Agent skill

Program To Tlaplus Spec Generator

by ArabelaTso in ArabelaTso/Skills-4-SE

Automatically generate TLA+ specifications from program code, repositories, or system implementations.

Apache-2.0Auto-check passed

Install Program To Tlaplus Spec Generator

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill program-to-tlaplus-spec-generator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE program-to-tlaplus-spec-generator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/program-to-tlaplus-spec-generator .claude/skills/program-to-tlaplus-spec-generator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
program-to-tlaplus-spec-generator
GitHub stars
253
Token cost
~2.1k tokens
SKILL.md length
795 words
Files
4 (incl. references, assets)
Skills in repo
170
Repo updated
First seen
Licence
Apache-2.0

At a glance

Automatically generate TLA+ specifications from program code, repositories, or system implementations.

  • Works in 9 steps: Analyze Input Program → Extract State Variables → Identify System Actions → …
  • Asked to generate TLA+ spec
  • SKILL.md covers Overview, Generation Workflow, Output Format and Common Patterns, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Program To Tlaplus Spec Generator is an agent skill from ArabelaTso/Skills-4-SE. Automatically generate TLA+ specifications from program code, repositories, or system implementations. Use when asked to generate TLA+ spec, create TLA+ specification from code, convert program to TLA+, formalize system in TLA+, extract TLA+ model from code, or when working with formal specification of concurrent systems, distributed systems, protocols, algorithms, or state machines that need to be verified.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files and assets (for example `references/language_patterns.md` and `references/tlaplus_syntax.md`).

The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Asked to generate TLA+ spec
  • Create TLA+ specification from code
  • Convert program to TLA+
  • Formalize system in TLA+

Example prompts

  • “/program-to-tlaplus-spec-generator”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Analyze Input Program
  2. Extract State Variables
  3. Identify System Actions
  4. Determine Initial State
  5. Analyze Control Flow
  6. Extract Invariants and Properties
  7. Generate TLA+ Module
  8. Create Abstraction Mapping
  9. Generate TLC Configuration (Optional)

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are tla).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Program To Tlaplus Spec Generator loads about 2.1k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 111 tokens; SKILL.md has 795 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 795 words, ~2,140 tokens.

Download SKILL.mdSave it as .claude/skills/program-to-tlaplus-spec-generator/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
program-to-tlaplus-spec-generator
description
Automatically generate TLA+ specifications from program code, repositories, or system implementations. Use when asked to generate TLA+ spec, create TLA+ specification from code, convert program to TLA+, formalize system in TLA+, extract TLA+ model from code, or when working with formal specification of concurrent systems, distributed systems, protocols, algorithms, or state machines that need to be verified.

Program to TLA+ Spec Generator

Overview

This skill enables automatic generation of TLA+ specifications from source code. It analyzes program structure, identifies state variables and transitions, and produces well-formed TLA+ modules with proper syntax and semantics.

Generation Workflow

Follow this sequential process to generate TLA+ specifications from code:

1. Analyze Input Program

Read and understand the source code:

  • Identify scope: Determine which components/modules to formalize
  • Understand purpose: What does the system do? What properties matter?
  • Detect patterns: Is it concurrent? Distributed? Sequential? State machine?
  • Note language: Adapt analysis to language-specific constructs

Ask clarifying questions if needed:

  • Which components should be included in the spec?
  • Are there specific properties or invariants to capture?
  • What level of abstraction is desired?
2. Extract State Variables

Identify variables that represent system state:

Look for:

  • Global variables and shared state
  • Object fields that persist across operations
  • Database/storage state
  • Message queues or buffers
  • Locks, semaphores, and synchronization primitives
  • Process/thread state (running, waiting, etc.)

Determine types:

  • Booleans, integers, sets, sequences, records
  • Map program types to TLA+ types
  • Identify bounded vs unbounded values

Output: List of state variables with TLA+ type declarations

3. Identify System Actions

Extract operations that modify state:

Look for:

  • Functions/methods that change state
  • Event handlers and callbacks
  • Message send/receive operations
  • Lock acquire/release
  • State transitions in state machines
  • Concurrent operations

For each action, identify:

  • Preconditions (when can it execute?)
  • State changes (what variables are modified?)
  • Postconditions (what must be true after?)
  • Parameters and return values

Output: List of actions with their effects

4. Determine Initial State

Identify how the system starts:

  • Variable initialization
  • Constructor logic
  • Setup/bootstrap code
  • Default values

Output: Initial state predicate (Init)

5. Analyze Control Flow

Understand execution patterns:

  • Sequential vs concurrent execution
  • Synchronization points
  • Branching and conditionals
  • Loops and iteration
  • Process spawning/termination

Output: Understanding of how actions compose

6. Extract Invariants and Properties

Identify correctness conditions:

Safety properties (something bad never happens):

  • Type invariants
  • Consistency constraints
  • Mutual exclusion
  • Assertions in code

Liveness properties (something good eventually happens):

  • Progress guarantees
  • Fairness requirements
  • Termination conditions

Output: List of properties to specify

7. Generate TLA+ Module

Construct the specification following TLA+ syntax:

Module structure:

tla
---- MODULE ModuleName ----
EXTENDS Naturals, Sequences, FiniteSets

CONSTANTS [constants]

VARIABLES [state variables]

vars == <<var1, var2, ...>>

Init == [initial state predicate]

Action1 == [action definition]
Action2 == [action definition]
...

Next == Action1 \/ Action2 \/ ...

Spec == Init /\ [][Next]_vars

TypeInvariant == [type constraints]
SafetyProperty == [safety properties]

====

Key elements:

  • Use proper TLA+ operators and syntax
  • Include EXTENDS for standard modules
  • Define CONSTANTS for parameters
  • Declare all VARIABLES
  • Write clear Init predicate
  • Define each action separately
  • Combine actions in Next with disjunction
  • Add Spec with stuttering
  • Include invariants and properties

See references/tlaplus_syntax.md for detailed syntax guide.

8. Create Abstraction Mapping

Document how program maps to TLA+:

State variable mapping:

Program Variable -> TLA+ Variable
---------------------------------
counter (int)    -> counter \in Nat
buffer (array)   -> buffer \in Seq(Data)
lock (bool)      -> lock \in BOOLEAN

Action mapping:

Program Function -> TLA+ Action
--------------------------------
increment()      -> Increment
send(msg)        -> Send(msg)
acquire_lock()   -> AcquireLock

Abstractions applied:

  • Unbounded integers -> bounded range
  • Complex data structures -> simplified types
  • Implementation details omitted
  • Nondeterminism introduced

Assumptions made:

  • Fairness assumptions
  • Environment behavior
  • Timing assumptions
9. Generate TLC Configuration (Optional)

Create model checking configuration:

SPECIFICATION Spec

CONSTANTS
  MaxValue = 10
  NumProcesses = 3

INVARIANTS
  TypeInvariant
  SafetyProperty

PROPERTIES
  LivenessProperty

Output Format

Provide outputs in this structure:

Generated TLA+ Specification
tla
[Complete .tla file content]
Program-to-Spec Mapping

State Variables:

  • program_var → tla_var: [explanation]

Actions:

  • program_function() → TLAAction: [explanation]

Abstractions:

  • [List abstractions and simplifications]

Assumptions:

  • [List assumptions made]
Show full SKILL.md (320 more words)Show less
TLC Configuration (if requested)
[.cfg file content]
Verification Guidance
  • Suggested invariants to check
  • Properties to verify
  • Model parameters to configure
  • Expected verification results

Common Patterns

Sequential Program

Program characteristics:

  • Single thread of execution
  • No concurrency

TLA+ approach:

  • Simple state machine
  • Actions execute atomically
  • Next is disjunction of all actions
Concurrent Program

Program characteristics:

  • Multiple threads/processes
  • Shared state with synchronization

TLA+ approach:

  • Model each thread as separate actions
  • Use process variables for thread state
  • Model locks/semaphores explicitly
  • Consider fairness
Distributed System

Program characteristics:

  • Multiple nodes communicating
  • Message passing
  • Network delays/failures

TLA+ approach:

  • Model each node's state
  • Explicit message buffers
  • Nondeterministic message delivery
  • Model network failures if needed
State Machine

Program characteristics:

  • Explicit states and transitions
  • Event-driven

TLA+ approach:

  • Direct mapping of states to TLA+ values
  • Each transition becomes an action
  • Guards become preconditions

Abstraction Guidelines

What to abstract:

  • Implementation details (algorithms → effects)
  • Concrete data structures (arrays → sequences/sets)
  • Timing (delays → nondeterminism)
  • Unbounded values (integers → bounded range)

What to preserve:

  • State space structure
  • Transition relationships
  • Concurrency patterns
  • Critical properties

Abstraction levels:

  • High: Focus on protocol/algorithm logic only
  • Medium: Include key data structures
  • Low: Close to implementation details

Choose abstraction level based on verification goals.

Tips for Effective Specs

  • Start simple: Model core behavior first, add details later
  • Be explicit: Make all state and transitions visible
  • Use symmetry: Exploit symmetry to reduce state space
  • Bound carefully: Choose bounds that expose bugs but keep verification tractable
  • Document well: Add comments explaining non-obvious parts
  • Validate mapping: Ensure TLA+ spec truly represents the program
  • Test incrementally: Verify simple properties first

Language-Specific Considerations

C/C++:

  • Model pointers as references or indices
  • Abstract memory management
  • Model concurrency primitives (pthread, etc.)

Java:

  • Model objects as records
  • Abstract inheritance/polymorphism
  • Model synchronized blocks and locks

Go:

  • Model goroutines as processes
  • Model channels explicitly
  • Capture select statement nondeterminism

Python:

  • Focus on high-level logic
  • Abstract dynamic typing
  • Model threading/asyncio patterns

Rust:

  • Leverage ownership for safety properties
  • Model borrowing as access control
  • Abstract lifetimes

For detailed patterns, see references/language_patterns.md.

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references, assets) in skills/program-to-tlaplus-spec-generator of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • assets/template.tla
  • references/language_patterns.md
  • references/tlaplus_syntax.md

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Program To Tlaplus Spec Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Program To Tlaplus Spec Generator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Program To Tlaplus Spec Generator this skillArabelaTso/Skills-4-SE253—~2.1kAutomated safety check: PassApache-2.0
Generatealirezarezvani/claude-skills28k1 repos~1.1kAutomated safety check: PassMIT
Generate Programfoldkit/foldkit935—~20kAutomated safety check: PassMIT
Fal Generatenexu-io/open-design100k—~306Automated safety check: PassApache-2.0
Video Generationbytedance/deer-flow84k3 repos~1.4kAutomated safety check: PassMIT
Image Generationonyx-dot-app/onyx32k1 repos~1.7kAutomated safety check: PassCustom licence

Similar skills

  • Generate

    alirezarezvani/claude-skills

    Generate Playwright tests. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.1k tokens
    Testing & QAAuto-check passed
  • Generate Program

    foldkit/foldkit

    Generate a complete, idiomatic Foldkit program from a natural language description.

    935 GitHub stars~20k tokensUpdated today
    Auto-check passed
  • Fal Generate

    nexu-io/open-design

    Generate images and videos using fal.ai AI models. An agent skill from nexu-io/open-design.

    100k GitHub stars~306 tokensUpdated today
    Media & CreativeAuto-check passed
  • Video Generation

    bytedance/deer-flow

    Generates short videos from a structured JSON prompt, optionally guided by a reference image used as the first or last frame.

    84k GitHub starsUsed in 3 repos~1.4k tokens
    Media & CreativeAuto-check passed
  • Image Generation

    onyx-dot-app/onyx

    Generate or edit raster images (photos, illustrations, textures, sprites, mockups, logos, infographics) using the workspace's configured image-generation provider via onyx-cli image.

    32k GitHub starsUsed in 1 repo~1.7k tokens
    Media & CreativeAuto-check passed
  • Structured Image Generation

    bytedance/deer-flow

    Turns an image request into a structured JSON prompt and runs a bundled Python script to generate the picture, optionally guided by reference images.

    84k GitHub starsUsed in 4 repos~2.9k tokens
    Media & CreativeAuto-check passed

More from ArabelaTso/Skills-4-SE

All 170 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Program To Tlaplus Spec Generator

What does Program To Tlaplus Spec Generator do?

Automatically generate TLA+ specifications from program code, repositories, or system implementations. Program To Tlaplus Spec Generator is an agent skill from ArabelaTso/Skills-4-SE. Automatically generate TLA+ specifications from program code, repositories, or system implementations.

When should I use Program To Tlaplus Spec Generator?

Program To Tlaplus Spec Generator fits situations like: asked to generate TLA+ spec; create TLA+ specification from code; convert program to TLA+; formalize system in TLA+.

How do I install Program To Tlaplus Spec Generator in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill program-to-tlaplus-spec-generator -a claude-code`. Or copy the skill folder (skills/program-to-tlaplus-spec-generator in ArabelaTso/Skills-4-SE) into .claude/skills/program-to-tlaplus-spec-generator in your project. Claude Code loads it when a task matches its description.

How do I install Program To Tlaplus Spec Generator in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill program-to-tlaplus-spec-generator -a codex`. Or copy the skill folder (skills/program-to-tlaplus-spec-generator in ArabelaTso/Skills-4-SE) into .agents/skills/program-to-tlaplus-spec-generator in your project. Codex loads it when a task matches its description.

Can I use Program To Tlaplus Spec Generator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill program-to-tlaplus-spec-generator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/program-to-tlaplus-spec-generator, .gemini/skills/program-to-tlaplus-spec-generator, .github/skills/program-to-tlaplus-spec-generator and .opencode/skills/program-to-tlaplus-spec-generator in your project.

What does Program To Tlaplus Spec Generator need to run?

SKILL.md names no scripts, command-line tools or credentials: Program To Tlaplus Spec Generator is instructions for the agent only.

Does Program To Tlaplus Spec Generator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Program To Tlaplus Spec Generator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Program To Tlaplus Spec Generator use?

Program To Tlaplus Spec Generator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Program To Tlaplus Spec Generator use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Program To Tlaplus Spec Generator?

Skills that share tags, products or a category with Program To Tlaplus Spec Generator: Generate (alirezarezvani/claude-skills, 28k stars), Generate Program (foldkit/foldkit, 935 stars), Fal Generate (nexu-io/open-design, 100k stars) and Video Generation (bytedance/deer-flow, 84k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Program To Tlaplus Spec Generator?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 170 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.