Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/firatcand/forge/ingest-specnpx skills add firatcand/forge --skill ingest-specgit clone --depth 1 https://github.com/firatcand/forgeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/firatcand/forge/ingest-spec)<a href="https://agentmods.dev/skills/firatcand/forge/ingest-spec"><img src="https://agentmods.dev/badge/skills/firatcand/forge/ingest-spec.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00039 | $0.00552 |
| Opus 5 | $0.00019 | $0.00276 |
| Sonnet 5 | $0.00008 | $0.00110 |
| Haiku 4.5 | $0.00004 | $0.00055 |
Grade A, and why
ingest-spec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
/ingest-spec
Validation checklist
For spec/BRIEF.md:
- Product section is concrete (one or two sentences describing what the product DOES)
- User & JTBD section is specific (named persona + JTBD format)
- v1 scope has at least 2 bullets
- Non-goals has at least 2 bullets
- Definition of done is a delivery checkpoint (not a metric, not a vision)
For spec/PRD.md:
- Problem is concrete (specific user, specific moment)
- Target user is specific
- Per-feature breakdown has one subsection per v1 feature; each has flow + acceptance + edge cases + non-goals
- Acceptance criteria (overall v1) are testable
- Explicit non-goals include all from BRIEF.non-goals
For spec/SPEC.md:
- Stack is specified (runtime, language, key libs)
- Data model present
- Key flows documented
- Environment variables enumerated
- Security model defined
For spec/DESIGN.md (if exists):
- Mode declared (
project_ownedorreference_external) - Tokens are self-contained (no
@inheritpatterns — if found, flag as drift from prior forge version) - Voice section calibrated for this product
Cross-document consistency
- PRD acceptance criteria must be testable given SPEC's data model
- DESIGN voice must be compatible with PRD's target user
- All env vars in SPEC must have entries in
.env.example(or be documented per secret manager) - BRIEF non-goals must appear verbatim in PRD non-goals
- PRD constraints (tracker, secret manager) must match
.forge/settings.yamlif present
On failure
List what's missing or inconsistent. Block /decompose with a clear message: "ingest-spec failed — fix the items above and re-run."
On success
Write spec/CONTEXT.md — single-page synthesis of all four docs. This is what /decompose reads.
Print: "Spec validated. /decompose unlocked."
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 54 lines · 39 tokens per session scan A c8c428e3d259
ingest-spec is a skill published in the GitHub repository firatcand/forge (13 stars, last pushed 1mo ago), licensed MIT. It adds 39 tokens to every session and 552 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
ospec-change
Create or advance a lightweight OSpec change using the classic fast workflow.
prospec-knowledge-generate
Generate AI Knowledge - Read raw-scan.md, analyze project structure, autonomously decide module boundaries, and produce Recipe-First module READMEs and index. Triggers: generate knowledge, analyze project, module split, 產生知識, 知識庫, 分析專案, 模組拆分.
submit-pr
Open a prospec pull request in the house format — push the change's two commits, write the Traditional Chinese body, and link it to its issue. Triggers: submit pr, open pr, 開 PR, 送 PR, 發 PR, pull request, 提交 PR.
prospec-explore
Explore - Requirement exploration, problem investigation, and solution comparison partner. Triggers: explore, compare, investigate, unsure, clarify, 探索, 比較, 釐清, 調查, 不確定.
prospec-knowledge-update
Incremental Knowledge Update - Parse delta-spec.md to identify affected modules, scan source code, and update module README, index.md, and module-map.yaml incrementally. Triggers: knowledge update, incremental update, sync knowledge, update docs, 更新知識, 增量更新, 同步知識, 更新文件.
prospec-plan
Plan Implementation - Convert User Story into technical implementation plan (plan.md) and change specification (delta-spec.md). Triggers: plan, architecture, technical plan, 規劃, 架構規劃, 技術規劃.