agent-comms
SendMessage recipient validation and worktreePath safety (CWE-59). TRIGGER when: validating a SendMessage `to:` recipient against the agent whitelist, or a…
Write OpenSpec design.md and tasks.md artifacts. TRIGGER when: producing a technical design or task checklist for a spec-driven feature. SKIP: writing proposal.md (use spec-research); executing tasks.md (use spec-develop).
$ npx -y skills add komluk/scaffolding --skill spec-design --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/spec-designContext preview
The summary Claude sees to decide when to auto-load this skill.
Write OpenSpec design.md and tasks.md artifacts. TRIGGER when: producing a technical design or task checklist for a spec-driven feature. SKIP: writing proposal.md (use spec-research); executing tasks.md (use spec-develop).
name: spec-design description: "Write OpenSpec design.md and tasks.md artifacts. TRIGGER when: producing a technical design or task checklist for a spec-driven feature. SKIP: writing proposal.md (use spec-research); executing tasks.md (use spec-develop)."
Guide for creating `design.md` (WHAT + HOW) and `tasks.md` (implementation checklist).
Read `{specs_path}/proposal.md` first. Reference its capabilities and impact sections.
**Path Enforcement**: The `specs_path` MUST be `.scaffolding/conversations/{UUID}/specs/` where `{UUID}` is a valid UUID (format: `xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx`). NEVER use descriptive folder names.
Write to: `{specs_path}/design.md`
| Section | Purpose | Format | |---------|---------|--------| | **Context** | Background, current state, constraints | Prose | | **Goals / Non-Goals** | Scope boundaries | Bullet lists | | **Specifications** | Requirements + scenarios | GIVEN/WHEN/THEN | | **Decisions** | Technical choices + rationale | Decision: Why X over Y | | **Risks / Trade-offs** | Known limitations | [Risk] -> Mitigation | | **Migration Plan** | Deploy + rollback steps | Checklist (if applicable) | | **Open Questions** | Unresolved items | Numbered list |
### Requirement: user-session-timeout The system SHALL terminate idle sessions after 30 minutes. #### Scenario: session expires after inactivity - **GIVEN** a user has an active session - **WHEN** no activity occurs for 30 minutes - **THEN** the session is invalidated and user is redirected to login
Rules:
## Decisions ### Use Redis for session storage **Alternatives**: PostgreSQL, in-memory **Rationale**: Sub-millisecond lookups, built-in TTL, already in stack
Include in all designs:
Write to: `{specs_path}/tasks.md`
| Rule | Detail | |------|--------| | Group by `## N. Group Name` | Numbered headings | | Checkbox per task | `- [ ] N.M Task description` | | Dependency order | Tasks ordered by what must come first | | File paths | Include target file path in task | | Acceptance criteria | Each task independently verifiable | | Validation step | Include `pytest` / `npm run validate` per group | | Size | Each task completable in one session |
## 1. Setup - [ ] 1.1 Create `./backend` module structure - [ ] 1.2 Add dependencies to `requirements.txt` ## 2. Core Implementation - [ ] 2.1 Implement service in `./backend/service.py` - [ ] 2.2 Add Pydantic schemas in `./backend/schemas.py` - [ ] 2.3 Add router in `./backend/router.py` - [ ] 2.4 Run validation: `pytest` ## 3. Frontend + Tests - [ ] 3.1 Add types to `app/frontend/src/types/index.ts` - [ ] 3.2 Create component, add unit + integration tests - [ ] 3.3 Run validation: `npm run validate && pytest`
Spec-driven multi-agent orchestration for Claude Code — pure markdown, zero backend, runs on the stock runtime. 13 agents, 36 skills, 19 commands, 15 hooks, per-phase model tiers, opt-in lifecycle hooks, optional cross-device semantic memory.
Repo: komluk/scaffolding
SendMessage recipient validation and worktreePath safety (CWE-59). TRIGGER when: validating a SendMessage `to:` recipient against the agent whitelist, or a…
3-tier markdown memory protocol (shared/agent/conversation) for cross-session knowledge. TRIGGER when: reading or writing agent memory files, choosing which…
RESTful API design standards: resource naming, HTTP methods, status codes, pagination, versioning. TRIGGER when: designing new API endpoints, defining error…
Optimize Claude Code context-window usage for accuracy and cost. TRIGGER when: hitting context limits, structuring prompts for an agent, or trimming what gets…
Schema design, index strategy, migration safety, and query analysis. TRIGGER when: designing tables or indexes, writing a migration, or diagnosing a slow…