Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add opsmill/infrahub-mcp --skill speckit-tinyspec-tinyspecgit clone --depth 1 https://github.com/opsmill/infrahub-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/opsmill/infrahub-mcp/speckit-tinyspec-tinyspec)<a href="https://agentmods.dev/skills/opsmill/infrahub-mcp/speckit-tinyspec-tinyspec"><img src="https://agentmods.dev/badge/skills/opsmill/infrahub-mcp/speckit-tinyspec-tinyspec/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/opsmill/infrahub-mcp/speckit-tinyspec-tinyspec"><img src="https://agentmods.dev/badge/skills/opsmill/infrahub-mcp/speckit-tinyspec-tinyspec.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00028 | $0.00995 |
| Opus 5 | $0.00014 | $0.00498 |
| Sonnet 5 | $0.00006 | $0.00199 |
| Haiku 4.5 | $0.00003 | $0.00100 |
Grade A, and why
speckit-tinyspec-tinyspec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 114 lines — stays where its author put it; the contents beside it link to each section on GitHub.
TinySpec
Generate a single lightweight specification file for small tasks that don't warrant the full SDD workflow. Combines context, requirements, implementation plan, and tasks into one concise document — minimal overhead, maximum clarity.
User Input
$ARGUMENTS
You MUST consider the user input before proceeding (if not empty). The user describes the small change they want to make (e.g., "add a logout button to the navbar", "fix the date format in the invoice PDF", "add input validation to the signup form").
Prerequisites
- Verify a spec-kit project exists by checking for
.specify/directory - Verify git is available and the project is a git repository
- Verify the user has described the change (if not, ask what they want to build)
Outline
-
Assess scope: Quickly evaluate whether this task is appropriate for tinyspec:
- Good fit: Single feature, bug fix, UI tweak, config change, small refactor — anything that touches 1-5 files and takes under ~1 hour
- Bad fit: Multi-module features, architectural changes, new services, database schema redesigns — recommend full
/speckit.specifyinstead - If the task seems too large, warn the user and suggest the full workflow
-
Identify affected files: Scan the codebase to determine:
- Which files will be modified (list them explicitly)
- Which files provide context (imports, types, related components)
- Which test files will need updates
-
Generate tinyspec file: Create a single file at
specs/tiny/{feature-name}.mdwith this structure:# TinySpec: {Title} **Branch**: {current-branch or new-branch-name} **Date**: {YYYY-MM-DD} **Status**: draft **Complexity**: small ## What {1-3 sentence description of what this change does and why} ## Context | File | Role | |------|------| | `src/components/Navbar.tsx` | Will be modified — add logout button | | `src/hooks/useAuth.ts` | Context — provides logout function | | `src/components/Navbar.test.tsx` | Will be modified — add test for logout | ## Requirements 1. {Requirement 1 — clear, testable} 2. {Requirement 2} 3. {Requirement 3} ## Plan 1. {Step 1 — what to change and where} 2. {Step 2} 3. {Step 3} ## Tasks - [ ] {Task 1} - [ ] {Task 2} - [ ] {Task 3} - [ ] {Test task} ## Done When - [ ] All tasks checked off - [ ] Tests pass - [ ] No lint errors
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 114 lines · 28 tokens per session scan A 8f69b6bf9c2c
speckit-tinyspec-tinyspec is a skill published in the GitHub repository opsmill/infrahub-mcp (10 stars, last pushed yesterday), licensed Apache-2.0. It adds 28 tokens to every session and 995 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
stale-sweep
Sweep the googleapis/mcp-toolbox repo for issues and PRs with no real activity in N days (default 60), sort each by whose silence it is (the author's, ours, or nobody's), and draft the nudge or close comment. Use whenever a maintainer asks for a stale sweep, backlog cleanup, or an SLO check, e.g. "stale sweep", "find…
linear-tickets
Create or update high-quality Linear tickets while preserving the originating report, diagnostic links, attachments, and reporter/requester attribution. Read this whenever someone asks to create, recreate, or update a Linear issue.
lambda-gpu-cloud
Safely inspect and operate Lambda Cloud GPU instances through the documented Cloud API and SSH, with explicit approval before billable or destructive actions.
tensorpool-gpu-cloud
Safely inspect and operate TensorPool GPU clusters and jobs using the current tp CLI, with explicit approval before any billable or destructive action.
runpod-gpu-cloud
Safely inspect and operate RunPod resources with runpodctl, live product data, and explicit approval before paid or destructive actions.
vast-ai-gpu-cloud
Safely inspect and operate Vast.ai marketplace instances with the vastai CLI, live offer data, and explicit approval before paid or destructive actions.