Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add opsmill/infrahub-mcp --skill speckit-tinyspec-implementgit clone --depth 1 https://github.com/opsmill/infrahub-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/opsmill/infrahub-mcp/speckit-tinyspec-implement)<a href="https://agentmods.dev/skills/opsmill/infrahub-mcp/speckit-tinyspec-implement"><img src="https://agentmods.dev/badge/skills/opsmill/infrahub-mcp/speckit-tinyspec-implement/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/opsmill/infrahub-mcp/speckit-tinyspec-implement"><img src="https://agentmods.dev/badge/skills/opsmill/infrahub-mcp/speckit-tinyspec-implement.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00021 | $0.00838 |
| Opus 5 | $0.00010 | $0.00419 |
| Sonnet 5 | $0.00004 | $0.00168 |
| Haiku 4.5 | $0.00002 | $0.00084 |
Grade A, and why
speckit-tinyspec-implement scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 88 lines — stays where its author put it; the contents beside it link to each section on GitHub.
TinySpec Implement
Implement a small change by following the plan and tasks in its tinyspec file. Works like /speckit.implement but optimized for single-file specs — reads one document, executes the tasks, and marks them complete.
User Input
$ARGUMENTS
You MUST consider the user input before proceeding (if not empty). The user may specify which tinyspec to implement (e.g., "logout-button") or a path to the tinyspec file.
Prerequisites
- Verify a spec-kit project exists by checking for
.specify/directory - Verify git is available and the project is a git repository
- Locate the tinyspec file:
- If user specifies a name, look for
specs/tiny/{name}.md - If no input, look for the most recently created tinyspec in
specs/tiny/ - If no tinyspec files exist, suggest running
/speckit.tinyspecfirst
- If user specifies a name, look for
Outline
-
Read the tinyspec: Parse the tinyspec file to extract:
- Context files: Files listed in the Context table
- Requirements: The numbered requirements list
- Plan: The ordered implementation steps
- Tasks: The checkbox task list
- Done When: The completion criteria
-
Read context files: Load all files listed in the Context table to understand:
- Current code structure and patterns
- Existing imports and dependencies
- Test patterns and conventions
-
Execute tasks: Work through the task list in order:
- For each task, follow the corresponding plan step
- Implement the change in the identified file
- Follow existing code patterns and conventions from context files
- Mark each task as
[x]in the tinyspec file after completion
-
Run verification: After all tasks are complete:
- Check that all "Done When" criteria are met
- Verify tests pass (if test tasks were included)
- Verify no lint errors (if linting is configured)
-
Update tinyspec: Mark the tinyspec as complete:
- Change
**Status**: draftto**Status**: done - All task checkboxes should be
[x] - All "Done When" checkboxes should be
[x]
- Change
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 88 lines · 21 tokens per session scan A 4d59702953b8
speckit-tinyspec-implement is a skill published in the GitHub repository opsmill/infrahub-mcp (10 stars, last pushed today), licensed Apache-2.0. It adds 21 tokens to every session and 838 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
tmux
Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output. Use when: (1) monitoring Claude/Codex sessions running in tmux, (2) sending input to interactive terminal applications, (3) scraping output from long-running processes inside tmux, (4) navigating tmux panes/windows…
tensorpool-gpu-cloud
Safely inspect and operate TensorPool GPU clusters and jobs using the current tp CLI, with explicit approval before any billable or destructive action.
lambda-gpu-cloud
Safely inspect and operate Lambda Cloud GPU instances through the documented Cloud API and SSH, with explicit approval before billable or destructive actions.
runpod-gpu-cloud
Safely inspect and operate RunPod resources with runpodctl, live product data, and explicit approval before paid or destructive actions.
vast-ai-gpu-cloud
Safely inspect and operate Vast.ai marketplace instances with the vastai CLI, live offer data, and explicit approval before paid or destructive actions.
agent-initialization
Initialize an Agent's settings from a user requirement by writing AGENTS.md, setting identity metadata, and installing only needed Skills.