Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add YuDefine/nuxt-supabase-starter --skill specformula-api-specgit clone --depth 1 https://github.com/YuDefine/nuxt-supabase-starterWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/yudefine/nuxt-supabase-starter/specformula-api-spec)<a href="https://agentmods.dev/skills/yudefine/nuxt-supabase-starter/specformula-api-spec"><img src="https://agentmods.dev/badge/skills/yudefine/nuxt-supabase-starter/specformula-api-spec/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/yudefine/nuxt-supabase-starter/specformula-api-spec"><img src="https://agentmods.dev/badge/skills/yudefine/nuxt-supabase-starter/specformula-api-spec.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00030 | $0.00604 |
| Opus 5 | $0.00015 | $0.00302 |
| Sonnet 5 | $0.00006 | $0.00121 |
| Haiku 4.5 | $0.00003 | $0.00060 |
Grade A, and why
specformula-api-spec scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
SpecFormula API Spec 撰寫指南
API Spec 使用 OpenAPI 3.0 格式,是 SpecFormula「規格三巨頭」之一。
SpecFormula 規範
1. summary 全域不可重複
summary 是 ApiCall 和 ResponseValidate 指令的識別依據,在整份 API Spec(含多檔案)中不可重複。使用「動詞 + 名詞」的業務語言命名:
# ✅ 正確
summary: 新增待辦事項
summary: 查詢待辦事項列表
summary: 查詢單一待辦事項
# ❌ 錯誤
summary: 查詢待辦事項 # 與上面重複,無法識別
summary: POST user # 避免技術用語
2. 檔案存放位置必須參考 isa.yml 配置檔
API Spec 的存放路徑由 isa.yml 的 config.api.resource_path 決定,撰寫前須先確認配置:
# isa.yml
config:
api:
resource_path: specs/api # ← 框架讀取路徑
project_path: my-project/src/test/resources/specs/api # ← Lint 報錯路徑
對應的檔案結構:
src/test/resources/specs/api/ # ← 與 resource_path 一致
├── api-spec.yml
├── auth-api.yml # 可拆分為多個檔案
└── ...
與 Feature 指令的對應
| Gherkin 元素 | API Spec 來源 |
|---|---|
新增待辦事項(summary) |
paths.*.*.summary |
| HTTP Method | 從 path 定義推斷 |
| URL Path | paths 的 key |
| Request Body 欄位 | requestBody.content.*.schema.properties |
Path 參數(P:) |
parameters[].in: path |
Query 參數(Q:) |
parameters[].in: query |
Header 參數(H:) |
parameters[].in: header |
| Response 欄位 | responses.*.content.*.schema.properties |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · -7 lines 92a1e4127aac
- yesterday First seen · 68 lines · 30 tokens per session scan A 5d92d5f8f47f
specformula-api-spec is a skill published in the GitHub repository YuDefine/nuxt-supabase-starter (45 stars, last pushed today), licensed MIT. It adds 30 tokens to every session and 604 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-10.
Other skills, from other repositories
nw-fp-domain-modeling
Domain modeling with algebraic data types, smart constructors, and type-level error handling.
nw-fp-hexagonal-architecture
Hexagonal architecture patterns with pure core and side-effect shell for functional codebases.
django-tdd
Django testing strategies with pytest-django, TDD methodology, factoryboy, mocking, coverage, and testing Django REST Framework APIs.
django-tdd
Django testing strategies with pytest-django, TDD methodology, factoryboy, mocking, coverage, and testing Django REST Framework APIs.
prd-v07-implementation-loop
Execute implementation within EPICs following test-first development, continuous SoT updates, and code traceability during PRD v0.7 Build Execution. Triggers on requests to start building, implement an epic, begin coding, or when user asks "start building", "implement epic", "coding", "development", "build execution"…
prd-v07-test-planning
Define test cases BEFORE implementation, ensuring every API, business rule, and user journey has verifiable acceptance criteria during PRD v0.7 Build Execution. Triggers on requests to define tests, plan test coverage, create test cases, or when user asks "define tests", "test planning", "what to test?", "test cases"…