Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add opsmill/infrahub-mcp --skill speckit-reconcile-rungit clone --depth 1 https://github.com/opsmill/infrahub-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/opsmill/infrahub-mcp/speckit-reconcile-run)<a href="https://agentmods.dev/skills/opsmill/infrahub-mcp/speckit-reconcile-run"><img src="https://agentmods.dev/badge/skills/opsmill/infrahub-mcp/speckit-reconcile-run/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/opsmill/infrahub-mcp/speckit-reconcile-run"><img src="https://agentmods.dev/badge/skills/opsmill/infrahub-mcp/speckit-reconcile-run.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 3 findings, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Excessive Agency · line 76 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
- medium Rogue Agent · line 76 Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.Fix: Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent.
- medium Rogue Agent · line 151 Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.Fix: Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00023 | $0.01915 |
| Opus 5 | $0.00012 | $0.00958 |
| Sonnet 5 | $0.00005 | $0.00383 |
| Haiku 4.5 | $0.00002 | $0.00192 |
Grade A, and why
speckit-reconcile-run scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 193 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Act as the Chief Software Architect and Implementation Auditor. A feature implementation has landed, but "artifact drift" has been discovered (e.g., missing routes, updated behavior, or unlinked UI). Your goal is to reconcile this drift by surgically amending the feature's own specification, plan, and task artifacts.
User Input
$ARGUMENTS
Input Parsing
The input $ARGUMENTS is a Gap Report — a natural language description of what is missing or changed in the implementation versus the documentation.
Examples:
- "Backend + tests for Invoice Settings exist; React screen scaffolded. Users can't navigate to it. Need sidebar link + route."
- "The /api/v1/settings endpoint now requires an 'org_id' header not in the original plan."
If $ARGUMENTS contains any of these flags, respect them (optional):
--spec-only— update onlyspec.md--plan-only— update onlyplan.md--tasks-only— update onlytasks.md
If $ARGUMENTS is empty, output ERROR: No gap report provided. Usage: /speckit.reconcile.run [gap report text] and stop.
Step 0: Discovery & Setup (Gate)
0.1 Resolve Paths
Run .specify/scripts/bash/check-prerequisites.sh --json --paths-only --include-tasks to identify the active feature directory and its artifacts. This script is mandatory for path discovery. If the script is missing, stop and inform the user.
Derive absolute paths for:
FEATURE_DIR(e.g.,specs/###-feature-name/)FEATURE_SPEC(FEATURE_DIR/spec.md)IMPL_PLAN(FEATURE_DIR/plan.md)TASKS_FILE(FEATURE_DIR/tasks.md)
Validation: Ensure spec.md and plan.md exist. If either is missing, stop with:
⚠️ Missing required files in
FEATURE_DIR. Expected: spec.md, plan.md. Run/speckit.specifyand/speckit.planfirst.
If tasks.md does not exist, create it with a ## Remediation: Gaps heading before appending tasks.
0.2 Load Context
Read FEATURE_SPEC, IMPL_PLAN, and TASKS_FILE.
Also read .specify/memory/constitution.md if it exists. If found, extract MUST-level constraints and Architecture Standards. These are enforced in Step 1 — any remediation item that conflicts with a MUST principle is flagged as CRITICAL:
🔴 CONSTITUTION CONFLICT: [remediation item] conflicts with [principle]
→ This must be resolved in Step 2 clarification before edits proceed.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 193 lines · 23 tokens per session scan A 12c9f9eeff6e
speckit-reconcile-run is a skill published in the GitHub repository opsmill/infrahub-mcp (10 stars, last pushed today), licensed Apache-2.0. It adds 23 tokens to every session and 1,915 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
lambda-gpu-cloud
Safely inspect and operate Lambda Cloud GPU instances through the documented Cloud API and SSH, with explicit approval before billable or destructive actions.
tensorpool-gpu-cloud
Safely inspect and operate TensorPool GPU clusters and jobs using the current tp CLI, with explicit approval before any billable or destructive action.
runpod-gpu-cloud
Safely inspect and operate RunPod resources with runpodctl, live product data, and explicit approval before paid or destructive actions.
vast-ai-gpu-cloud
Safely inspect and operate Vast.ai marketplace instances with the vastai CLI, live offer data, and explicit approval before paid or destructive actions.
givemeanode-agent-compute
Operate GiveMeANode GPU nodes, batch jobs, storage, and rollout sandboxes through its connected MCP server with bounded spend, durable recovery, and explicit approval for paid or destructive actions.
gpt-image-gen
MUST read before generating images. Prompt-crafting guide for gpt-image-2.5 covering tool routing (native imagegeneration server tool vs the generateimage tool), model and quality selection, prompt structure, exact text rendering, reference-image editing, transparent assets, output formats, and multi-turn refinement.