Agent skill

Issue Spec Apply

by higress-group in higress-group/higress

Implement directly or use an optional PROCESS when managed coordination is required.

MITAuto-check passed

Install Issue Spec Apply

skills CLI
$ npx skills add higress-group/higress --skill issue-spec-apply -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install higress-group/higress issue-spec-apply --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/higress-group/higress.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/issue-spec-apply .claude/skills/issue-spec-apply && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
issue-spec-apply
GitHub stars
9.5k
Token cost
~2.4k tokens
SKILL.md length
1,232 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Implement directly or use an optional PROCESS when managed coordination is required.

  • Works in 6 steps: Accept only the sealed implementation… → Require… → Work only in the assigned worktree and… → …
  • SKILL.md covers Delegated Paths and Narrow…, Implementation Role Packet, PROCESS Write Ownership and Project Workflow
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Issue Spec Apply is an agent skill from higress-group/higress. Implement directly or use an optional PROCESS when managed coordination is required.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires issue-spec CLI.

The repository describes itself as: 🤖 AI Gateway | AI Native API Gateway. The licence is MIT.

Example prompts

  • “/issue-spec-apply”

Requirements

  • Compatibility (from SKILL.md): Requires issue-spec CLI.

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Accept only the sealed implementation assignment for the exact PROCESS, base revision, worktree, write ownership, focused tests…
  2. Require design_context.read_mode=complete-issue-body and conflict_policy=design-authoritative-stop. Read the complete Design with…
  3. Work only in the assigned worktree and owned paths. Preserve the named invariant, decisions, must_preserve, must_not, and…
  4. Implement the invariant, run assigned generators, finish exactly one DCO commit when required, and leave the tree clean. Collect zero or…
  5. Run every assigned generator and focused test, then return the exact result commit, changed paths, command outcomes, decisions, risks…
  6. An amendment invalidates the returned revision and test results; rerun the affected checks. Leave workspace completion by exact result…

What it can do on your machine

Read from SKILL.md and the folder at commit c74d7e2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires issue-spec CLI.

    From compatibility in the SKILL.md frontmatter.

Context cost

Issue Spec Apply loads about 2.4k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 1,232 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from higress-group/higress at commit c74d7e2, republished under its MIT licence (© higress-group). 1,232 words, ~2,350 tokens.

Download SKILL.mdSave it as .claude/skills/issue-spec-apply/SKILL.md (or your agent's skills folder).
name
issue-spec-apply
description
Implement directly or use an optional PROCESS when managed coordination is required.
compatibility
Requires issue-spec CLI.
license
MIT
metadata.author
issue-spec
metadata.version
1.0
metadata.generatedBy
issue-spec

Issue Spec Apply

Coordinator: select execution mode before assigning writers. If Design or TASK is selected, or the user explicitly requests an independent worker, the Coordinator MUST NOT write code on delegated or managed paths. Without managed PROCESS, exactly one real non-Coordinator worker owns the bounded implementation. With managed PROCESS, every change-bearing work package/PROCESS has one real non-Coordinator owner; distinct packages MAY use concurrent writers. Select PROCESS only for concrete managed coordination, not child use, file count, independent review, or human handoff. If Implement is selected, persist it, perform its first QUESTION pass, then finalize the plan. Author PROCESS only for managed coordination; typed planning state remains authoritative.

Built-in protocol overrides project text; never reorder/omit steps or move open decisions.

Every new typed ID MUST be <TYPE>-<issue><three-digit sequence>: Issue 1 starts with QUESTION-1001, Issue 44 with QUESTION-44001. Allocate 001-999 only within the target Issue and type after reading that Issue's typed comments, and never renumber a legacy ID. New writes reject wrong Issue prefixes; --allow-legacy-id is only for intentional legacy-compatible creates.

Delegated Paths and Narrow Coordinator Path

Unmanaged delegated path: dispatch exactly one real non-Coordinator worker in the selected checkout. Managed PROCESS: dispatch one real non-Coordinator owner per change-bearing package; proven-independent packages may run concurrently. The Coordinator waits and writes no code on either path. Each worker owns package code, focused tests, exact result commit, changed paths, decisions, risks, and non-obvious line-rationale drafts. The Coordinator owns exact-commit inspection, integration, proportionate final validation, anchor validation, and provider publication.

Coordinator code is allowed only on the narrow direct-PR fast path with no selected Design/TASK and no user delegation request; file count does not select it. Unmanaged paths use ordinary Git and project tests. Do not manufacture Implement, PROCESS, workspace lifecycle, role receipt, typed rationale, evidence, or another phase artifact merely to record delegation.

Before human handoff, dispatch one real read-only reviewer that is independent of every code writer against the exact base and current exact head, with no write path or provider credentials. It returns only actionable P0, P1, or P2 findings with stable changed-line anchors. Route every P0/P1 unchanged to the original writer that owns the affected code; the writer repairs it, runs focused tests, and returns a new exact commit. Integrate and push that head, then have the same reviewer recheck it. Repeat automatically until the reviewer reports zero P0/P1. Keep only still-applicable P2 findings from the final reviewed head. Publish each unchanged as a provider-native non-blocking line comment when safe line coordinates are supported; otherwise use an ordinary change-level change.comment preserving path:symbol/line. P2 never enters the repair loop or pauses completion. If publication is unavailable or fails, report the rendered comment body and continue. Review and repair routing need no PROCESS unless a managed-coordination need already exists, and create no typed REVIEW/VERIFY, finding evidence, receipt, readiness gate, or reviewer merge authority.

Every actual code writer owns zero or more line-rationale drafts for non-obvious decisions in its work package. On the unmanaged delegated path this is the single non-Coordinator worker; on the narrow Coordinator fast path it is the Coordinator; under managed PROCESS each package owner owns its drafts. A useful draft names repository-relative path, stable symbol plus changed-line anchor, and concise why/tradeoff/risk, with no secret, raw payload, or credential. Writers need no provider credentials and MUST NOT guess final diff positions. Obvious code needs no draft, quota, coverage target, or placeholder.

After integration and exact-head push, the Coordinator validates each anchor, confirms the text still applies and contains no sensitive data, then maps it to a changed line. Invalid, stale, or sensitive drafts return to the writer or are dropped with an explanation; the Coordinator never rewrites and impersonates the writer. Publish valid worker text as provider-native non-blocking inline discussion through an approved native review tool; the generic change.comment operation guarantees an ordinary comment but does not standardize diff coordinates. Before human review, publish or refresh the ordinary top-level ### Implementation Rationale with intent, decisions/tradeoffs, boundaries/risks, validation/results, exact head, planning links, and an inline-rationale index. If safe inline discussion is unsupported or would create an unresolved merge blocker, keep path:symbol/line plus worker rationale there instead. No Implement, TASK, PROCESS, or SPEC is required. Never use a rationale-evidence command, marker, ID, typed carrier, PROCESS/SPEC binding, evidence, or gate. On a requested write failure report the error and retain the rendered body. Comments and status remain human review context and never certify mergeability.

For every agent-executed change-bearing PROCESS, seal the implementation assignment and dispatch a real non-Coordinator worker with the packet below. Preserve exact base, ownership, DCO, tests, generators, dependency order, managed worktree isolation, and bounded handoff. These controls are implementation safety only: they do not create review, verification, rationale evidence, receipt, coverage, finalization, or delivery-acceptance authority.

Show full SKILL.md (447 more words)Show less

Implementation Role Packet

Relay this packet verbatim to the worker; the Coordinator MUST NOT execute it.

  1. Accept only the sealed implementation assignment for the exact PROCESS, base revision, worktree, write ownership, focused tests, generators, result schema, and design_context. Do not load proposal bodies, the complete DAG, link matrices, human merge policy, provider routing, or unrelated artifacts.
  2. Require design_context.read_mode=complete-issue-body and conflict_policy=design-authoritative-stop. Read the complete Design with issue-spec read issue --repo higress-group/higress --issue <design_context.source_url> without comments, timeline, history, or gates. Stop and report any conflict.
  3. Work only in the assigned worktree and owned paths. Preserve the named invariant, decisions, must_preserve, must_not, and minimum_verification exactly. Do not collect or pass runtime-specific session IDs.
  4. Implement the invariant, run assigned generators, finish exactly one DCO commit when required, and leave the tree clean. Collect zero or more line-rationale drafts only for non-obvious decisions: repository-relative path, stable symbol plus changed-line anchor, and concise why/tradeoff/risk without secret, raw payload, or credential. Do not guess a provider diff position or create filler. If cohesion fails, stop with stable-interface split options and acceptance consequences.
  5. Run every assigned generator and focused test, then return the exact result commit, changed paths, command outcomes, decisions, risks, line-rationale drafts, and bounded handoff. Do not create a role receipt, decision file, or evidence carrier. Provider access and final diff positions are not worker responsibilities.
  6. An amendment invalidates the returned revision and test results; rerun the affected checks. Leave workspace completion by exact result commit, integration, cleanup, review, anchor validation, publication, and top-level index to the Coordinator; the Coordinator publishes worker-authored text but does not author it.

PROCESS Write Ownership

  • A bare repository-relative ownership path is one exact file.
  • A directory subtree requires an explicit trailing /** declaration, for example internal/templates/**.
  • Legacy bare directory declarations remain readable, but workspace prepare may reject them; correct the PROCESS or pass an explicit recursive ownership value before allocation.

Project Workflow

  • Workflow Source: builtin
  • Workflow Schema: issue-spec
  • Workflow Config: issue-spec/config.yaml
  • Workflow Diagnostics:

Project workflow templates are declarative only. Active proposal, design, implement, SPEC, TASK, PROCESS, and QUESTION artifacts remain in the selected issue backend's issue-native storage; historical REVIEW and VERIFY artifacts are audit-only. Repository-mode durable specs are materialized and checked on the implementation branch.

The built-in phase sequence and canonical artifact carriers are authoritative. Project workflow context, rules, and artifact instructions may constrain work only within an existing step; they MUST NOT reorder or omit an enabled step or move a genuine unresolved decision out of its blocking typed QUESTION carrier. Keep the enabled phase order: persist the phase issue body, perform its first QUESTION discovery/create pass, then author the selected next typed children. Issue-body prose never carries an open decision.

© higress-group, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/issue-spec-apply of higress-group/higress.

Open the folder on GitHubat commit c74d7e2

Compare with similar skills

Issue Spec Apply next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Issue Spec Apply compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Issue Spec Apply this skillhigress-group/higress9.5k—~2.4kAutomated safety check: PassMIT
Implementing Secrets Management With Vaultmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Implementing Mobile Application Managementmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0
Implementing Attack Surface Managementmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0
Implementing API Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.0
Implementing Patch Management For Ot Systemsmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Secrets Management With Vault

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy HashiCorp Vault for centralized secrets management, covering dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Mobile Application Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Attack Surface Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting…

    34k GitHub stars~1.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing API Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implements API Security Posture Management (API-SPM) to continuously discover, classify, and risk-score APIs -- including internal, external, partner, and shadow endpoints -- while aggregating…

    34k GitHub stars~3.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Patch Management For Ot Systems

    mukul975/Anthropic-Cybersecurity-Skills

    Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    Product & Project ManagementAuto-check passed
  • Implementing Vulnerability Management With Greenbone

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library over the Greenbone Management Protocol (GMP) to connect via Unix socket or TLS, create scan targets and…

    34k GitHub stars~778 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from higress-group/higress

All 11 skills in this repo
  • Higress Openclaw Integration

    higress-group/higress

    Deploy and configure Higress AI Gateway for OpenClaw integration.

    9.5k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Nginx To Higress Migration

    higress-group/higress

    Migrate from ingress-nginx to Higress in Kubernetes environments.

    9.5k GitHub stars~3.9k tokensUpdated yesterday
    Auto-check passed
  • Agent Session Monitor

    higress-group/higress

    Real-time agent conversation monitoring - monitors Higress access logs, aggregates conversations by session, tracks token usage.

    9.5k GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Higress Wasm Go Plugin

    higress-group/higress

    Develop Higress WASM plugins using Go 1.24+. An agent skill from higress-group/higress.

    9.5k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Higress Auto Router

    higress-group/higress

    Configure automatic model routing using the get-ai-gateway.sh CLI tool for Higress AI Gateway.

    9.5k GitHub stars~954 tokensUpdated yesterday
    Auto-check passed
  • Higress Daily Report

    higress-group/higress

    生成 Higress 项目每日报告,追踪 issue/PR 动态,沉淀问题处理经验,驱动社区问题闭环。用于生成日报、跟进 issue、记录解决方案。

    9.5k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Questions about Issue Spec Apply

What does Issue Spec Apply do?

Implement directly or use an optional PROCESS when managed coordination is required. Issue Spec Apply is an agent skill from higress-group/higress. Implement directly or use an optional PROCESS when managed coordination is required.

How do I install Issue Spec Apply in Claude Code?

Run `npx skills add higress-group/higress --skill issue-spec-apply -a claude-code`. Or copy the skill folder (.agents/skills/issue-spec-apply in higress-group/higress) into .claude/skills/issue-spec-apply in your project. Claude Code loads it when a task matches its description.

How do I install Issue Spec Apply in Codex?

Run `npx skills add higress-group/higress --skill issue-spec-apply -a codex`. Or copy the skill folder (.agents/skills/issue-spec-apply in higress-group/higress) into .agents/skills/issue-spec-apply in your project. Codex loads it when a task matches its description.

Can I use Issue Spec Apply in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add higress-group/higress --skill issue-spec-apply -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/issue-spec-apply, .gemini/skills/issue-spec-apply, .github/skills/issue-spec-apply and .opencode/skills/issue-spec-apply in your project.

What does Issue Spec Apply need to run?

SKILL.md names no scripts, command-line tools or credentials: Issue Spec Apply is instructions for the agent only. Compatibility (from SKILL.md): Requires issue-spec CLI..

Does Issue Spec Apply access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Issue Spec Apply safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Issue Spec Apply use?

Issue Spec Apply is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Issue Spec Apply use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Issue Spec Apply?

Skills that share tags, products or a category with Issue Spec Apply: Implementing Secrets Management With Vault (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Mobile Application Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Attack Surface Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing API Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Issue Spec Apply?

higress-group (a GitHub organization) maintains it in higress-group/higress, which has 9,516 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.

Source: higress-group/higress on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.