Home / komluk / scaffolding · skills/spec-review/SKILL.md · GitHub

spec-review skillA

spec-review is agent-read markdown (skill) from komluk/scaffolding: Verify an implementation against its OpenSpec artifacts. TRIGGER when: checking completed work against design.md and tasks.md. SKIP: security-specific review (use security-review-checklists); executing tasks (use spec-develop)..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# OpenSpec Verification

Guide for verifying that implementation matches spec artifacts.

## Input Files

| File | Required | Purpose |
|------|----------|---------|
| `{specs_path}/design.md` | Yes | Requirements and scenarios to verify |
| `{specs_path}/tasks.md` | Yes | Completion checklist |
| `{specs_path}/proposal.md` | Optional | Original intent reference |

**Path Enforcement**: The `specs_path` MUST be `.scaffolding/conversations/{UUID}/specs/` where `{UUID}` is a valid UUID (format: `xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx`). NEVER use descriptive folder names.

## Three Verification Dimensions

### 1. Completeness

**Question**: Are all tasks done and all requirements covered?

| Check | Method | Issue Level |
|-------|--------|-------------|
| All checkboxes marked `[x]` | Parse tasks.md | CRITICAL if incomplete |
| All requirements have code | Search codebase for keywords | CRITICAL if missing |
| All new files exist | Verify file paths from tasks | CRITICAL if missing |

### 2. Correctness

**Question**: Does the code do what the spec says?

| Check | Method | Issue Level |
|-------|--------|-------------|
…

Read the whole file at its exact version.

How to install

Latest version
mdr add komluk/scaffolding/spec-review@git:20260520.3aa374b
Exact content
mdr add komluk/scaffolding/spec-review@sha256:9a189e3e9092d94e

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_z2qvbor5zrkzla52.svg)](https://markdownregistry.com/a/art_z2qvbor5zrkzla52)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260520.3aa374b latest2026-05-20 3aa374b 4,108 BA view · diff
git:20260409.25dc3ca2026-04-09 25dc3ca 3,936 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (4108 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

komluk/scaffolding · 15 stars · license MIT · pushed 2026-09-21 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_z2qvbor5zrkzla52
GET https://markdownregistry.com/api/v1/resolve?ref=komluk/scaffolding/spec-review
GET https://markdownregistry.com/api/v1/blob/9a189e3e9092d94e6579851ff6e536d721b17ae2ba6d65210e86baa1c311300a

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from komluk/scaffolding

CLAUDE.md claude
komluk/scaffolding · CLAUDE.md
git:20260705.06a321d · audit A · 15 stars
agent-comms skill
komluk/scaffolding · skills/agent-comms/SKILL.md · SendMessage recipient validation and worktreePath safety (CWE-59). TRIGGER when: validating a SendMessage `to:`…
git:20260705.958c030 · audit A · 15 stars
agent-memory skill
komluk/scaffolding · skills/agent-memory/SKILL.md · 3-tier markdown memory protocol (shared/agent/conversation) for cross-session knowledge. TRIGGER when: reading or…
git:20260606.ad5816e · audit A · 15 stars
api-design skill
komluk/scaffolding · skills/api-design/SKILL.md · RESTful API design standards: resource naming, HTTP methods, status codes, pagination, versioning. TRIGGER when…
git:20260520.3aa374b · audit A · 15 stars
context-engineering skill
komluk/scaffolding · skills/context-engineering/SKILL.md · Optimize Claude Code context-window usage for accuracy and cost. TRIGGER when: hitting context limits, structuring…
git:20260627.c37d831 · audit A · 15 stars
database-optimization skill
komluk/scaffolding · skills/database-optimization/SKILL.md · Schema design, index strategy, migration safety, and query analysis. TRIGGER when: designing tables or indexes, writing…
git:20260614.9d809af · audit A · 15 stars
distill skill
komluk/scaffolding · skills/distill/SKILL.md · Knowledge distillation methodology: candidate extraction, confidence scoring, tier routing, conversation-scoped mode…
git:20260702.49d89e4 · audit A · 15 stars
docker-templates skill
komluk/scaffolding · skills/docker-templates/SKILL.md · Docker multi-stage build templates, image security, and docker-compose patterns. TRIGGER when: writing a Dockerfile…
git:20260520.3aa374b · audit A · 15 stars
error-handling skill
komluk/scaffolding · skills/error-handling/SKILL.md · Consistent error handling across frontend and backend layers. TRIGGER when: implementing error boundaries, exception…
git:20260614.9d809af · audit A · 15 stars
git-operations skill
komluk/scaffolding · skills/git-operations/SKILL.md · Git command patterns, branching strategy, and safety protocols. TRIGGER when: managing branches, resolving merge…
git:20260627.c37d831 · audit A · 15 stars
github-actions-template skill
komluk/scaffolding · skills/github-actions-template/SKILL.md · GitHub Actions CI pipeline templates and workflow YAML patterns. TRIGGER when: creating or editing a CI workflow…
git:20260520.3aa374b · audit A · 15 stars
logging-standards skill
komluk/scaffolding · skills/logging-standards/SKILL.md · Structured logging standards: log levels, structured fields, correlation IDs, PII masking, and event naming. TRIGGER…
git:20260627.c37d831 · audit A · 15 stars

Every file in komluk/scaffolding

Other files named spec-review

spec-review skill
hhu3637kr/skills · spec-review/SKILL.md · 审查 Spec 执行完成情况,检验实现是否严格按照 Spec 执行,识别未完成项和不符项,在 reviewer/ 下生成审查报告(review.html)。在 spec-execute 完成 executor/summary.html…
git:20260923.a4b35af · audit A · 145 stars
spec-review skill
insajin/autopus-adk · .omp/skills/spec-review/SKILL.md · Multi-provider SPEC review gate skill
git:20260902.afc4b94 · audit A · 111 stars
spec-review skill
vibeic/vibe-ic · vibe-ic-marketplace/plugins/vibe-ic/skills/spec-review/SKILL.md · Review a natural-language hardware specification for ambiguity, internal inconsistency, untestable statements, and…
git:20260613.86cacb4 · audit A · 26 stars
spec-review skill
rizwanzafaris/product-manager-os · skills/spec-review/SKILL.md · Read any written spec, PRD, BRD, FRD, NFR, one-pager, business rules register, acceptance criteria, or epic and story…
git:20260919.72235e0 · audit A · 4 stars

Browse by kind, by grade A, or by owner.