Spec Kitty is an open-source command-line tool that turns product requirements into a repository-based workflow for AI-assisted software development. It stores specifications, plans, tasks, acceptance criteria, reviews, and merge decisions in Git while giving agents isolated git worktrees for parallel implementation. The catalogue add-ons support the project's workflows for coordinating agents and governing their work.
Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Priivacy-ai/spec-kitty --skill spk-run-review-wpgit clone --depth 1 https://github.com/Priivacy-ai/spec-kittyWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/priivacy-ai/spec-kitty/spk-run-review-wp)<a href="https://agentmods.dev/skills/priivacy-ai/spec-kitty/spk-run-review-wp"><img src="https://agentmods.dev/badge/skills/priivacy-ai/spec-kitty/spk-run-review-wp/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/priivacy-ai/spec-kitty/spk-run-review-wp"><img src="https://agentmods.dev/badge/skills/priivacy-ai/spec-kitty/spk-run-review-wp.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00026 | $0.00275 |
| Opus 5 | $0.00013 | $0.00138 |
| Sonnet 5 | $0.00005 | $0.00055 |
| Haiku 4.5 | $0.00003 | $0.00028 |
Grade A, and why
spk-run-review-wp scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
spk-run-review-wp
Use this skill when the user asks to review a WP, approve/reject work, or operate the review workflow surface.
Flow
- Claim or select the WP from the runtime/review output.
- Compare implementation against WP scope, spec, plan, and acceptance checks.
- Approve only when behavior and verification satisfy the WP.
- Reject with concrete, actionable feedback and affected files or commands.
- Let
spk-run-implement-reviewcontinue the loop.
Recording the verdict
Capture the approve/reject decision through the deterministic event-log seam described in
spk-run-verdict-capture — the review_result event in status.events.jsonl is the sole
authority (the review-cycle-N.md render is non-authoritative). In practice:
spec-kitty agent tasks move-task <WP> --to approved to approve, or --to planned --review-feedback-file <f> to reject. Never hand-edit the .md render to change a verdict.
Legacy Alias
For detailed review command behavior, use spec-kitty-runtime-review when
available.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 31 lines · 26 tokens per session scan A b8379d6cbffd
spk-run-review-wp is a skill published in the GitHub repository Priivacy-ai/spec-kitty (1,603 stars, last pushed 4d ago), licensed MIT. It adds 26 tokens to every session and 275 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
clarity-over-cleverness
Apply clarity-over-cleverness rewrites — prefer code a junior engineer can read at a glance over compact-but-clever code. Use during /build's simplify step and during /code-simplify (alias "simplify the code"). Never weakens behavior; suite must remain green.
spring-code-review-rubric
Pre-commit code review rubric for Spring Boot 4 changes. Used by spring-code-reviewer to produce 08-code-review.md before any commit. Covers traceability, architecture, Spring idioms, error handling, data access, security, test quality, clarity, and migration.
6_gofer_validate
Validate implementation with 10-category engineering rubric (100 points).
enforcement-audit
Run a compliance audit against a technology instruction file, detecting discrepancies, planning workstreams, implementing fixes, and validating quality gates.
spec-to-code-compliance
Check code against the documentation that specifies it - which requirements hold, which the code contradicts, which are absent, and what the code does that no document mentions. Use when comparing an implementation against a whitepaper, protocol spec, or design document.
code-review
Run a structured Spec Kit review focused on code compliance, documentation quality, or test coverage, positioned within the spec-driven development pipeline.