skill-spec-validator

A validator that compares a TASK document’s Requirements Traceability Matrix (a list linking requirements to identifiers) with a PLAN document’s implementation checklists.

In plain words
What is it for?
Use it to check TASK.md for a valid requirements matrix and PLAN.md for explicit coverage of every listed requirement.
Why use it?
It prevents requirements from disappearing between specification and planning, including mistakes where one requirement identifier is confused with another.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/matrixfounder/agentic-development/skill-spec-validator
Any agent
npx skills add MatrixFounder/Agentic-development --skill skill-spec-validator
Clone the repo
git clone --depth 1 https://github.com/MatrixFounder/Agentic-development

Made for: Claude Code, Codex.

Per session 23 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,054 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00023 $0.02054
Opus 5 $0.00012 $0.01027
Sonnet 5 $0.00005 $0.00411
Haiku 4.5 $0.00002 $0.00205

Measured 2d ago against content hash dd492f30cc9e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

skill-spec-validator scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

The scan reads SKILL.md. This mod also ships 8 executable files (scripts/tests/_fixtures.py, scripts/tests/run_tests.sh, scripts/tests/test_anchor.py, …), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.agent/skills/skill-spec-validator/SKILL.md · 127 lines

How it starts

The opening of the file, as written. The whole thing — 127 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Skill: Spec Validator

[!IMPORTANT] TIER 2 (High Integrity): This skill acts as a mechanical gatekeeper for the /vdd-enhanced workflow.

1. Purpose

To strictly enforce "Requirements Hardening" by mechanically verifying that:

  1. TASK.md contains a Requirements Traceability Matrix (RTM).
  2. PLAN.md explicitly covers every item in the RTM using Atomic Checklists.

2. Usage

Mode A: TASK Validation

Trigger: After Analysis Phase. Command:

python3 scripts/validate.py --mode task /absolute/path/to/docs/TASK.md

Checks:

  • Presence of an RTM heading (h2–h4), matched flexibly: ## Requirements Traceability [Matrix], ## N. ... (RTM), and the bare ### N. Requirements (RTM) form are all accepted.
  • Columns ID, Requirement.

Mode B: PLAN Validation

Trigger: After Planning Phase. Command:

python3 scripts/validate.py --mode plan /absolute/path/to/docs/PLAN.md /absolute/path/to/docs/TASK.md

Checks:

  • Every RTM ID in TASK appears as a whole token somewhere in PLAN — in a step heading (## Step 1 — ... (R1)) or a - [ ] R1 ... bullet. R1 does not satisfy R10.

3. Failure Handling

  • Exit Code 1: Issues found. Orchestrator should trigger a Correction Loop (instruct Analyst/Planner to fix).
  • Bypass: If validation is buggy, add the bypass token — BYPASS_VALIDATION in square brackets — to TASK.md.

    [!WARNING] The bypass is a bare substring test anywhere in TASK.md, so a spec that merely mentions the token switches its own gate off and prints Validation bypassed … with exit 0 — which reads like a pass. Write it only when you mean it (that is why this section spells the token out instead of quoting it). Pinned by a test, deliberately not "fixed": tightening it is a behavior change to a live gate.

4. Dependencies

  • Python 3 (stdlib only)
  • validate.py (in scripts/)

Execution Mode

  • Mode: script-first. The whole judgement is mechanical — two regex matchers and a table parser. Nothing here is prompt-side; if a matcher disagrees with an artifact, that is a finding for a human, not something to reason around.

Read the full file on GitHub · 127 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 127 lines · 23 tokens per session scan A dd492f30cc9e

Subscribe to this mod's changes

skill-spec-validator is a skill published in the GitHub repository MatrixFounder/Agentic-development (5 stars, last pushed 19d ago), licensed Apache-2.0. It adds 23 tokens to every session and 2,054 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

argent-tv-interact

Control and inspect TV apps via argent — Apple TV (tvOS), Android TV (leanback), and Amazon Fire TV (Vega). Boot the target, read focus, navigate with the D-pad remote, type, screenshot, and on Vega debug the JS runtime (evaluate, console logs, network inspector). Use when a task targets a TV (runtimeKind "tv", or…

software-mansion/argent · 107 tokens

review-offered-task

Review a task that has been offered to you and decide whether to accept or reject it.

desplega-ai/agent-swarm · 22 tokens

company-hiring-intelligence

Reverse-engineer what a company is building by scraping their job postings, careers page, LinkedIn Jobs, and engineering blog using TinyFish web agents. Use whenever a user wants to understand a company's strategic direction from hiring signals, do competitive intelligence, figure out a tech stack from job…

tinyfish-io/tinyfish-cookbook · 169 tokens

文档协作

引导用户通过结构化的文档共同编写工作流程。当用户想撰写文档、提案、技术规范、决策文档或类似结构化内容时使用。该工作流程帮助用户高效传递上下文,通过迭代优化内容,并验证文档对读者有效。当用户提到写文档、创建提案、起草规范或类似文档任务时触发。.

Tencent/WeKnora · 95 tokens

aidd-dev:08:for-sure

Iterative agent loop that tracks attempts and retries until a success condition is met. Use when the user says "for sure", "make sure", "keep trying until", "loop until done", "don't stop until", or needs guaranteed completion of a task with explicit success criteria.

ai-driven-dev/framework · 66 tokens

Swift Performance Optimization Skill

Use when investigating measured Swift or Apple-platform regressions in CPU, memory, launch, scrolling, animation hitches, image processing, energy, networking, or concurrency, or when designing performance tests and Instruments experiments. Do not use for speculative micro-optimization, ordinary refactoring, or a…

termio-sh/termio · 68 tokens