spec-workflow
Guide Spec-Driven Implementation
Feature work often drifts beyond approved acceptance criteria. This skill guides Claude, Codex, and Claude Code through AC review, TDD, scope checks, and completion review.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "spec-workflow" from https://skillstore.io/skills/clionegohan-spec-workflow.md and its manifest at https://skillstore.io/api/skills/clionegohan-spec-workflow/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "spec-workflow". Implement the user authentication subtask from the current spec.
Expected outcome:
- Summarizes the user story and acceptance criteria.
- Asks for approval before implementation starts.
- Plans failing tests, minimal implementation, and refactor checks.
- Reports completion against each acceptance criterion.
Using "spec-workflow". Also add CI setup while working on the configuration subtask.
Expected outcome:
- Identifies CI setup as outside the current acceptance criteria.
- Explains why it should not be added to the current subtask.
- Offers to define it as a separate follow-up task.
Using "spec-workflow". Finish this story and prepare review handoff.
Expected outcome:
- Checks that all subtasks and tests are complete.
- Summarizes implemented acceptance criteria.
- Requests confirmation before branch or pull request actions.
Security Audit
SafeMost backtick-related findings are false positives caused by Markdown fences, inline formatting, and TypeScript examples. The filesystem findings are confirmed because SKILL.md references hidden .ai files through parent-directory traversal at lines 306-307.
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (40)
📁 Filesystem access (4)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/clionegohan-spec-workflow/audits/10?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/clionegohan-spec-workflow?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/clionegohan-spec-workflow?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/clionegohan-spec-workflow/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/clionegohan-spec-workflow.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
Clionegohan. (2026). spec-workflow security audit report (audit version 10) [Author version unspecified]. Skillstore. https://skillstore.io/skills/clionegohan-spec-workflow/audits/10BibTeX citation
@techreport{clionegohan-clionegohan-spec-workflow-2026,
author = {Clionegohan},
title = {spec-workflow security audit report (audit version 10)},
institution = {Skillstore},
year = {2026},
number = {10},
url = {https://skillstore.io/skills/clionegohan-spec-workflow/audits/10},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "spec-workflow security audit report (audit version 10)"
version: "unspecified"
type: report
authors:
- name: "Clionegohan"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/clionegohan-spec-workflow/audits/10"
identifiers:
- type: other
value: "skillstore:clionegohan-spec-workflow:audit:10"
description: "Skillstore immutable audit report identifier"
Compare variants
2 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
tencentcloudbase-spec-workflow
2026-09-09
clionegohan-spec-workflow
2026-09-09
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Implement Approved Subtasks
Use the workflow to read a subtask, confirm acceptance criteria, and implement only the approved scope.
Keep Delivery Aligned
Use acceptance criteria checks to prevent extra features and confirm completion before status updates.
Structure AI Pair Programming
Guide Claude, Codex, or Claude Code through a repeatable TDD cycle for feature work.
Try These Prompts
Implement subtask 001-01-01. Read the matching spec, summarize the acceptance criteria, and ask for approval before coding.
Use the spec workflow for this story. Derive test cases from each acceptance criterion before making implementation changes.
Check whether this requested change is inside the current subtask acceptance criteria. If it is outside scope, propose the next step.
After all tests pass, check every acceptance criterion, update the subtask status, and prepare the branch and pull request handoff.
Best Practices
- Keep each prompt tied to one subtask and one approved acceptance criteria set.
- Review the proposed tests before allowing implementation changes.
- Require explicit approval before branch, status, or pull request updates.
Avoid
- Do not use the skill to invent acceptance criteria without upstream specification work.
- Do not bundle unrelated feature requests into one subtask implementation.
- Do not skip the Red phase when tests are available for the project.
Frequently Asked Questions
Does this skill create specifications?
Can it work without tests?
Does it change files automatically?
What specification format does it expect?
Can it handle EARS acceptance criteria?
Is it suitable for large stories?
Developer Details
Author
ClionegohanLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
26421118b848d9f1efc0aa169d8a7a9e7e0a877e
Maintenance freshness
7/18/2026
Usage
6 downloads · 224 views
File structure
📄 SKILL.md