Skills specsfy-aux-stack
📦

specsfy-aux-stack

Content revision r1 Safe ⚙️ External commands📁 Filesystem access

Maintain Your Project Stack Inventory

Project stack documentation often becomes incomplete after dependency changes. This skill detects supported technologies and updates .specsfy/STACK.md while preserving human-authored content.

Supports: Claude Codex Code(CC)
📊 75 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "specsfy-aux-stack" from https://skillstore.io/skills/promovaweb-specsfy-aux-stack.md and its manifest at https://skillstore.io/api/skills/promovaweb-specsfy-aux-stack/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "specsfy-aux-stack". Update the stack inventory for a Laravel project using Pest.

Expected outcome:

The managed inventory lists PHP, Laravel, and Pest with composer.json as evidence. Existing notes outside the managed section remain unchanged.

Using "specsfy-aux-stack". Refresh documentation for a Next.js project using Prisma and Vitest.

Expected outcome:

The inventory records Node.js, Next.js, Prisma, and Vitest with package.json evidence, without duplicating existing entries.

Using "specsfy-aux-stack". Inspect a repository with no recognized manifests.

Expected outcome:

The inventory records that the framework requires confirmation and states that no recognized manifest was found.

Security Audit

Safe
v1 • 9/27/2026 Open versioned report

All 18 static findings are false positives caused by JavaScript template literals, Markdown code formatting, or intentional access to .specsfy/STACK.md. The script reads project manifests and updates one documented stack inventory file without shell execution, certificate access, network activity, or evidence of malicious intent.

3
Files scanned
66
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were detected by the latest completed static and semantic audit. This does not prove the skill has no side effects.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/promovaweb-specsfy-aux-stack/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/promovaweb-specsfy-aux-stack/security.svg)](https://skillstore.io/skills/promovaweb-specsfy-aux-stack?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/promovaweb-specsfy-aux-stack?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/promovaweb-specsfy-aux-stack/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/promovaweb-specsfy-aux-stack.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA · BibTeX · CFF)

APA citation

promovaweb. (2026). specsfy-aux-stack security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/promovaweb-specsfy-aux-stack/audits/1

BibTeX citation

@techreport{promovaweb-promovaweb-specsfy-aux-stack-2026, author = {promovaweb}, title = {specsfy-aux-stack security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/promovaweb-specsfy-aux-stack/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "specsfy-aux-stack security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "promovaweb" date-released: "2026-09-27" url: "https://skillstore.io/skills/promovaweb-specsfy-aux-stack/audits/1" identifiers: - type: other value: "skillstore:promovaweb-specsfy-aux-stack:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Refresh stack documentation

Update the technical inventory after adding or removing major project dependencies.

Prepare repository context

Create a concise stack reference before another agent begins implementation work.

Review technology evidence

Compare documented stack entries with manifests, lockfiles, and configuration files.

Try These Prompts

Update the stack inventory
Use $specsfy-aux-stack to inspect this project and update .specsfy/STACK.md.
Document a framework change
Use $specsfy-aux-stack after the recent framework changes. Preserve existing human notes and cite evidence for each new stack entry.
Verify stack documentation
Use $specsfy-aux-stack to compare .specsfy/STACK.md with current manifests and configurations. Mark unsupported claims for conversational review.
Coordinate a persistence update
Use $specsfy-aux-stack to refresh the stack inventory after persistence changes. Invoke the related database workflow when required and preserve manual decisions.

Best Practices

  • Confirm the project root before running the update script.
  • Review each generated row against manifests, lockfiles, and configuration files.
  • Keep human decisions and notes outside the managed stack block.

Avoid

  • Do not add technologies without evidence from project files.
  • Do not remove human-authored content outside the managed block.
  • Do not copy complete dependency trees into the stack inventory.

Frequently Asked Questions

Which files does the skill inspect?
It reads composer.json, package.json, optional Docker Compose files, and the existing .specsfy/STACK.md file.
Does it preserve manual documentation?
Yes. It replaces only the managed specsfy:stack block and preserves content before and after that block.
Which technologies can it detect?
It detects selected PHP, Node.js, framework, testing, persistence, React, TypeScript, and container technologies.
Does it install dependencies?
No. It reads manifests and writes stack documentation without installing packages.
What happens when no supported manifest is found?
It adds a placeholder stating that the framework requires confirmation.
Can it document database changes?
It detects selected persistence packages and directs broader persistence changes to the related database skill.

Developer Details

Author

promovaweb

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

8b5ad1599e7c55e9b6c627bca3f556f6e9061cb1

Maintenance freshness

9/30/2026

Usage

0 downloads · 0 views

File structure

View all