Spec Kitty is an open-source command-line tool that turns product requirements into a repository-based workflow for AI-assisted software development. It stores specifications, plans, tasks, acceptance criteria, reviews, and merge decisions in Git while giving agents isolated git worktrees for parallel implementation. The catalogue add-ons support the project's workflows for coordinating agents and governing their work.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Priivacy-ai/spec-kitty --skill spk-run-blocked-recoverygit clone --depth 1 https://github.com/Priivacy-ai/spec-kittyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/priivacy-ai/spec-kitty/spk-run-blocked-recovery)<a href="https://agentmods.dev/skills/priivacy-ai/spec-kitty/spk-run-blocked-recovery"><img src="https://agentmods.dev/badge/skills/priivacy-ai/spec-kitty/spk-run-blocked-recovery/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/priivacy-ai/spec-kitty/spk-run-blocked-recovery"><img src="https://agentmods.dev/badge/skills/priivacy-ai/spec-kitty/spk-run-blocked-recovery.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00031 | $0.00195 |
| Opus 5 | $0.00015 | $0.00097 |
| Sonnet 5 | $0.00006 | $0.00039 |
| Haiku 4.5 | $0.00003 | $0.00019 |
Grade A, and why
spk-run-blocked-recovery scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
spk-run-blocked-recovery
Use this skill when next, review, accept, merge, sync, or dashboard output
shows a blocker.
Flow
- Capture the exact command and blocker output.
- Classify the blocker: missing artifact, invalid state, guard failure, worktree/git issue, sync issue, auth issue, or user decision required.
- Use the nearest specialist skill: setup doctor, git workflow, team sync, review, accept, or merge.
- Make one repair, rerun the same command, and compare output.
- Escalate to the user only when the command requires a product decision or external credential.
Rule
Do not bypass a guard. Resolve the reason the guard exists.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 25 lines · 31 tokens per session scan A ccf960cf27f5
spk-run-blocked-recovery is a skill published in the GitHub repository Priivacy-ai/spec-kitty (1,603 stars, last pushed 5d ago), licensed MIT. It adds 31 tokens to every session and 195 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
performance-optimization
Spring Boot 4 / JVM performance work — measure first, then fix. Profiling (async-profiler, JFR, JMH), Micrometer, common Spring antipatterns (N+1, unbounded lists, HikariCP sizing, virtual-thread pinning), caching, GC, and SLO-driven work. Used by /plan for risk callouts and by /review to flag perf regressions.
debugging-and-error-recovery
Use when encountering unexpected behavior, crashes, or test failures in Android. Six-step triage from reproduction to regression guard, using Logcat, Android Studio debugger, and profiling tools.
tencentcloud-cls
Search and analyze Tencent Cloud CLS (Cloud Log Service) logs. Use whenever the user asks to: search logs, debug API errors, trace requests by trace ID, find 5xx errors, run CQL/SQL analytics over log topics, extract structured fields. Backed by the official tencentcloud-sdk-python CLS client.
qa-triage
Analyze test failures from any domain, categorize by severity and type, identify root causes, and produce a structured triage report with recommended owners and next actions. Use after any test run that produced failures.
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
find-bugs
Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.