ghe-design
Draft Domain-Specific Requirements
Teams lose time when requirements are vague or forced into one template. This skill guides Claude, Codex, and Claude Code to create clear, testable requirements for each domain.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "ghe-design" from https://skillstore.io/skills/emasoft-ghe-design.md and its manifest at https://skillstore.io/api/skills/emasoft-ghe-design/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "ghe-design". Request requirements for a dark mode toggle.
Expected outcome:
A short requirement describing the toggle, user value, persistence behavior, system preference handling, transition expectations, and acceptance checks.
Using "ghe-design". Request requirements for a payment flow.
Expected outcome:
A structured requirement covering compliance, transaction flow, retention rules, audit logging, failure handling, and verification steps.
Using "ghe-design". Request requirements for an authentication system.
Expected outcome:
A security-focused requirement with threat model, trust boundaries, authentication flow, required headers, and measurable controls.
Security Audit
High RiskMost static command and network findings are false positives from Markdown code fences, inline paths, and reference links. The audit confirms the ~/.claude write allowance and flags absolute prompt-control wording plus mandatory full-report posting.
Confirmed security concerns (2)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (27)
🌐 Network access (8)
📁 Filesystem access (2)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/emasoft-ghe-design/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/emasoft-ghe-design?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/emasoft-ghe-design?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/emasoft-ghe-design/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/emasoft-ghe-design.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
Emasoft. (2026). ghe-design security audit report (audit version 8) [Author version unspecified]. Skillstore. https://skillstore.io/skills/emasoft-ghe-design/audits/8BibTeX citation
@techreport{emasoft-emasoft-ghe-design-2026,
author = {Emasoft},
title = {ghe-design security audit report (audit version 8)},
institution = {Skillstore},
year = {2026},
number = {8},
url = {https://skillstore.io/skills/emasoft-ghe-design/audits/8},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "ghe-design security audit report (audit version 8)"
version: "unspecified"
type: report
authors:
- name: "Emasoft"
date-released: "2026-07-05"
url: "https://skillstore.io/skills/emasoft-ghe-design/audits/8"
identifiers:
- type: other
value: "skillstore:emasoft-ghe-design:audit:8"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Plan a Feature Requirement
Create a concise requirement with purpose, acceptance criteria, assets, and references before implementation starts.
Specify a Technical System
Document architecture, failure modes, data contracts, and verification steps for complex engineering work.
Prepare Security Requirements
Capture threat models, trust boundaries, mitigations, and security headers in a format engineers can verify.
Try These Prompts
Use ghe-design to draft requirements for this feature: [feature]. Include what, why, acceptance criteria, and references.
Use ghe-design to write requirements for [domain]. Choose sections that fit the domain and explain how completion will be verified.
Use ghe-design to review this requirement draft: [draft]. Add missing constraints, edge cases, references, and testable acceptance criteria.
Use ghe-design to create a full requirement for [system]. Cover architecture, risks, compliance, failure modes, assets, and verification evidence.
Best Practices
- Start with the user goal, then add only sections that improve clarity.
- Make every acceptance criterion observable and testable.
- List external references without copying large source documents.
Avoid
- Do not force every requirement into the same template.
- Do not replace user requirements with silent improvements.
- Do not use vague success terms without verification evidence.