Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add maksimzayats/specx --skill specx-settingsgit clone --depth 1 https://github.com/maksimzayats/specxWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/maksimzayats/specx/specx-settings)<a href="https://agentmods.dev/skills/maksimzayats/specx/specx-settings"><img src="https://agentmods.dev/badge/skills/maksimzayats/specx/specx-settings/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/maksimzayats/specx/specx-settings"><img src="https://agentmods.dev/badge/skills/maksimzayats/specx/specx-settings.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00063 | $0.00557 |
| Opus 5 | $0.00032 | $0.00279 |
| Sonnet 5 | $0.00013 | $0.00111 |
| Haiku 4.5 | $0.00006 | $0.00056 |
Grade A, and why
specx-settings scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 53 lines — stays where its author put it; the contents beside it link to each section on GitHub.
specx Settings
Use this skill whenever runtime configuration is needed. Read
references/settings.md before adding settings code.
Rules
- Model runtime config with classes that inherit
BaseRuntimeSettings. - Give each settings class a docstring that explains the configuration scope
and includes a concrete
Example:. - Place settings near the class that consumes them unless the setting is truly application-wide.
- Logging settings are application-wide and live beside
infrastructure/logging/configurator.pyand itsLoggingConfigurator. - Use
BaseStrEnumfor finite configuration values such as logging levels. - Inject settings objects only into delivery, infrastructure, and composition
classes. Do not inject
BaseRuntimeSettingssubclasses into core use cases, services, capabilities, entities, repositories, or gateway ports. - When configuration represents a genuine business policy, map it at the
composition root into a typed core value or capability that has no dependency
on Pydantic or
BaseRuntimeSettings. - Let
diwireauto-register settings as root-scoped singletons. Register a settings instance explicitly only for an intentional override. - At operational entrypoints, load required runtime values with
SettingsClass.from_environment(). Build explicit test or composition overrides withSettingsClass.model_validate({...})so strict type checking does not mistake raw input strings for already-validated field types. - Do not read
os.environoutside settings classes or composition code. - Use clear environment variable names and safe defaults only when safe.
- Type secret fields with
SecretStr, keep secrets out of examples, and unwrap them only at the adapter call that needs the raw value. - Update
.env.examplewhen adding user-provided environment variables. - Isolate settings-source tests from a developer's
.envby changing totmp_path, then override environment values withmonkeypatch. - Do not inherit raw
BaseSettings; inheritspecx.infrastructure.foundation.settings.BaseRuntimeSettings.
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 53 lines · 63 tokens per session scan A e3514ea4e047
specx-settings is a skill published in the GitHub repository maksimzayats/specx (201 stars, last pushed 1mo ago), licensed MIT. It adds 63 tokens to every session and 557 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
scaffold-archipy-domain
Scaffold a full ArchiPy domain slice (DTOs, errors, repository adapters, logic, service). Use when adding a new domain to an existing ArchiPy app.
scaffold-archipy-app
Scaffold a minimal ArchiPy application package (config, containers stub, domain slice, helpers tree, optional manage.py). Use when starting a new ArchiPy-based service or asking to bootstrap project layout.
scaffold-archipy-logic
Scaffold an ArchiPy logic class with unit-of-work decorator and domain DTO I/O. Use when adding a use-case under logics/{domain}/.
Python Clean Architecture
This skill should be used when the user asks to "scaffold a FastAPI project", "set up clean architecture", "refactor to clean architecture", "add a new endpoint", "add a router", "add an operation", "add a repository", "review my code structure", "apply design patterns in Python", "decouple my code", "improve code…
software-engineer-python
Auto-route to this skill if project contains.
python
Enforces FastAPI, Dependency Injection, and general Python coding standards based on the repository structure.