spec-validation

spec-validation is a skill for Claude Code, Codex from jmanhype/speckit. It costs 38 tokens per session (965 once invoked), scanned A, original, MIT.

Validates specification quality for technology-agnosticism, testability, and completeness. Automatically invoked when reviewing specs, checking requirements, or before transitioning from specify to plan phase.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/jmanhype/speckit/spec-validation
Any agent
npx skills add jmanhype/speckit --skill spec-validation
Clone the repo
git clone --depth 1 https://github.com/jmanhype/speckit

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for spec-validation

README.md
[![agentmods](https://agentmods.dev/badge/skills/jmanhype/speckit/spec-validation.svg)](https://agentmods.dev/skills/jmanhype/speckit/spec-validation)
Your own site
<a href="https://agentmods.dev/skills/jmanhype/speckit/spec-validation"><img src="https://agentmods.dev/badge/skills/jmanhype/speckit/spec-validation.svg" alt="Measured on agentmods" height="20"></a>
Per session 38 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 965 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00038 $0.00965
Opus 5 $0.00019 $0.00483
Sonnet 5 $0.00008 $0.00193
Haiku 4.5 $0.00004 $0.00097

Measured 2d ago against content hash 2867068bde3f, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

spec-validation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/spec-validation/SKILL.md · 164 lines

How it starts

The opening of the file, as written. The whole thing — 164 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Spec Validation Skill

You are validating specifications in a Spec Kit workflow. This skill ensures specifications meet quality standards before proceeding to technical planning.

Validation Criteria

1. Technology Agnosticism

Specifications must describe WHAT and WHY, not HOW. Flag any references to:

Frameworks & Libraries

  • ❌ React, Vue, Angular, Django, FastAPI, Express
  • ❌ Redux, MobX, Zustand (state management)
  • ❌ Tailwind, Bootstrap, Material UI (styling)

Languages & Syntax

  • ❌ async/await, promises, callbacks
  • ❌ decorators, hooks, mixins
  • ❌ specific type systems

Databases & Storage

  • ❌ PostgreSQL, MongoDB, Redis, S3
  • ❌ SQL queries, NoSQL patterns
  • ❌ Specific ORM syntax

Infrastructure

  • ❌ Docker, Kubernetes, AWS, GCP
  • ❌ Specific API protocols (REST, GraphQL, gRPC)
  • ❌ Deployment patterns

Good Example:

Users can view their order history sorted by date.

Bad Example:

Use React Query to fetch orders from the REST API and display in a Tailwind-styled table.

2. Testability

Every requirement must be verifiable. Flag:

Vague Requirements

  • ❌ "System should be fast"
  • ❌ "Good user experience"
  • ❌ "Intuitive interface"
  • ❌ "Improve performance"

Subjective Criteria

  • ❌ "Easy to use"
  • ❌ "Modern design"
  • ❌ "Scalable architecture"

Good Examples:

- Page loads in under 2 seconds on 3G connection
- Form validates email format before submission
- Users receive confirmation within 24 hours
- System handles 1000 concurrent users

3. Completeness

Check for:

Missing Scenarios

  • Happy path (main flow)
  • Error cases (what can go wrong)
  • Edge cases (boundary conditions)
  • Empty/null states

Undefined Terms

  • Acronyms without definitions
  • Domain-specific terms
  • Ambiguous references ("the system", "it")

Missing Acceptance Criteria

  • Success conditions
  • Error conditions
  • Performance requirements
  • Security requirements

4. Consistency

Verify:

  • No contradicting requirements
  • Consistent terminology
  • Aligned with constitution (if exists)
  • No duplicate requirements

Read the full file on GitHub · 164 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 164 lines · 38 tokens per session scan A 2867068bde3f

Subscribe to this mod's changes

spec-validation is a skill published in the GitHub repository jmanhype/speckit (26 stars, last pushed 5mo ago), licensed MIT. It adds 38 tokens to every session and 965 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-01.

Related

Other skills, from other repositories

scaffold-runner

Interactive wrapper for the scaffold CLI that surfaces a pipeline step's decision points before executing it and manages the step lifecycle. Use when the user asks to run a scaffold step ("run scaffold ", "scaffold ", "what's next?"), to start building, or works in a project with a .scaffold/ directory.

zigrivers/scaffold · 73 tokens

work-beads

Work the project's Beads task queue end-to-end - claim a bead, build in an isolated worktree, verify, review, merge, close, report. Use when the user says "/work-beads", "/work-beads 5", "work the next N beads", "work on ", "pick up some open tasks", or asks to work the backlog. Applies to every coding agent (Claude…

zigrivers/scaffold · 106 tokens

scaffold-pipeline

Static reference for scaffold pipeline ordering, dependencies, and phase structure. Use ONLY for questions about pipeline design, step ordering, or dependency constraints — NOT for status, progress, or "what's next" queries (those go through scaffold-runner).

zigrivers/scaffold · 54 tokens

multi-model-dispatch

Correct patterns for invoking Codex CLI and Antigravity CLI (agy) as independent reviewers from Claude Code. Covers headless invocation, context bundling, output parsing, dual-model reconciliation, and fallback handling.

zigrivers/scaffold · 47 tokens

mmr

Run multi-model code review with the MMR CLI (mmr review) before merging or finishing a change, or a multi-model design critique (mmr critique) of a design doc, plan, or proposed approach before building it. Use when the user asks to review code, a PR, a diff, or staged changes, or to critique/second-opinion a design…

zigrivers/scaffold · 81 tokens

bug-triage

Read all open bugs in production/qa/bugs/, re-evaluate priority vs. severity, assign to sprints, surface systemic trends, and produce a triage report. Run at sprint start or when the bug count grows enough to need re-prioritization.

Donchitos/Claude-Code-Game-Studios · 59 tokens