Agent skill

Spec Polish

by leo-kuang-ai in leo-kuang-ai/spec-first

Start the dev server, inspect the feature in browser, and iterate on polish.

MITAuto-check passedDevelopment

Install Spec Polish

skills CLI
$ npx skills add leo-kuang-ai/spec-first --skill spec-polish -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install leo-kuang-ai/spec-first spec-polish --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/leo-kuang-ai/spec-first.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/spec-polish .claude/skills/spec-polish && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spec-polish
GitHub stars
107
Token cost
~2.5k tokens
SKILL.md length
1,079 words
Files
24 (incl. scripts, references)
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Start the dev server, inspect the feature in browser, and iterate on polish.

  • Works in 3 steps: Get on the right branch → Start the dev server → Iterate
  • Tasks that involve Code review
  • SKILL.md covers Workflow Contract Summary, Mutation Authority Boundary, Phase 0: Get on the right branch and Phase 1: Start the dev server, plus 2 more sections
  • Runs JavaScript and Shell scripts from its folder; calls bash

What it does

Spec Polish is an agent skill from leo-kuang-ai/spec-first. Start the dev server, inspect the feature in browser, and iterate on polish. Browser-interactive polish only: static code review belongs to spec-code-review and implementation planning to spec-plan — route such requests out by naming the destination skill, never by doing the work here.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 31 other files, including scripts and reference files (for example `evals/cases/r2-screenshot-review-routes-out.yaml`, `evals/cases/review-request-routes-out.yaml` and `evals/eval.yaml`).

It sits in Development, covering Code review. The repository describes itself as: 仓库原生 AI Coding Harness —— 把一次性 AI 对话变成可治理、可验证、可沉淀的工程闭环 · spec-first.cn. The licence is MIT.

When your agent uses it

  • Tasks that involve Code review

Example prompts

  • “/spec-polish”

Requirements

  • Node.js
  • A Bash shell

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Get on the right branch
  2. Start the dev server
  3. Iterate

What it can do on your machine

Read from SKILL.md and the folder at commit 74655dc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript and Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spec Polish loads about 2.5k tokens when it runs, and up to ~9k if it reads all its reference files. Until then it costs about 75 tokens; SKILL.md has 1,079 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from leo-kuang-ai/spec-first at commit 74655dc, republished under its MIT licence (© leo-kuang-ai). 1,079 words, ~2,460 tokens.

Download SKILL.mdSave it as .claude/skills/spec-polish/SKILL.md (or your agent's skills folder). This skill also uses 23 other files; get the full folder from GitHub.
name
spec-polish
description
Start the dev server, inspect the feature in browser, and iterate on polish. Browser-interactive polish only: static code review belongs to spec-code-review and implementation planning to spec-plan — route such requests out by naming the destination skill, never by doing the work here.
disable-model-invocation
true
argument-hint
[PR number, branch name, or blank for current branch]

Polish

Start the dev server, open the feature in a browser, and iterate. You use the feature, say what feels off, and fixes happen.

Workflow Contract Summary

When To Use

Use when a feature or branch is ready for hands-on browser polish: start its dev server, inspect the feature in browser, and make iterative UI/UX fixes from direct feedback.

When Not To Use

Do not use for initial requirements, implementation planning, non-browser backend work, static code review, broad visual audits, or MCP setup/repair beyond the browser helper handoff. When routing out for one of these, name the destination skill explicitly in your reply (static code review belongs to spec-code-review) — recognizing the mismatch and then doing the excluded work anyway is adopting the wrong workflow, not a helpful fallback. A direct user request to do the excluded work inside this workflow ("帮我静态审查一下,不用起服务") is still a routing-out condition: name spec-code-review, do not run the review here — not even a partial, "quick pass" version of it.

Inputs

A PR number, branch name, or current branch; project dev-server conventions; feature URL/route when known; user feedback from browser inspection.

Outputs

Running local dev server URL, browser handoff, authorized scoped polish edits, verification notes, and an explicit commit status.

Artifacts

Authorized source edits in the user's project, dev-server log in temp space, optional browser screenshots/inspection notes, and a final commit only when separately authorized.

Failure Modes

Wrong branch, main/master branch, missing branch-mutation authority, missing dev-server command, unresolved port, server startup failure, browser helper unavailable, or user feedback requiring upstream product/design decisions.

Workflow

Select the branch, start the dev server, resolve the browser handoff, iterate on user-reported polish issues, and stop when the user says the loop is complete.

Downstream Consumers

The user reviewing the browser result, spec-work for deeper implementation follow-up, and release/review workflows that consume the final branch changes.

Mutation Authority Boundary

Before checkout or the first source edit, derive four independent run-local facts from the current user request and any visible upstream handoff:

yaml
branch_mutation_authorization: authorized | missing
local_fix_authorization: authorized | missing
commit_authorization: authorized | missing
landing_authorization: authorized | missing
  • A PR number or branch name selects review/polish scope; it does not authorize checkout. Set branch_mutation_authorization: authorized only when the current user or upstream owner explicitly requests the switch/worktree, or the user accepts the concrete checkout/isolation action after it is disclosed.
  • Set local_fix_authorization: authorized only when the current user explicitly requests polishing/fixes or the upstream handoff explicitly owns local apply. A route recommendation, branch target, or tool permission is not mutation authority.
  • Set commit_authorization: authorized only for an explicit commit request. done is a completion signal, not commit authorization.
  • Set landing_authorization: authorized only for an explicit push/PR request. Without landing authorization, do not push and do not open a PR.
  • These facts are non-transitive: local fixes do not imply checkout, commit, or landing; commit does not imply landing.

Phase 0: Get on the right branch

  1. If blank, use the current branch.
  2. If a PR number or branch name was provided, resolve it as scope and probe for existing worktrees without switching. When it is not the current checkout:
    • with branch_mutation_authorization: authorized, use the explicitly approved existing-worktree/checkout action;
    • otherwise stop before mutation with branch_mutation_authorization_missing, name the current and requested refs, and ask the user to switch themselves or authorize the exact action.
  3. Verify the selected checkout is not main/master.

Phase 1: Start the dev server

The scripts below ship in this skill's scripts/ directory. The Bash tool's working directory is the user's project, not the skill directory, so a bare scripts/<name> path will not resolve — invoke each by the skill's own absolute path. Every runnable block below sets SKILL_DIR inline (shell state does not persist between Bash tool calls, so each command must carry it); replace the <absolute path …> placeholder with the directory you loaded this spec-polish SKILL.md from before running.

1.1 Check for .claude/launch.json
bash
SKILL_DIR="<absolute path of the directory containing this SKILL.md>";
bash "$SKILL_DIR/scripts/read-launch-json.sh"

If it finds a configuration, use it — the user already told us how to start the project.

Show full SKILL.md (436 more words)Show less
1.2 Auto-detect (when no launch.json)

Identify the framework:

bash
SKILL_DIR="<absolute path of the directory containing this SKILL.md>";
bash "$SKILL_DIR/scripts/detect-project-type.sh"

Route by type to the matching recipe reference for start command and port defaults:

TypeRecipe
railsreferences/dev-server-rails.md
nextreferences/dev-server-next.md
vitereferences/dev-server-vite.md
nuxtreferences/dev-server-nuxt.md
astroreferences/dev-server-astro.md
remixreferences/dev-server-remix.md
sveltekitreferences/dev-server-sveltekit.md
procfilereferences/dev-server-procfile.md
unknownAsk the user how to start the project

For framework types that need a package manager, run the resolver and substitute the result into the start command:

bash
SKILL_DIR="<absolute path of the directory containing this SKILL.md>";
bash "$SKILL_DIR/scripts/resolve-package-manager.sh"

Resolve the port:

bash
SKILL_DIR="<absolute path of the directory containing this SKILL.md>";
bash "$SKILL_DIR/scripts/resolve-port.sh" --type <type>
1.3 Start the server

Start the dev server in the background, log output to a temp file. Probe http://localhost:<port> for up to 30 seconds. If it doesn't come up, show the last 20 lines of the log and ask the user what to do.

1.4 Open in browser

Load references/ide-detection.md for the env-var probe table. Open the browser using the IDE's mechanism (Claude Code → open, Cursor → Cursor browser, VS Code → Simple Browser).

Tell the user:

Dev server running on http://localhost:<port>
Browse the feature and tell me what could be better.

Phase 2: Iterate

This is the core loop. The user browses the feature and tells you what to improve. You fix it. Repeat until they're happy.

  • When the user describes something to fix, that explicit request may authorize that bounded fix. Re-resolve local_fix_authorization for the requested change; when authorized, make only that scoped change and let the dev server hot-reload. When missing, describe the proposed fix without editing and return local_fix_authorization_missing.
  • When the user asks to check something → invoke the internal spec-test-browser owner with current target-origin:http://127.0.0.1:<port> (normalize the caller-owned server handoff to its exact loopback root before invoking). Pass only the smallest repo-relative route/action plan needed for the check. spec-polish never constructs agent-browser argv or bypasses the owner's exact-origin, durable-effect, synthetic-input, private-evidence, or cleanup gates. Consume only structured route/step facts and private screenshot/inspection refs. If the owner returns not_supported or not_run, surface its reason code, recommend spec-runtime-setup when capability is missing, and continue the human browser loop without claiming automated inspection.
  • When the user says they're done, stop the loop. If commit_authorization: authorized, commit only run-owned verified paths. Otherwise leave the changes uncommitted and return commit_status: not-created with reason commit_authorization_missing.

Return a compact closeout with changed paths, verification notes, commit_status, landing_status, and limitations. This workflow never infers push or PR authority from completion.

References

Reference files (loaded on demand):

  • references/launch-json-schema.md — launch.json schema + per-framework stubs
  • references/ide-detection.md — host IDE detection and browser-handoff
  • references/dev-server-detection.md — port resolution documentation
  • references/dev-server-rails.md — Rails dev-server defaults
  • references/dev-server-next.md — Next.js dev-server defaults
  • references/dev-server-vite.md — Vite dev-server defaults
  • references/dev-server-nuxt.md — Nuxt dev-server defaults
  • references/dev-server-astro.md — Astro dev-server defaults
  • references/dev-server-remix.md — Remix dev-server defaults
  • references/dev-server-sveltekit.md — SvelteKit dev-server defaults
  • references/dev-server-procfile.md — Procfile-based dev-server defaults

Scripts (invoked via bash "$SKILL_DIR/scripts/<name>" — see Phase 1 for SKILL_DIR):

  • scripts/read-launch-json.sh — launch.json reader
  • scripts/detect-project-type.sh — project-type classifier
  • scripts/resolve-package-manager.sh — lockfile-based package-manager resolver
  • scripts/resolve-port.sh — port resolution cascade

© leo-kuang-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 23 other files (scripts, references) in skills/spec-polish of leo-kuang-ai/spec-first.

  • SKILL.md
  • evals/cases/r2-screenshot-review-routes-out.yaml
  • evals/cases/review-request-routes-out.yaml
  • evals/eval.yaml
  • evals/fixtures/repos/mini-ledger/README.md
  • evals/fixtures/repos/mini-ledger/package.json
  • evals/fixtures/repos/mini-ledger/src/server.js
  • evals/fixtures/scripts/asks-a-question.sh
  • references/dev-server-astro.md
  • references/dev-server-detection.md
  • references/dev-server-next.md
  • references/dev-server-nuxt.md
  • references/dev-server-procfile.md
  • … and 11 more

Open the folder on GitHubat commit 74655dc

Compare with similar skills

Spec Polish next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spec Polish compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spec Polish this skillleo-kuang-ai/spec-first107—~2.5kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow155k—~3.5kAutomated safety check: NotesMIT
Mole Bug Patternstw93/Mole70k—~2kAutomated safety check: PassGPL-3.0
Backend Code Reviewlanggenius/dify158k—~676Automated safety check: PassCustom licence

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    155k GitHub stars~3.5k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    70k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from leo-kuang-ai/spec-first

All 35 skills in this repo
  • Spec App Consistency Audit

    leo-kuang-ai/spec-first

    Audit mobile App PRD/Figma/local-source consistency across page routes, KMP/Clean Architecture, components, analytics, i18n, engineering quality, and industry lenses before runtime validation; use…

    107 GitHub stars~4.6k tokensUpdated 2 days ago
    Auto-check passed
  • Spec Handoff

    leo-kuang-ai/spec-first

    Create a durable cross-session handoff or resume from a user-selected continuity source.

    107 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • Spec Pov

    leo-kuang-ai/spec-first

    Give a decisive, project-grounded verdict on an external input — judged against the current project, not in the abstract.

    107 GitHub stars~4.5k tokensUpdated 2 days ago
    Auto-check passed
  • Spec Resolve PR Feedback

    leo-kuang-ai/spec-first

    Resolve PR review feedback by evaluating validity and fixing issues with conflict-aware resolver dispatch.

    107 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check: notes
  • Spec Riffrec Feedback Analysis

    leo-kuang-ai/spec-first

    Analyze explicit Riffrec product-feedback captures, including riffrec-.zip, the Riffrec session.json + events.json + recording.webm + voice.webm bundle, or media/notes the user identifies as a…

    107 GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Spec Compound

    leo-kuang-ai/spec-first

    Document a recently solved problem or durable project vocabulary in docs/solutions/ or CONCEPTS.md.

    107 GitHub stars~18k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Spec Polish

What does Spec Polish do?

Start the dev server, inspect the feature in browser, and iterate on polish. Spec Polish is an agent skill from leo-kuang-ai/spec-first. Start the dev server, inspect the feature in browser, and iterate on polish.

When should I use Spec Polish?

Spec Polish fits situations like: tasks that involve Code review.

How do I install Spec Polish in Claude Code?

Run `npx skills add leo-kuang-ai/spec-first --skill spec-polish -a claude-code`. Or copy the skill folder (skills/spec-polish in leo-kuang-ai/spec-first) into .claude/skills/spec-polish in your project. Claude Code loads it when a task matches its description.

How do I install Spec Polish in Codex?

Run `npx skills add leo-kuang-ai/spec-first --skill spec-polish -a codex`. Or copy the skill folder (skills/spec-polish in leo-kuang-ai/spec-first) into .agents/skills/spec-polish in your project. Codex loads it when a task matches its description.

Can I use Spec Polish in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add leo-kuang-ai/spec-first --skill spec-polish -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spec-polish, .gemini/skills/spec-polish, .github/skills/spec-polish and .opencode/skills/spec-polish in your project.

What does Spec Polish need to run?

Going by SKILL.md and its folder, Spec Polish needs JavaScript and a shell for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: Node.js; A Bash shell.

Does Spec Polish access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Spec Polish safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Spec Polish use?

Spec Polish is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spec Polish use?

About 2.5k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.5k tokens, read only when the agent opens those files.

What are the alternatives to Spec Polish?

Skills that share tags, products or a category with Spec Polish: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 155k stars) and Mole Bug Patterns (tw93/Mole, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spec Polish?

leo-kuang-ai (a GitHub user) maintains it in leo-kuang-ai/spec-first, which has 107 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 8, 2026.

Source: leo-kuang-ai/spec-first on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.