agent-comms
SendMessage recipient validation and worktreePath safety (CWE-59). TRIGGER when: validating a SendMessage `to:` recipient against the agent whitelist, or a…
Verify an implementation against its OpenSpec artifacts. TRIGGER when: checking completed work against design.md and tasks.md. SKIP: security-specific review (use security-review-checklists); executing tasks (use spec-develop).
$ npx -y skills add komluk/scaffolding --skill spec-review --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/spec-reviewContext preview
The summary Claude sees to decide when to auto-load this skill.
Verify an implementation against its OpenSpec artifacts. TRIGGER when: checking completed work against design.md and tasks.md. SKIP: security-specific review (use security-review-checklists); executing tasks (use spec-develop).
name: spec-review description: "Verify an implementation against its OpenSpec artifacts. TRIGGER when: checking completed work against design.md and tasks.md. SKIP: security-specific review (use security-review-checklists); executing tasks (use spec-develop)."
Guide for verifying that implementation matches spec artifacts.
| File | Required | Purpose | |------|----------|---------| | `{specs_path}/design.md` | Yes | Requirements and scenarios to verify | | `{specs_path}/tasks.md` | Yes | Completion checklist | | `{specs_path}/proposal.md` | Optional | Original intent reference |
**Path Enforcement**: The `specs_path` MUST be `.scaffolding/conversations/{UUID}/specs/` where `{UUID}` is a valid UUID (format: `xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx`). NEVER use descriptive folder names.
**Question**: Are all tasks done and all requirements covered?
| Check | Method | Issue Level | |-------|--------|-------------| | All checkboxes marked `[x]` | Parse tasks.md | CRITICAL if incomplete | | All requirements have code | Search codebase for keywords | CRITICAL if missing | | All new files exist | Verify file paths from tasks | CRITICAL if missing |
**Question**: Does the code do what the spec says?
| Check | Method | Issue Level | |-------|--------|-------------| | GIVEN/WHEN/THEN satisfied | Trace scenario through code | WARNING if divergent | | Tests cover scenarios | Match test names to scenarios | WARNING if uncovered | | Edge cases handled | Check error paths in code | WARNING if missing | | Validation commands pass | Run pytest / npm run validate | CRITICAL if failing |
**Question**: Does the code match design decisions?
| Check | Method | Issue Level | |-------|--------|-------------| | Design decisions followed | Compare Decisions section to code | WARNING if violated | | Patterns consistent | Check naming, structure, style | SUGGESTION | | No undocumented changes | Diff scope vs design scope | WARNING if extra | | No design deviations | Cross-reference architecture | WARNING if different |
1. **Load artifacts** - Read design.md, tasks.md, proposal.md 2. **Check completeness** - Parse checkboxes, search for requirement implementations 3. **Check correctness** - Trace each scenario through code, verify test coverage 4. **Check coherence** - Compare decisions to implementation, check patterns 5. **Generate report** - Summarize findings with issue levels
## Verification Report ### Summary | Dimension | Status | |--------------|---------------------| | Completeness | X/Y tasks, N reqs | | Correctness | M/N scenarios pass | | Coherence | Followed / N issues | ### Critical Issues | # | Dimension | Issue | File | Recommendation | |---|-----------|-------|------|----------------| | 1 | Completeness | Task 2.3 incomplete | - | Complete or mark blocked | ### Warnings | # | Dimension | Issue | File | Recommendation | |---|-----------|-------|------|----------------| | 1 | Correctness | Scenario X not tested | test_foo.py | Add test case | ### Suggestions - [Pattern deviation details with file reference] ### Assessment [CRITICAL: N issues | WARNINGS: N | Ready for archive: Yes/No]
| Available Artifacts | Checks Performed | |--------------------|-----------------| | tasks.md only | Completeness (checkboxes) only | | tasks.md + design.md | Completeness + Correctness | | All three | All three dimensions |
Always note which checks were skipped and why.
Spec-driven multi-agent orchestration for Claude Code — pure markdown, zero backend, runs on the stock runtime. 13 agents, 36 skills, 19 commands, 15 hooks, per-phase model tiers, opt-in lifecycle hooks, optional cross-device semantic memory.
Repo: komluk/scaffolding
SendMessage recipient validation and worktreePath safety (CWE-59). TRIGGER when: validating a SendMessage `to:` recipient against the agent whitelist, or a…
3-tier markdown memory protocol (shared/agent/conversation) for cross-session knowledge. TRIGGER when: reading or writing agent memory files, choosing which…
RESTful API design standards: resource naming, HTTP methods, status codes, pagination, versioning. TRIGGER when: designing new API endpoints, defining error…
Optimize Claude Code context-window usage for accuracy and cost. TRIGGER when: hitting context limits, structuring prompts for an agent, or trimming what gets…
Schema design, index strategy, migration safety, and query analysis. TRIGGER when: designing tables or indexes, writing a migration, or diagnosing a slow…