Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/github/spec-kit-copilot/speckit-bundlenpx skills add github/spec-kit-copilot --skill speckit-bundlegit clone --depth 1 https://github.com/github/spec-kit-copilotWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00099 | $0.00701 |
| Opus 5 | $0.00049 | $0.00351 |
| Sonnet 5 | $0.00020 | $0.00140 |
| Haiku 4.5 | $0.00010 | $0.00070 |
Grade A, and why
speckit-bundle scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 61 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Spec Kit — bundles
Discover, install, and author Spec Kit bundles with the Specify CLI
specify bundle command group. A bundle is a versioned, curated set of components
(extensions, presets, integrations, workflows) installed together through each
primitive's own machinery. (Requires Specify CLI >= 0.11.)
Prerequisite: needs the
specifyCLI. Ifspecify --versionfails, install it with the speckit-cli-setup skill first.
When to use
- Find and install a bundle, or update/remove an installed one.
- Author a bundle: validate its manifest and build a distributable artifact.
- Initialize a project and install a bundle in one step.
How to invoke
# Discover
specify bundle search <query>
specify bundle info <bundle-id> # full metadata + fully expanded component set
specify bundle list # bundles installed in this project
# Install / update / remove
specify bundle install <bundle-id-or-path> # catalog id, .zip, dir, or bundle.yml
specify bundle install <bundle-id> --integration <key> --offline
specify bundle update <bundle-id>
specify bundle remove <bundle-id> # removes only what this bundle contributed
# Initialize a project, then optionally install a bundle
specify bundle init [<bundle-id>] [--integration <key>] [--offline]
# Authoring
specify bundle validate # manifest well-formed + references resolve
specify bundle build --path <dir> --output <dir> # produce a versioned .zip
# Catalog sources
specify bundle catalog list
specify bundle catalog add <url> [--policy install-allowed|discovery-only] [--priority <n>] [--id <id>]
specify bundle catalog remove <id>
Notes
installaccepts a catalog bundle id or a local path to a.zip, a bundle directory, or abundle.yml.removeonly uninstalls components the bundle contributed — no collateral removals.- Use
--offlineto avoid network access when installing from local artifacts. - For authoring, run
specify bundle validatebeforespecify bundle build. - A bundle installs its components through each primitive's own machinery, so any
extension/command components scaffold Copilot skills under
.github/skills/(in a skills-mode project). Run/skills reloadto pick those up in the current session, or they load on the next session start.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 61 lines · 99 tokens per session scan A db3dbbff7791
speckit-bundle is a skill published in the GitHub repository github/spec-kit-copilot (11 stars, last pushed 6d ago), licensed MIT. It adds 99 tokens to every session and 701 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
brag-sheet
Turns vague "what did I do?" into evidence-backed impact statements for performance reviews, self-reviews, promotion packets, and weekly updates. Uniquely mines Copilot CLI session logs to reconstruct forgotten work, plus git commits and GitHub PRs. Enforces a 3-part impact contract (action → result → evidence). Works…
distributed-mesh
How to coordinate with squads on different machines using git as transport.
external-comms
PAO workflow for scanning, drafting, and presenting community responses with human review gate.
init-mode
Team initialization flow (Phase 1 proposal + Phase 2 creation).
tiered-memory
Three-tier agent memory model (hot/cold/wiki) for context reduction per spawn.
client-compatibility
Platform detection and adaptive spawning for CLI vs VS Code vs other surfaces.