Agent skill

Contract Builder

by MageByte-Zero in MageByte-Zero/spec-superflow

Maintain an execution contract only for an existing legacy change that requires one.

MITAuto-check passedDevelopment

Install Contract Builder

skills CLI
$ npx skills add MageByte-Zero/spec-superflow --skill contract-builder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MageByte-Zero/spec-superflow contract-builder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MageByte-Zero/spec-superflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/contract-builder .claude/skills/contract-builder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
contract-builder
GitHub stars
839
Used in
1 other repo
Token cost
~1.3k tokens
SKILL.md length
605 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Maintain an execution contract only for an existing legacy change that requires one.

  • Works in 4 steps: List every SHALL/MUST from specs/ → Verify each is reflected in Approved… → Flag unmapped requirements in Escalation… → …
  • Development work in your project
  • SKILL.md covers Bundled runtime, Artifact Language, Artifact Mapping and Cross-Check: Requirement…, plus 7 more sections
  • Calls node

What it does

Contract Builder is an agent skill from MageByte-Zero/spec-superflow. Maintain an execution contract only for an existing legacy change that requires one. New direct/planned changes do not invoke this skill when a contract is absent.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: 源码级融合 OpenSpec 规划引擎 + Superpowers 执行纪律的 AI 编程工作流插件。17 平台支持,9 skills,Spec-first,契约驱动。 The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/contract-builder”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. List every SHALL/MUST from specs/
  2. Verify each is reflected in Approved Behavior, has a test obligation, and appears in at least one batch
  3. Flag unmapped requirements in Escalation Rules
  4. Note cross-batch dependencies

What it can do on your machine

Read from SKILL.md and the folder at commit 25d9b0c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Contract Builder loads about 1.3k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 605 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MageByte-Zero/spec-superflow at commit 25d9b0c, republished under its MIT licence (© MageByte-Zero). 605 words, ~1,286 tokens.

Download SKILL.mdSave it as .claude/skills/contract-builder/SKILL.md (or your agent's skills folder).
name
contract-builder
description
Maintain an execution contract only for an existing legacy change that requires one. New direct/planned changes do not invoke this skill when a contract is absent.

Contract Builder

Bundled runtime

Before executing a CLI line below, replace its leading SSF with node "<plugin-root>/scripts/spec-superflow.mjs"; <plugin-root> is the absolute directory two levels above this file. Never run SSF literally or call an ssf from PATH.

Legacy compatibility only: new planned changes use proposal.md + tasks.md and SSF workflow start --path planned. Do not generate a contract or request a second approval for them. Read the remaining instructions only for an existing legacy change.

Converts planning artifacts into a single execution handshake: execution-contract.md. Load the baseline with SSF runtime asset read templates/execution-contract.md.

Read before generating: .spec-superflow.yaml (especially dp_0_decisions), proposal.md, specs/, design.md, tasks.md, then load docs/artifact-contract.md with SSF runtime asset read docs/artifact-contract.md.

Enter bridging before writing the contract; skip the transition if already there. Honor configured specs/design omissions. Reference requirement IDs and task IDs instead of copying their full text; preserve scope, obligations, tests, and review policy.

Artifact Language

Read artifact_language=<concrete-language> from dp_0_decisions. Generate execution-contract.md in the same language as that resolved value and the approved planning artifacts. Preserve required schema keywords and code identifiers verbatim; language consistency applies to explanatory prose and headings. If the concrete artifact language is missing or still auto, route back to workflow-start before writing the contract instead of guessing or silently defaulting to English.

Artifact Mapping

SourceExtract
proposal.md → ## Why + ## What ChangesIntent Lock (problem + scope)
proposal.md → ## Scope > ### Out of ScopeScope Fence
specs/ → each ### Requirement:Approved Requirements, Scenarios, Test Obligations
design.md → ## DecisionsArchitecture, Interface, Dependency Constraints
tasks.md → numbered task groupsExecution Batches, Completion Definitions, Review Timing

Cross-Check: Requirement Coverage

Before finalizing:

  1. List every SHALL/MUST from specs/
  2. Verify each is reflected in Approved Behavior, has a test obligation, and appears in at least one batch
  3. Flag unmapped requirements in Escalation Rules
  4. Note cross-batch dependencies

Contract Structure

Must make obvious: approved behavior, out-of-scope, constraints, batches, test obligations, review gates, and conditions that force a rewind to planning. Prefer compression over repeating planning details.

Approval Model (DP-3)

After drafting: summarize handoff rules, identify ambiguity and flag unmapped requirements. Reuse explicit approval already covering this exact contract; otherwise request it once, together with any still-pending planning decisions and the default Native execution choice. Approval of scope alone does not approve a contract that has not been shown. Never ask the user to approve the same unchanged contract twice. After approval:

bash
SSF state set <change-dir> dp_3_result "approved: <summary>"
SSF state set <change-dir> dp_3_timestamp now
SSF state rebuild <change-dir>

Advance the state after approval:

bash
SSF state transition <change-dir> approved-for-build

DP-3 is a hard gate — no implementation without this record.

Show full SKILL.md (204 more words)Show less

Stale Contract Detection

Refresh if: scope changed in proposal, requirements changed in specs, constraints changed in design, batches changed materially in tasks, or the contract no longer matches intent.

Hotfix Mode

Generate a minimal contract only for a legacy Hotfix: Intent Lock (one sentence), Task List (numbered), Approval Gate (DP-3). Skip Scope Fence, Build Rules, Review Gates, Test Evidence. Still requires DP-3 approval. Quick direct execution and direct incident Hotfix do not invoke this skill; they use the signed receipt and finish with test_result: pass instead.

Guardrails

  • Do not continue to implementation if ambiguity remains
  • Do not approve the contract on the user's behalf
  • Do not skip the contract because planning docs look complete
  • Flag unmapped requirements; do not silently drop them

Post-Generation

The approved contract is recorded by state rebuild in the DP-3 sequence above, before the guarded transition. This applies to Full and legacy Hotfix. Do not refresh hashes merely to suppress an unapproved content change.

Exception Handling

  • Parse failures: Report specific file and section. Suggest re-running spec-writer.
  • Missing files: List every missing artifact. Route back to spec-writer.
  • User interruption: Re-read all artifacts on resume; check contract staleness via content comparison.
  • Validation failure: Flag unmapped requirements in Escalation Rules and approval summary.

© MageByte-Zero, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/contract-builder of MageByte-Zero/spec-superflow.

Open the folder on GitHubat commit 25d9b0c

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in MageByte-Zero/spec-superflow, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Contract Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Contract Builder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Contract Builder this skillMageByte-Zero/spec-superflow8391 repos~1.3kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k24 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 24 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Guidelines

    akash-network/node

    Behavioral guidelines to reduce common LLM coding mistakes. An agent skill from akash-network/node.

    1.1k GitHub starsUsed in 22 repos~577 tokens
    DevelopmentAuto-check passed

More from MageByte-Zero/spec-superflow

All 9 skills in this repo
  • Bug Investigator

    MageByte-Zero/spec-superflow

    A skill your agent uses when encountering any bug, test failure, or unexpected behavior during spec-superflow execution, before proposing fixes.

    839 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed
  • Need Explorer

    MageByte-Zero/spec-superflow

    Clarify intent, scope, constraints, and success criteria before artifact creation.

    839 GitHub starsUsed in 1 repo~805 tokens
    Auto-check passed
  • Spec Writer

    MageByte-Zero/spec-superflow

    Create or refine spec-superflow planning artifacts. An agent skill from MageByte-Zero/spec-superflow.

    839 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed
  • Build Executor

    MageByte-Zero/spec-superflow

    Execute an active direct request or approved planned change.

    839 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Release Archivist

    MageByte-Zero/spec-superflow

    Close out a spec-superflow change with verification, summary, and archive readiness.

    839 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Workflow Start

    MageByte-Zero/spec-superflow

    Primary entry point for the spec-superflow state-machine workflow.

    839 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed

Categories

Questions about Contract Builder

What does Contract Builder do?

Maintain an execution contract only for an existing legacy change that requires one. Contract Builder is an agent skill from MageByte-Zero/spec-superflow. Maintain an execution contract only for an existing legacy change that requires one.

When should I use Contract Builder?

Contract Builder fits situations like: development work in your project.

How do I install Contract Builder in Claude Code?

Run `npx skills add MageByte-Zero/spec-superflow --skill contract-builder -a claude-code`. Or copy the skill folder (skills/contract-builder in MageByte-Zero/spec-superflow) into .claude/skills/contract-builder in your project. Claude Code loads it when a task matches its description.

How do I install Contract Builder in Codex?

Run `npx skills add MageByte-Zero/spec-superflow --skill contract-builder -a codex`. Or copy the skill folder (skills/contract-builder in MageByte-Zero/spec-superflow) into .agents/skills/contract-builder in your project. Codex loads it when a task matches its description.

Can I use Contract Builder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MageByte-Zero/spec-superflow --skill contract-builder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/contract-builder, .gemini/skills/contract-builder, .github/skills/contract-builder and .opencode/skills/contract-builder in your project.

What does Contract Builder need to run?

Going by SKILL.md and its folder, Contract Builder needs the command-line tools its instructions call (node).

Does Contract Builder access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Contract Builder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Contract Builder use?

Contract Builder is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Contract Builder use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Contract Builder?

Skills that share tags, products or a category with Contract Builder: Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars) and Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Contract Builder?

MageByte-Zero (a GitHub user) maintains it in MageByte-Zero/spec-superflow, which has 839 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 1, 2026.

Source: MageByte-Zero/spec-superflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.