Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/t1djani/servo/shape-specnpx skills add t1djani/servo --skill shape-specgit clone --depth 1 https://github.com/t1djani/servoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/t1djani/servo/shape-spec)<a href="https://agentmods.dev/skills/t1djani/servo/shape-spec"><img src="https://agentmods.dev/badge/skills/t1djani/servo/shape-spec.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00050 | $0.00498 |
| Opus 5 | $0.00025 | $0.00249 |
| Sonnet 5 | $0.00010 | $0.00100 |
| Haiku 4.5 | $0.00005 | $0.00050 |
Grade A, and why
shape-spec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
shape-spec
Turn a decided design into a spec that the rest of the flow can trust. A good servo spec is not just a description; it carries the means to check itself. Two moves make that happen.
The two moves
-
Embed the invariants inline (constrain). Whatever the work must never break — pulled from the
invariantsoracle and the relevant experts — is written into the spec as an explicit list, not left implicit. A constraint that is physically present in the document cannot be silently forgotten downstream. -
Name the oracles (point, do not freeze). The spec declares which sources it will be judged against —
scope,invariants,acceptance,prior-art— by reference, so they stay fresh. (A plan, later, will snapshot its acceptance target instead; a spec evolves, so it points.)
Procedure
- Start from the context brief (
gather-context) and the decided forks (expert-panel). Do not re-open settled decisions here. - Write the spec. State the goal, the approach, and the scope — including what is explicitly out of scope.
- Add an Invariants section. List, inline, what must not break, each tagged with the oracle/expert it came from.
- Add an Oracles section. Name the manifest keys this spec will be gated against.
- Gate the spec. Run
servo-gateon the spec, once per relevant oracle: againstinvariants(does it violate any?),scope(does it match the intent, no creep?),prior-art(does it ignore or contradict what exists?),footguns(does it walk into a known trap?). Fix what comes backFIX/STOP; do not proceed on an open finding.
Rule
The spec is the last place divergence is allowed. After it, the plan is pure convergence. If a real fork is still open, go back to expert-panel — do not bury the choice in the spec for the plan to trip over.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 27 lines · 50 tokens per session scan A b4c6b1e9f430
shape-spec is a skill published in the GitHub repository t1djani/servo (1 stars, last pushed 2mo ago), licensed MIT. It adds 50 tokens to every session and 498 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
quiz-me
Quiz the user on root cause and intended fix BEFORE writing any non-trivial code, then verify comprehension of every change after. Use when the user asks for a bug fix, refactor, or feature and wants to stay technically sharp instead of vibe-coding. Also use when the user says "quiz me", "don't let me vibe code", or…
website-deploy-builder
Plan what to build on Website Deploy (simple-host.app). Helps a user decide whether their idea fits the static + light-backend model, maps it to concrete patterns (shared JSON state with atomic ops, append-only collections, private/password-locked pages on a custom domain, drop-in comments/feedback widgets…
connect-domain
Connect a user's own custom domain (subdomain e.g. recipes.brand.com via CNAME, or apex e.g. brand.com via A record) to a site already deployed on simple-host. Use when a user wants their site served from their own domain with automatic HTTPS, or wants a private/password-protected site (privacy is offered only on a…
personal-voice-capture
Use when a user wants an agent to learn, encode, or improve their personal writing voice as a reusable skill through source-text ingestion and iterative calibration edits.
demo-video-factory
Generate a custom 26s product-demo video from any SaaS URL — brand-matched scenes, a recreated product-UI "wow" scene, real screenshots, and a soundtrack. Use whenever the user wants a demo, promo, launch, or marketing video for a website or product.
website-deploy
Deploy static websites to simple-host.app. Use when an agent needs to guide a user through registration, build/validate a static site, deploy it (inline JSON files OR a tar.gz/zip archive), or wire up the per-site backend — shared JSON state with atomic ops, append-only collections, private (password-locked) pages on…