Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/ronronner02/codepilot-agent/spec-doc-reviewnpx skills add ronronner02/codepilot-agent --skill spec-doc-reviewgit clone --depth 1 https://github.com/ronronner02/codepilot-agentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ronronner02/codepilot-agent/spec-doc-review)<a href="https://agentmods.dev/skills/ronronner02/codepilot-agent/spec-doc-review"><img src="https://agentmods.dev/badge/skills/ronronner02/codepilot-agent/spec-doc-review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00048 | $0.05770 |
| Opus 5 | $0.00024 | $0.02885 |
| Sonnet 5 | $0.00010 | $0.01154 |
| Haiku 4.5 | $0.00005 | $0.00577 |
Grade A, and why
spec-doc-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 196 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Document Review
Review requirements or plan documents through multi-persona analysis. Task packs are reviewed as derived, report-only execution inputs against their current source plan. Dispatches generic subagents seeded with skill-local reviewer prompt assets, applies safe_auto fixes only when the run-local mutation policy is markdown-write, and preserves the same structural/semantic review as report-only findings when mutation is unavailable or forbidden.
Workflow Contract Summary
- 输入: requirements、统一计划、legacy plan、task pack 或其他可读 spec artifact,及可选 roster/output/mutation 参数。
- 输出: 默认 report-only 的结构化文档 findings、coverage、改进建议与可选 JSON envelope;只有显式 apply 授权才可修改 Markdown。
- 硬出口: 文档不可读、flag 冲突、task-pack/source-plan 漂移、format/source owner 不明确,或 mutation authority 缺失时不得写入文档。
- 权威: 原文和 source refs 提供事实,persona/LLM 判断语义充分性;producer 拥有 derived artifact 修复,review 不继承 commit/landing authority。
- 消费者: 文档 owner、
spec-brainstorm、spec-plan、spec-write-tasks、spec-work与人工 reviewer。
Interactive mode rules
- Pre-load the platform question tool before any question fires. In Claude Code,
AskUserQuestionis deferred — callToolSearchwithselect:AskUserQuestiononce, eagerly, at the top of Interactive-mode work (before the routing question, walk-through, bulk-preview, and Phase 5 terminal question) rather than at the first question site. Other hosts don't need this preload. - The numbered-list fallback applies only when the harness genuinely lacks a blocking question tool (
ToolSearchno match, the call fails, or the mode doesn't expose it, e.g. Codex edit modes). A pending schema load is not a fallback trigger. In genuine-fallback cases present options as a numbered list and wait. Rendering a question as narrative text because the tool feels inconvenient, the model is mid-report, or the instruction was buried is a bug — a question that calls for a user decision must either fire the tool or fall back loudly, never slip past as prose.
What ships with it
31 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/bulk-preview.md 11 KB
- references/cross-model-eval.md 8.3 KB
- references/cross-model-review.md 2.2 KB
- references/document-classification-signals.md 2.8 KB
- references/findings-schema.json 4.9 KB
- references/open-questions-defer.md 10 KB
- references/persona-activation-matrix.md 4.0 KB
- references/personas/adversarial-document-reviewer.md 10 KB
- references/personas/coherence-reviewer.md 9.1 KB
- references/personas/design-lens-reviewer.md 4.5 KB
- references/personas/feasibility-reviewer.md 6.0 KB
- references/personas/product-lens-reviewer.md 9.0 KB
- references/personas/scope-guardian-reviewer.md 5.7 KB
- references/personas/security-lens-reviewer.md 4.5 KB
- references/personas/whole-doc-reviewer.md 3.0 KB
- references/rendering-floor.md 6.9 KB
- references/review-output-template.md 11 KB
- references/subagent-confidence-rubric-detail.md 3.6 KB
- references/subagent-suggested-fix-advanced.md 5.0 KB
- references/subagent-template.md 11 KB
- references/subagent-why-it-matters-guide.md 2.9 KB
- references/synthesis-and-presentation.md 24 KB
- references/synthesis-chain-linking.md 7.2 KB
- references/synthesis-contradictions.md 1.2 KB
- references/synthesis-multi-round.md 3.3 KB
- references/synthesis-premise-collapse.md 2.2 KB
- references/synthesis-restatement-suppression.md 2.0 KB
- references/task-pack-review-lens.md 6.9 KB
- references/walkthrough.md 30 KB
- scripts/cross-model-doc-review.sh 8.4 KB runs code
- scripts/peer-job-runner.py 86 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 196 lines · 48 tokens per session scan A cd7bbcb4838b
spec-doc-review is a skill published in the GitHub repository ronronner02/codepilot-agent (0 stars, last pushed 3d ago), licensed MIT. It adds 48 tokens to every session and 5,770 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
generate-ai-rules
Generate AI assistant configuration files for a repository — CLAUDE.md, AGENTS.md, and Cursor rules (.cursor/rules/.mdc) — from codebase analysis. Use whenever the user wants to create or update CLAUDE.md, AGENTS.md, agent rules, Cursor rules, AI coding assistant configuration, or "onboard AI tools" to a project, even…
generate-readme
Generate or refresh a comprehensive, professional README.md for a repository, with architecture overview, mermaid and optional C4 diagrams, repository structure, dependencies, and API documentation. Use whenever the user asks to create, write, update, improve, or regenerate a README, project documentation, or a…
analyze-codebase
Run a multi-agent deep analysis of a codebase, producing AI-readable analysis documents in .ai/docs/ covering structure, dependencies, data flow, request flow, and APIs. Use whenever the user asks to analyze a repository, generate codebase analysis, understand an unfamiliar codebase in depth, or before generating…
deploy-vercel-render
Deploy vpeetla-ai demos: Vercel static/Next.js frontends, Render FastAPI backends, env vars, free tier gotchas. Use when shipping demos, fixing deploy failures, or adding render.yaml / vercel.json.
langgraph-orchestration
Build or modify LangGraph StateGraph agents in vpeetla-ai repos: typed state, nodes, conditional edges, MemorySaver, interruptbefore HITL. Use when adding orchestrators, coding loops, or multi-agent graphs.
aegis-gateway
Integrate AegisAI gateway before tool side effects (notify, publish, deploy). Use when adding Slack/Telegram/WhatsApp notify, content publish, or any irreversible external action in VAP, AegisLoop, or ai-content-factory.