Compare implementation against specifications, identify gaps and issues.

MITAuto-check passedDevelopment

Install Sdd Audit

skills CLI
$ npx skills add madebyaris/spec-kit-command-cursor --skill sdd-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install madebyaris/spec-kit-command-cursor sdd-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/madebyaris/spec-kit-command-cursor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/sdd-audit .claude/skills/sdd-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sdd-audit
GitHub stars
197
Token cost
~405 tokens
SKILL.md length
133 words
Files
3 (incl. scripts, references)
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Compare implementation against specifications, identify gaps and issues.

  • Works in 5 steps: Load specs: Read spec.md → plan.md →… → Identify scope: Check todo-list.md for… → Inspect code: Review implementation for… → …
  • Quality assurance
  • SKILL.md covers When to Use, Workflow, Audit Checklist and Severity Levels, plus 2 more sections
  • Runs Shell scripts from its folder

What it does

Sdd Audit is an agent skill from madebyaris/spec-kit-command-cursor. Compare implementation against specifications, identify gaps and issues. Use for code review, quality assurance, and verifying spec compliance.

Its SKILL.md is about 410 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/checklist.md` and `scripts/validate.sh`).

It sits in Development, covering QA and bug reports and Code review. The repository describes itself as: SDD toolkit for Cursor IDE — /specify, /plan, /tasks to turn ideas into specs, plans, and actionable tasks. The licence is MIT.

When your agent uses it

  • Quality assurance
  • Verifying spec compliance

Example prompts

  • “/sdd-audit”

Requirements

  • A Bash shell

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Load specs: Read spec.md → plan.md → tasks.md
  2. Identify scope: Check todo-list.md for completed work
  3. Inspect code: Review implementation for each task
  4. Gap analysis: Compare spec requirements vs actual code
  5. Generate report: Structured findings with severity levels

What it can do on your machine

Read from SKILL.md and the folder at commit 36b26f9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sdd Audit loads about 405 tokens when it runs, and up to ~977 if it reads all its reference files. Until then it costs about 38 tokens; SKILL.md has 133 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~405
With references · SKILL.md plus every file in references/, read only if the agent opens them
~977

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from madebyaris/spec-kit-command-cursor at commit 36b26f9, republished under its MIT licence (© madebyaris). 133 words, ~405 tokens.

Download SKILL.mdSave it as .claude/skills/sdd-audit/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
sdd-audit
description
Compare implementation against specifications, identify gaps and issues. Use for code review, quality assurance, and verifying spec compliance.

SDD Audit Skill

Compare implementations against specifications and generate structured review reports.

When to Use

  • Code review before marking tasks complete
  • Quality assurance checks
  • Verifying implementation matches spec

Workflow

  1. Load specs: Read spec.md → plan.md → tasks.md
  2. Identify scope: Check todo-list.md for completed work
  3. Inspect code: Review implementation for each task
  4. Gap analysis: Compare spec requirements vs actual code
  5. Generate report: Structured findings with severity levels

Audit Checklist

Reference references/checklist.md for the complete audit checklist.

Severity Levels

  • CRITICAL: Broken functionality, security risk, release blocker
  • MAJOR: Logic error, missing feature, significant bug
  • MINOR: Style issue, optimization opportunity, cleanup
  • OUTDATED: Code correct but spec needs updating

Report Format

markdown
## Audit Report: [Feature]

**Status:** Pass | Fail | Warnings

### Quick Stats
- CRITICAL: [N] | MAJOR: [N] | MINOR: [N]

### Review Comments
| ID | Severity | Location | Issue | Recommendation |

### Spec Compliance
| Requirement | Status | Evidence |

### Recommended Actions
1. [Priority action]

Integration

  • Works with sdd-verifier subagent for automated validation
  • Can trigger scripts/validate.sh for automated checks
  • Use the ask question tool if audit criteria are unclear

© madebyaris, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in .cursor/skills/sdd-audit of madebyaris/spec-kit-command-cursor.

  • SKILL.md
  • references/checklist.md
  • scripts/validate.sh

Open the folder on GitHubat commit 36b26f9

Compare with similar skills

Sdd Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sdd Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sdd Audit this skillmadebyaris/spec-kit-command-cursor197—~405Automated safety check: PassMIT
Pre-Merge Checkjsmastery-pro/skills1.5k—~1.1kAutomated safety check: NotesMIT
Fix The Classjoetawil7/first-pass95—~1.5kAutomated safety check: PassMIT
Write Fix Briefn1m21n/Infinite271—~2.9kAutomated safety check: PassCustom licence
Feature Verifysd0xdev/sd0x-harness192—~3.2kAutomated safety check: NotesMIT
Rtl Equivalence CheckerArabelaTso/Skills-4-SE253—~2.5kAutomated safety check: PassApache-2.0

Similar skills

  • Pre-Merge Check

    jsmastery-pro/skills

    A gate before merge: verify runs the real app against the spec, and review has a different model do a senior code review, without editing code.

    1.5k GitHub stars~1.1k tokensUpdated 2 mo ago
    DevelopmentAuto-check: notes
  • Fix The Class

    joetawil7/first-pass

    Bug-fix routine that fixes the whole class of bug, not just the reported instance.

    95 GitHub stars~1.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Write Fix Brief

    n1m21n/Infinite

    Turn a bug report, review findings, broken-UI screenshot or new-node idea into a verified, file/line-precise implementation prompt after checking the real code.

    271 GitHub stars~2.9k tokensUpdated today
    Testing & QAAuto-check passed
  • Feature Verify

    sd0xdev/sd0x-harness

    Feature verification (READ-ONLY, P0-P5). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~3.2k tokensUpdated 2 days ago
    Testing & QAAuto-check: notes
  • Rtl Equivalence Checker

    ArabelaTso/Skills-4-SE

    Hardware verification tool for checking functional equivalence between two RTL designs (Verilog).

    253 GitHub stars~2.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Spec Dogfood

    leo-kuang-ai/spec-first

    Hands-off, diff-scoped browser QA of the active branch or PR.

    107 GitHub stars~6.1k tokensUpdated 2 days ago
    Testing & QAAuto-check: notes

More from madebyaris/spec-kit-command-cursor

  • Sdd Evolve

    madebyaris/spec-kit-command-cursor

    Update specifications with discoveries made during development.

    197 GitHub stars~562 tokensUpdated 3 mo ago
    Auto-check passed
  • Sdd Implementation

    madebyaris/spec-kit-command-cursor

    Execute planned implementations following todo-lists systematically.

    197 GitHub stars~444 tokensUpdated 3 mo ago
    Auto-check passed
  • Sdd Research

    madebyaris/spec-kit-command-cursor

    Pattern investigation and technical research before specification.

    197 GitHub stars~1.3k tokensUpdated 3 mo ago
    Auto-check passed
  • Sdd Planning

    madebyaris/spec-kit-command-cursor

    Generate technical plans from specifications. An agent skill from madebyaris/spec-kit-command-cursor.

    197 GitHub stars~499 tokensUpdated 3 mo ago
    Auto-check passed
  • Sdd Memory

    madebyaris/spec-kit-command-cursor

    Recall and persist durable project knowledge (decisions, conventions, gotchas, architecture) across SDD sessions.

    197 GitHub stars~862 tokensUpdated 3 mo ago
    Auto-check passed

Questions about Sdd Audit

What does Sdd Audit do?

Compare implementation against specifications, identify gaps and issues. Sdd Audit is an agent skill from madebyaris/spec-kit-command-cursor. Compare implementation against specifications, identify gaps and issues.

When should I use Sdd Audit?

Sdd Audit fits situations like: quality assurance; verifying spec compliance.

How do I install Sdd Audit in Claude Code?

Run `npx skills add madebyaris/spec-kit-command-cursor --skill sdd-audit -a claude-code`. Or copy the skill folder (.cursor/skills/sdd-audit in madebyaris/spec-kit-command-cursor) into .claude/skills/sdd-audit in your project. Claude Code loads it when a task matches its description.

How do I install Sdd Audit in Codex?

Run `npx skills add madebyaris/spec-kit-command-cursor --skill sdd-audit -a codex`. Or copy the skill folder (.cursor/skills/sdd-audit in madebyaris/spec-kit-command-cursor) into .agents/skills/sdd-audit in your project. Codex loads it when a task matches its description.

Can I use Sdd Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add madebyaris/spec-kit-command-cursor --skill sdd-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sdd-audit, .gemini/skills/sdd-audit, .github/skills/sdd-audit and .opencode/skills/sdd-audit in your project.

What does Sdd Audit need to run?

Going by SKILL.md and its folder, Sdd Audit needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Sdd Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sdd Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Sdd Audit use?

Sdd Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sdd Audit use?

About 405 tokens (SKILL.md is roughly 1.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 572 tokens, read only when the agent opens those files.

What are the alternatives to Sdd Audit?

Skills that share tags, products or a category with Sdd Audit: Pre-Merge Check (jsmastery-pro/skills, 1.5k stars), Fix The Class (joetawil7/first-pass, 95 stars), Write Fix Brief (n1m21n/Infinite, 271 stars) and Feature Verify (sd0xdev/sd0x-harness, 192 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sdd Audit?

madebyaris (a GitHub user) maintains it in madebyaris/spec-kit-command-cursor, which has 197 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on June 22, 2026.

Source: madebyaris/spec-kit-command-cursor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.