks.md). - No forge mutations. Do not commit, push, branch, open PRs, apply labels,
create issues, or merge. Fill
handoff.forge/ recommend/commit-workspace. - Ground every
NEW-ADRfinding in the actual codebase before classifying or drafting it — never draft from feasibility'sALTERNATIVE:text alone. Feasibility's F1/F2 baseline already inspected the repo once; this stage re-verifies and extends that evidence, because a finding's prose can itself encode a wrong question (see the ADR qualification rubric below). Use a codegraph provider when available (prayog-skills/references/codegraph-tool-contract.md), otherwise readsource_rootsdirectly — the tool is optional, the grounding activity is not. Record what was found (or "none found — new capability") in the row's Code evidence — extend feasibility's column, don't just trust it blank or stale. - If a codegraph provider is available, prefer it for the grounding pass in
NON-NEGOTIABLE 11 and for other architecture/impact questions. Always
fall back to direct
source_rootsreads when unavailable — never block or change outcome selection on its absence.
What ships with it
10 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- prompts/fixtures/happy_path.expected.md 3.8 KB
- prompts/fixtures/happy_path.inputs.yaml 240 B
- prompts/schema.yaml 361 B
- prompts/template.md 3.5 KB
- references/adr-template.md 7.7 KB
- references/checks.md 13 KB
- references/governance.md 6.1 KB
- references/layout-defaults.md 657 B
- references/output-template.md 10 KB
- scripts/adr_boundary_lint.py 39 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 283 lines · 134 tokens per session scan A d92f13cb51e2
spec-technical-review is a skill published in the GitHub repository drivestream-lab/prayog-skills (2 stars, last pushed 4d ago), licensed MIT. It adds 134 tokens to every session and 4,186 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
insight-error-page
Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…