sdcorejs-spec

A specification-writing guide for turning confirmed requirements into an approved, stored project specification. A specification records what should be built and why, while a plan records which files to change and in what order.

In plain words
What is it for?
Use it after requirements are confirmed, or when drafting, reviewing, approving, or changing an sdcorejs specification.
Why use it?
It creates a durable requirements record and adds checks for decisions, architecture, approval identity, revision history, blockers, and planning gaps. It prevents implementation from starting with an unreviewed contract.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/sdcorejs/sdcorejs-agent/sdcorejs-spec
Any agent
npx skills add sdcorejs/sdcorejs-agent --skill sdcorejs-spec
Clone the repo
git clone --depth 1 https://github.com/sdcorejs/sdcorejs-agent

Made for: Claude Code, Codex.

Per session 88 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,338 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00088 $0.04338
Opus 5 $0.00044 $0.02169
Sonnet 5 $0.00018 $0.00868
Haiku 4.5 $0.00009 $0.00434

Measured 2d ago against content hash 3a68f9b4ae7c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

sdcorejs-spec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/sdcorejs-spec/SKILL.md · 455 lines

How it starts

The opening of the file, as written. The whole thing — 455 lines — stays where its author put it; the contents beside it link to each section on GitHub.

02 - Spec

Shared Protocols

Read _refs/shared/runtime-protocols.md. Draft and approved spec artifacts apply _refs/shared/artifact-lifecycle.md and emit artifact_context. Resolve track/profile/repository semantics from _refs/shared/system-registry.json. Create and verify every approval identity with the executable _refs/shared/approved-artifact.mjs helper. Read _refs/shared/decision-coverage.md, validate decision_coverage at the spec stage with _refs/shared/decision-coverage.mjs, and preserve its stable IDs, revision history, blockers, and future planning gaps. Read _refs/sdlc/architecture.md and classify the post-spec conditional gate with classifyArchitectureGate from _refs/shared/architecture-contract.mjs. The spec records the classification; it does not author the architecture artifact.

Purpose

Turn the confirmed requirement contract into a durable spec, hold the user approval gate, and persist the approved spec corpus inside the same skill.

A spec answers what and why. A plan answers which files and in what order.

Preconditions

  • sdcorejs-brainstorming has confirmed the minimum blockers and emitted requirement_context, or the conversation already contains an equivalent complete requirement set with explicit decisions, assumptions, target root, target root kind, track, stack profile, and acceptance criteria seed.
  • Target root and context/track are known.
  • owner_repository_id, owner_repository_role, optional owner_module_id, and execution_host_repository_id are resolved from semantic topology rather than the current working directory.
  • For non-trivial code/test generation, do not proceed from an unconfirmed idea.

If these are missing, route back to sdcorejs-brainstorming. If the semantic owner repository is unavailable or not writable, block. Do not write a module spec into the portal as a fallback.

Before drafting, apply _refs/shared/project-context.md with:

Read the full file on GitHub · 455 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 455 lines · 88 tokens per session scan A 3a68f9b4ae7c

Subscribe to this mod's changes

sdcorejs-spec is a skill published in the GitHub repository sdcorejs/sdcorejs-agent (2 stars, last pushed 15d ago), licensed MIT. It adds 88 tokens to every session and 4,338 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

brainstorming

You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.

obra/superpowers · 37 tokens

chat-pet-sprite-creation

Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.

microsoft/vscode · 53 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

agent-host-chat-contributions

Build and review cross-cutting agent-host chat behavior through lifecycle contributions. Use when adding turn lifecycle side effects, prompt or context injection, restored-history transformation, protocol-action observation, or when reviewing changes that add code to AgentSideEffects or AgentService.

microsoft/vscode · 56 tokens

auto-perf-optimize

Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.

microsoft/vscode · 62 tokens