Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/firatcand/forge/update-specnpx skills add firatcand/forge --skill update-specgit clone --depth 1 https://github.com/firatcand/forgeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/firatcand/forge/update-spec)<a href="https://agentmods.dev/skills/firatcand/forge/update-spec"><img src="https://agentmods.dev/badge/skills/firatcand/forge/update-spec.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00050 | $0.03830 |
| Opus 5 | $0.00025 | $0.01915 |
| Sonnet 5 | $0.00010 | $0.00766 |
| Haiku 4.5 | $0.00005 | $0.00383 |
Grade A, and why
update-spec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 214 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/update-spec
Two modes, one lifecycle (ephemeral ADRs — see .forge/CONTEXT.md §Ephemeral ADR workflow):
--draft— interview → writespec/decisions/<YYYY-MM-DD>-<slug>.mdfromtemplates/adr.template.md. The user reviews, optionally gets a second opinion, and flipsstatus: acceptedby hand.--apply <slug>(+--yes-all,--resume,--dry-run) — author the payload-complete journal, preview every artifact diff, then delegate ALL mutation toforge orchestrate apply-decision. On success the skill (not the verb) runs the git commit with the ADR's rationale as the body.
Skill ↔ verb contract: this skill owns interviews, diff previews, confirmations, journal authoring (the verb's documented upstream input), and git. The verb owns every artifact mutation, the resumable journal state machine, INDEX.md, and ADR deletion. The skill NEVER edits SPEC/PRD/phases/tracker directly.
Mode --draft
Preflight
templates/adr.template.mdmust exist. Missing → stop: "runforge migrate(orforge upgrade) to restore the bundled scaffold."- One decision at a time. Scan
spec/decisions/*.mdand classify each file:INDEX.md→ ignore (the durable decision index).- ADR frontmatter parses with
status: proposedorstatus: accepted→ refuse:✗ /update-spec --draft: an active ADR already exists: <file> (status: <status>). Finish it first: /update-spec --apply <slug> (or edit/delete the draft) status: rejected→ refuse with: "delete the rejected ADR manually (SPEC lifecycle: rejected ADRs are removed by hand, never applied or replaced)."- Filename matches the ADR shape
<YYYY-MM-DD>-<slug>.mdbut the frontmatter is missing or unparseable → REFUSE ("malformed ADR — fix or remove it first"). A broken ADR must not be silently treated as a companion note and bypassed. - Anything else (no ADR-shaped name, no frontmatter — e.g. companion
*.plan.mdnotes) → ignore; companions never block.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 214 lines · 50 tokens per session scan A e98282b86109
update-spec is a skill published in the GitHub repository firatcand/forge (13 stars, last pushed 1mo ago), licensed MIT. It adds 50 tokens to every session and 3,830 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
ospec-change
Create or advance a lightweight OSpec change using the classic fast workflow.
prospec-knowledge-generate
Generate AI Knowledge - Read raw-scan.md, analyze project structure, autonomously decide module boundaries, and produce Recipe-First module READMEs and index. Triggers: generate knowledge, analyze project, module split, 產生知識, 知識庫, 分析專案, 模組拆分.
submit-pr
Open a prospec pull request in the house format — push the change's two commits, write the Traditional Chinese body, and link it to its issue. Triggers: submit pr, open pr, 開 PR, 送 PR, 發 PR, pull request, 提交 PR.
submit-issue
Open a prospec GitHub issue in the house format — conventional-commit title, Traditional Chinese body (problem → solutions → acceptance criteria), downstream-compatibility block, series cross-links, and optional model-routing guidance. Triggers: submit issue, open issue, create issue, file issue, 開 issue, 發 issue, 建…
prospec-explore
Explore - Requirement exploration, problem investigation, and solution comparison partner. Triggers: explore, compare, investigate, unsure, clarify, 探索, 比較, 釐清, 調查, 不確定.
prospec-plan
Plan Implementation - Convert User Story into technical implementation plan (plan.md) and change specification (delta-spec.md). Triggers: plan, architecture, technical plan, 規劃, 架構規劃, 技術規劃.