Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add xiqin/loom --skill loom-detail-expansiongit clone --depth 1 https://github.com/xiqin/loomWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/xiqin/loom/loom-detail-expansion)<a href="https://agentmods.dev/skills/xiqin/loom/loom-detail-expansion"><img src="https://agentmods.dev/badge/skills/xiqin/loom/loom-detail-expansion/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/xiqin/loom/loom-detail-expansion"><img src="https://agentmods.dev/badge/skills/xiqin/loom/loom-detail-expansion.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00093 | $0.01796 |
| Opus 5 | $0.00046 | $0.00898 |
| Sonnet 5 | $0.00019 | $0.00359 |
| Haiku 4.5 | $0.00009 | $0.00180 |
Grade A, and why
loom-detail-expansion scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 147 lines — stays where its author put it; the contents beside it link to each section on GitHub.
行为义务展开(detail-expansion)
触发条件
specs/<date+feature>/spec.md与specs/<date+feature>/requirements.json已存在并经用户批准。requirements.json中某些 REQ 的behaviors仍为默认REQ-xxx-B01(happy-path 占位),未按需求types覆盖全部必需维度。- 即将进入
loom-writing-plans,需要先把每个 REQ 拆成可独立验证、可分配到 task 的行为义务。
非触发条件
requirements.json已显式覆盖每个 REQ 的所有required_categories,且每个 behavior 都有具体description与acceptance。- quickfix / chore / hotfix 等无 spec 的轻量流程。
执行流程
Step 0:运行校验
调用 loom MCP 工具 loom_detail_expansion_check(参数 spec_dir)。
工具会读取 requirements.json,对每个 REQ 检查:所有 required_categories 都有对应 behavior、每个 behavior 有 test_plan、无 requires-clarification 残留、description 非占位文案。返回 ok:false 表示有缺口需要补齐。
说明:
scripts/check-detail-expansion.mjs是该工具的实现,运行在 loom MCP 服务器进程内,可直接 import loom 仓库的 core 模块。不要在用户项目里用node skills/...调用(部署后路径会断裂)。
Step 1:读取现有账本
读取 specs/<date+feature>/spec.md、specs/<date+feature>/requirements.json、必要时的 specs/<date+feature>/handoffs/brainstorming.json。禁止重新展开用户已显式确定的 behavior;只补充缺失维度或细化占位 description。
Step 2:按需求类型确定必需维度
对每个 REQ,根据其 types 与 required_categories,合并出必须覆盖的 category 集合:
functional→happy-pathinput→invalid-inputauthorization/auth→authorizationwrite/mutation→atomicitystate→state-transitionidempotent→idempotencyconcurrent→concurrencyexternal→external-failuresecurity→securityperformance→performanceobservable→observabilityrecovery→recoveryforbidden-behavior:所有涉及写、权限、外部副作用或旧 API 的 REQ 都应额外考虑一个forbidden-behavior维度,用于"不应发生"的负空间。
Step 3:逐维度展开 Behavior Obligation
对每个必需维度,若 requirements.json 中没有对应 category 的 behavior,追加新的 REQ-xxx-Bnn:
id:递增Bnn,保持REQ-xxx-Bnn格式。category:固定维度之一。description:具体到可被代码实现与测试验证的单一行为。禁止"系统应正常"、"接口应稳定"等模糊描述。status:初始failing。acceptance:可测量、可观察的验收项列表。每个 acceptance 必须可由一个或多个测试用例证明,例如:- 正常路径:输入 X 时返回 Y,状态 Z 为 W。
- 边界:输入 N-1/0/N 时分别返回 A/B/C。
- 幂等:同一请求重复调用 K 次,副作用计数为 1。
- 失败回滚:外部依赖超时后,已写入的部分记录被回滚,数据库无脏数据。
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 147 lines · 93 tokens per session scan A f642eff1ec29
loom-detail-expansion is a skill published in the GitHub repository xiqin/loom (5 stars, last pushed 1mo ago), licensed MIT. It adds 93 tokens to every session and 1,796 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
research-engineer
An uncompromising Academic Research Engineer. Operates with absolute scientific rigor, objective criticism, and zero flair. Focuses on theoretical correctness, formal verification, and optimal implementation across any required technology.
tika-eval-compare
Compare extracts from two Tika builds over a corpus to detect regressions in content, encoding, exceptions, and embedded-document handling. Use for "compare before/after extracts", "eval this change against the corpus".
neuron-evaluation-engineer
Create and run AI evaluations with datasets, assertions, and output drivers in Neuron AI. Use this skill whenever the user mentions evaluation, testing AI systems, creating evaluators, dataset-driven testing, assertion-based validation, or wants to measure AI system performance. Also trigger for tasks involving…
jetson-validate-image
Use after jetson-flash-image to run static BSP checks, on-target smoke/regression tests on a flashed DUT, or both. Not for build or flash steps. Triggers: validate bsp, on-target validation.
atmos-validation
Validate Atmos projects, components, arbitrary JSON Schema inputs, EditorConfig, and GitHub Actions; use affected-file selection and native CI annotations.
skill-benchmark
Benchmark AI skill effectiveness by measuring implementation quality against legacy constraints.