Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add pivoshenko/pivoshenko.ai --skill spec-applygit clone --depth 1 https://github.com/pivoshenko/pivoshenko.aiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pivoshenko/pivoshenko.ai/spec-apply)<a href="https://agentmods.dev/skills/pivoshenko/pivoshenko.ai/spec-apply"><img src="https://agentmods.dev/badge/skills/pivoshenko/pivoshenko.ai/spec-apply/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/pivoshenko/pivoshenko.ai/spec-apply"><img src="https://agentmods.dev/badge/skills/pivoshenko/pivoshenko.ai/spec-apply.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00188 | $0.03119 |
| Opus 5.5 | $0.00075 | $0.01248 |
| Sonnet 5.5 | $0.00038 | $0.00624 |
| Haiku 4.5 | $0.00019 | $0.00312 |
Grade A, and why
spec-apply scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 183 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Spec Apply
task queue -> wave plan -> agents -> verify -> tick -> commit -> repeat.
/opsx:apply walks tasks one at a time in one context and never touches git. This replaces that loop only: the same OpenSpec mechanics, run in parallel, plus the commit seam it leaves out. Planning artifacts stay sequential and belong to spec-propose - never author one here.
Substrate-independent. Inside Herdr (HERDR_ENV=1) workers are panes and the mechanics belong to herdr-dispatch; outside it they are Agent tool subagents. This skill owns only what is spec-specific, including the per-task worktree isolation in Isolation, which no substrate provides on its own.
Preflight
openspec context --json
no_openspec_root -> stop. Offer openspec init --tools claude and wait for the user. Never auto-init, never fall back to the current directory. Use the returned root.path as authoritative.
.claude/commands/opsx/apply.md exists -> the OpenSpec mechanics are its job; invoke it and own only the git seam. Absent -> drive the openspec CLI directly.
The user naming a store -> openspec store list --json for ids, then --store <id> on every command that accepts it, sticky for the rest of the run.
Change selection: a name given -> use it. Exactly one active change -> select it and say so. Ambiguous -> openspec list --json and ask. Either way, announce which change is in use and how to override it. Why -> every command here takes --change and operates on whatever it is handed without complaint, so announcing it is the only moment the user can catch a wave aimed at the wrong change before agents start writing files.
Flow
- Read the apply state:
openspec instructions apply --change "<name>" --jsonstate: "blocked"-> required artifacts are missing; send the user tospec-proposeand stop. Never author artifacts here.state: "all_done"-> nothing left to apply; send them tospec-verify.ready-> continue, and keepprogressandcontextFiles - Read
tasks.mditself, at the path fromcontextFiles.tasks. Key every task on theN.Mlabel parsed out of the file text. See The Queue JSON Is Lossy - Any unticked task without
files:andneeds:-> stop. See Markers - Plan the wave: unticked tasks whose
needs:are all ticked and whosefiles:sets are pairwise disjoint. Cap at what you can brief and verify in one pass; everything else waits. See Waves - Isolate first, then dispatch one agent per task, all launched together, each briefed into its own worktree path. See Isolation and Brief
- Collect, verify, tick, commit - per task, in that order, no reordering. See Collect, Verify, Tick, Commit
- Wave done -> re-read step 1 AND
tasks.mdfrom disk, then plan the next wave. Never an in-memory copy. Why -> workers mutate the tree under you and a merged task branch changes what is ticked, so a stale queue plans a wave against a file layout that no longer exists remaining: 0-> hand off tospec-verify. Never archive here and never open the PR here - both arespec-archive's
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago Changed · -16 lines 8668c5d2d905
- 13d ago First seen · 199 lines · 188 tokens per session scan A 0b5ec82ff230
spec-apply is a skill published in the GitHub repository pivoshenko/pivoshenko.ai (6 stars, last pushed 2d ago), licensed MIT. It adds 188 tokens to every session and 3,119 once invoked, about $0.0008 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-16.
Other skills, from other repositories
comet-safe-delivery
A Chinese-language procedure for safely delivering specified Comet changes through Git. It covers checking worktrees and unrelated edits, staging exact files, validating hooks, and authorized commits or pushes.
ac-commit-manager
Manage git commits for autonomous coding. Use when committing feature implementations, creating descriptive commits, managing git workflow, or handling version control.
agent-commit
Analyze changes and create a meaningful commit with agent authorship. Internal skill for evolveloop.
loom-git-workflow
Git operations guidance including branching strategies, commit conventions, merge workflows, conflict resolution, and worktree management.
conventional-commit
Generer conventional commit-meldinger med Nav-relevante scopes og breaking change-format.
git-commit
Safely create a git commit by validating repository state, staging intended changes, scanning for secrets/conflicts, generating a Conventional Commits message (repository convention first, else an English Angular default) from the staged diff, and committing without amend.