Skills executor-spec
๐Ÿ“ฆ

executor-spec

Content revision r1 Safe โš™๏ธ External commands๐ŸŒ Network access๐Ÿ“ Filesystem access

Write Testable Specifications Before Planning

Ambiguous requirements create conflicting implementations and unverifiable reviews. This skill guides linked specifications, risk assessments, and verification strategies through explicit human approval.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 75 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "executor-spec" from https://skillstore.io/skills/atri10-executor-spec.md and its manifest at https://skillstore.io/api/skills/atri10-executor-spec/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "executor-spec". Draft acceptance requirements for placement requests that name an unknown cell.

Expected outcome:

  • Requirement R02: A request naming an unavailable cell returns HTTP 422 with the error value unknown_cell.
  • Observable: The response contains the required status and error value; no placement row is added.
  • Verification: One criterion checks the rejection response, and another checks the absence of a stored placement.
  • Review state: Draft awaiting explicit human approval.

Using "executor-spec". Assess placement latency risks before approving the specification.

Expected outcome:

  • Failure scenario: Placement latency exceeded the agreed threshold as tenant count increased.
  • Cause: The available-cell scan was not measured at the expected tenant scale.
  • Mitigation: Add a measurable latency requirement and a linked load-test criterion.
  • Evidence plan: Record the observed percentile latency at the specified tenant count; keep the criterion pending until execution.

Using "executor-spec". Change a requirement threshold after implementation plans already depend on the specification.

Expected outcome:

  • Change classification: Material because the new threshold can change implementation and review outcomes.
  • Document action: Create a replacement specification and preserve the previous specification body.
  • Traceability: Keep surviving requirement numbers and relink the verification strategy to the replacement.
  • Plan impact: Record which dependent plans need revision and which remain unaffected.

Security Audit

Safe
v1 โ€ข 10/5/2026 Open versioned report

Most findings are Markdown formatting, legitimate test examples, or fixed sibling references, not shell substitution, reconnaissance, or exploitable traversal. The verification example writes to predictable /tmp/b, creating a local symlink overwrite risk if copied and executed. No evidence found of credential exfiltration or prompt injection; referenced sibling helpers are outside the reviewed package.

4
Files scanned
1,175
Lines analyzed
1
Review items
0
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Temp directory access
| V02 | R02 unknown cell rejected | integration | `curl -s -o /tmp/b -w '%{http_code}' localhost:808
curl writes to predictable /tmp/b without exclusive creation. Another local user could pre-create a symlink and redirect the write to an accessible file.

Risk Factors

โš™๏ธ External commands (50)
references/risk-template.md:71-78 references/risk-template.md:78 references/risk-template.md:83-116 references/spec-template.md:47-48 references/spec-template.md:48-49 references/spec-template.md:49-56 references/spec-template.md:56-67 references/spec-template.md:67-68 references/spec-template.md:68-70 references/spec-template.md:70-73 references/spec-template.md:73-88 references/spec-template.md:88-89 references/spec-template.md:89-94 references/spec-template.md:94-95 references/spec-template.md:95-99 references/spec-template.md:99-100 references/spec-template.md:100-112 references/spec-template.md:112-129 references/spec-template.md:129-135 references/verification-template.md:46 references/verification-template.md:47 references/verification-template.md:48 references/verification-template.md:49 references/verification-template.md:50 references/verification-template.md:51 references/verification-template.md:52 references/verification-template.md:53 references/verification-template.md:55 references/verification-template.md:69 references/verification-template.md:70-71 references/verification-template.md:71-72 references/verification-template.md:72 references/verification-template.md:73-74 references/verification-template.md:74-75 references/verification-template.md:75-77 references/verification-template.md:77-78 references/verification-template.md:78-84 references/verification-template.md:84 SKILL.md:14 SKILL.md:15 SKILL.md:16 SKILL.md:19 SKILL.md:27 SKILL.md:30 SKILL.md:33 SKILL.md:35 SKILL.md:50-57 SKILL.md:57-59 SKILL.md:59-60 SKILL.md:60-66
๐ŸŒ Network access (1)
๐Ÿ“ Filesystem access (16)
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/atri10-executor-spec/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/atri10-executor-spec/security.svg)](https://skillstore.io/skills/atri10-executor-spec?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/atri10-executor-spec?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/atri10-executor-spec/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/atri10-executor-spec.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

atri10. (2026). executor-spec security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/atri10-executor-spec/audits/1

BibTeX citation

@techreport{atri10-atri10-executor-spec-2026, author = {atri10}, title = {executor-spec security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/atri10-executor-spec/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "executor-spec security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "atri10" date-released: "2026-10-05" url: "https://skillstore.io/skills/atri10-executor-spec/audits/1" identifiers: - type: other value: "skillstore:atri10-executor-spec:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
65
Community
87
Spec Compliance

What You Can Build

Prepare an implementation specification

Convert approved design candidates into numbered requirements, constraints, scope exclusions, and linked acceptance criteria.

Review delivery risks before approval

Connect failure scenarios to requirements, mitigations, accepted risks, and unresolved questions before authorizing planning.

Define auditable acceptance evidence

Map requirements and constraints to named tests, manual steps, negative cases, boundary checks, and observable outputs.

Try These Prompts

Draft a first specification
Use executor-spec to draft requirements from [approved design handoff] for [initiative]. Include constraints, exclusions, and owned questions. Stop for human review before planning.
Add a linked risk assessment
Review [draft specification] with executor-spec. Write a failure narrative, trace causes, assign mitigation links, and document accepted risks. Update affected requirements before approval.
Complete verification coverage
Create a verification strategy for [specification]. Cover every requirement and constraint with exact procedures and expected observations. Include rejection and boundary checks. Keep results pending.
Supersede a specification with dependent plans
Assess [proposed change] against [specification] and [dependent plans]. For material changes, preserve existing IDs, draft supersession documents, relink verification, and record plan impacts.

Best Practices

  • Provide the approved design handoff, charter, architecture records, and interface documents before drafting requirements.
  • Use exact thresholds and observable outcomes, then map every requirement and constraint to verification evidence.
  • Review companion helpers before execution, use private temporary files, and require explicit approval before passing the phase gate.

Avoid

  • Replace missing decisions with vague terms such as appropriate, robust, or performant.
  • Claim tests passed when the document only defines expected evidence.
  • Edit material requirements in place after dependent plans exist, or treat silence as approval.

Frequently Asked Questions

Which AI tools can use this skill?
The report lists Claude, Codex, and Claude Code as supported tools.
What documents does this workflow produce?
It guides a specification, a risk assessment, and a verification strategy with linked document and requirement identifiers.
Does the package include the Executor helper scripts?
No. The reviewed package contains the skill instructions and three templates; companion scripts and contract references must be provided separately.
Does creating verification criteria mean the tests passed?
No. Criteria remain pending until verification executes their procedures and records observed evidence.
Can an approved specification be changed?
Material changes require supersession once dependent plans exist. Surviving requirement numbers remain stable, and affected plans receive impact records.
Are there precautions before running example commands?
Review companion helpers and adapt commands to your repository. Replace the predictable temporary file with a private temporary file before execution.

Developer Details

Author

atri10

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

6d0b11444384184b7ae743742a7e233a9a705cd9

Maintenance freshness

10/6/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“ references/

๐Ÿ“„ risk-template.md

๐Ÿ“„ spec-template.md

๐Ÿ“„ verification-template.md

๐Ÿ“„ SKILL.md

More from atri10

View all
View all