Official agent skill

Webspec Index

by SAP in SAP/project-foxhound

Use webspec-index to query WHATWG, W3C, IETF and TC39 web specifications from the command line

OfficialGPL-3.0Auto-check passedSecurity

Install Webspec Index

skills CLI
$ npx skills add SAP/project-foxhound --skill webspec-index -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SAP/project-foxhound webspec-index --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SAP/project-foxhound.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/webspec-index .claude/skills/webspec-index && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
webspec-index
GitHub stars
180
Used in
2 other repos
Token cost
~1.1k tokens
SKILL.md length
362 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
GPL-3.0

At a glance

Use webspec-index to query WHATWG, W3C, IETF and TC39 web specifications from the command line

  • Security work in your project
  • SKILL.md covers Available specs, Installation, Commands and Usage patterns for Gecko…
  • Calls cargo; reaches html.spec.whatwg.org

What it does

Webspec Index is an agent skill from SAP/project-foxhound, published by the product's own GitHub organization. Use webspec-index to query WHATWG, W3C, IETF and TC39 web specifications from the command line

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: A web browser with dynamic data-flow tracking enabled in the Javascript engine and DOM, based on Mozilla Firefox (https://github.com/mozilla-firefox/firefox). It can be used to… The licence is GPL-3.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/webspec-index”

What it can do on your machine

Read from SKILL.md and the folder at commit 9dcb850. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • html.spec.whatwg.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Webspec Index loads about 1.1k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 362 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SAP/project-foxhound at commit 9dcb850, republished under its GPL-3.0 licence (© SAP). 362 words, ~1,072 tokens.

Download SKILL.mdSave it as .claude/skills/webspec-index/SKILL.md (or your agent's skills folder).
name
webspec-index
description
Use webspec-index to query WHATWG, W3C, IETF and TC39 web specifications from the command line

webspec-index

Query WHATWG, W3C, IETF and TC39 web specifications from the command line.

Use webspec-index whenever you need to understand what a web spec says — algorithm steps, section content, cross-references, or whether a spec anchor exists. Specs are fetched and cached locally on first use.

Available specs

Assume that all specs from WHATWG, W3C, IETF and TC39 are indexed. If in doubt, run webspec-index specs to list all spec names and their base URLs.

Installation

If webspec-index is not already available in your environment, you can install it via cargo:

bash
cargo binstall webspec-index
# or
cargo install webspec-index

Commands

Always put the section identifier in quotes to avoid shell interpretation of #.

Look up a spec section
bash
webspec-index query 'HTML#navigate'
webspec-index query 'DOM#concept-tree'
webspec-index query 'CSS-GRID#grid-container'
webspec-index query 'https://html.spec.whatwg.org/#navigate'
webspec-index query 'DOM#concept-tree'
webspec-index query "RFC9000#section-22"
webspec-index query "draft-ietf-tsvwg-sctp-dtls-chunk#name-security-considerations"

Returns the section's title, type (heading/algorithm/definition), full content as markdown, navigation tree (parent/prev/next/children), and cross-references. This is the primary command — use it to read what a spec section says.

Use --format markdown for human-readable output, or default --format json for structured data.

Search across specs
bash
webspec-index search "tree order"
webspec-index search "navigate" --spec HTML --limit 5

Full-text search with snippets. Use --spec to narrow to one spec.

Check if a section exists
bash
webspec-index exists 'HTML#navigate'

Exit code 0 = found, 1 = not found. Use this to validate anchor names before referencing them.

Find anchors by pattern
bash
webspec-index anchors "*-tree" --spec DOM
webspec-index anchors "concept-*" --spec HTML
webspec-index anchors "dom-*assign*"

Glob matching (* wildcard). Useful when you know part of an anchor name but not the exact id.

List all sections in a spec
bash
webspec-index list DOM

Returns all heading-level sections with their anchors, titles, types, and depths.

Show full SKILL.md (139 more words)Show less
Cross-references
bash
webspec-index refs 'HTML#navigate' --direction incoming
webspec-index refs 'HTML#navigate' --direction outgoing
webspec-index refs 'HTML#navigate'

Shows which sections reference this one (incoming), which sections this one references (outgoing), or both (default). Useful for understanding how a concept connects across specs.

Update specs
bash
webspec-index update
webspec-index update --spec HTML
webspec-index update --force

Fetches latest spec versions. Uses 24h cache unless --force is given. Specs are auto-fetched on first query, so you rarely need this.

Usage patterns for Gecko development

Understanding what you're implementing

When working on a bug that references a spec algorithm:

bash
# Read the algorithm you need to implement
webspec-index query 'HTML#navigate' --format markdown

# Check what concepts it references
webspec-index refs 'HTML#navigate' --direction outgoing

# Look up a referenced concept you don't understand
webspec-index query 'INFRA#ordered-set'
Finding the right spec section

When you see a spec URL in code comments (e.g., https://html.spec.whatwg.org/#navigate), or a step comment like // Step 3.2, query the section to understand the algorithm:

bash
webspec-index query 'https://html.spec.whatwg.org/#navigate'

When you know a concept but not its exact anchor:

bash
# Search by text
webspec-index search "tree order" --spec DOM

# Or find by anchor pattern
webspec-index anchors "*tree*order*" --spec DOM
Verifying spec anchors

Before adding a spec URL to a code comment, verify the anchor exists:

bash
webspec-index exists 'HTML#navigate' && echo "valid"
Understanding cross-spec dependencies

To see what other specs depend on a concept you're changing:

bash
webspec-index refs 'DOM#concept-tree' --direction incoming

© SAP, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/webspec-index of SAP/project-foxhound.

Open the folder on GitHubat commit 9dcb850

Used in 3 other repositories

We found 7 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in SAP/project-foxhound, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Webspec Index next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Webspec Index compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Webspec Index this skillSAP/project-foxhound1802 repos~1.1kAutomated safety check: PassGPL-3.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4801 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    480 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from SAP/project-foxhound

All 10 skills in this repo
  • Accessibility Frontend Review

    SAP/project-foxhound

    Official

    Performs an accessibility code review of a local diff or Phabricator revision in the style of the Firefox accessibility team.

    180 GitHub starsUsed in 2 repos~3.2k tokens
    Auto-check passed
  • JS Perf Investigation

    SAP/project-foxhound

    Official

    Structured performance opportunity investigation for SpiderMonkey (the Firefox JavaScript engine).

    180 GitHub starsUsed in 2 repos~4.1k tokens
    Auto-check passed
  • Bug Filing

    SAP/project-foxhound

    Official

    File a Bugzilla bug for Firefox/Gecko work, or draft a bug summary and description.

    180 GitHub starsUsed in 2 repos~828 tokens
    Auto-check passed
  • Specmap

    SAP/project-foxhound

    Official

    Map relationships between a web spec section, its Firefox implementation code, and Web Platform Tests.

    180 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Stmo

    SAP/project-foxhound

    Official

    Manage Redash queries and dashboards on Mozilla's STMO (sql.telemetry.mozilla.org) using stmo-cli.

    180 GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • Android New Module

    SAP/project-foxhound

    Official

    Guide for creating new Android gradle modules in the android-components project.

    180 GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed

Categories

Questions about Webspec Index

What does Webspec Index do?

Use webspec-index to query WHATWG, W3C, IETF and TC39 web specifications from the command line. Webspec Index is an agent skill from SAP/project-foxhound, published by the product's own GitHub organization.

When should I use Webspec Index?

Webspec Index fits situations like: security work in your project.

How do I install Webspec Index in Claude Code?

Run `npx skills add SAP/project-foxhound --skill webspec-index -a claude-code`. Or copy the skill folder (.agents/skills/webspec-index in SAP/project-foxhound) into .claude/skills/webspec-index in your project. Claude Code loads it when a task matches its description.

How do I install Webspec Index in Codex?

Run `npx skills add SAP/project-foxhound --skill webspec-index -a codex`. Or copy the skill folder (.agents/skills/webspec-index in SAP/project-foxhound) into .agents/skills/webspec-index in your project. Codex loads it when a task matches its description.

Can I use Webspec Index in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SAP/project-foxhound --skill webspec-index -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/webspec-index, .gemini/skills/webspec-index, .github/skills/webspec-index and .opencode/skills/webspec-index in your project.

What does Webspec Index need to run?

Going by SKILL.md and its folder, Webspec Index needs the command-line tools its instructions call (cargo).

Does Webspec Index access the network?

SKILL.md names 1 domain. In commands or code: html.spec.whatwg.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Webspec Index safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Webspec Index use?

Webspec Index is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Webspec Index use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Webspec Index?

Skills that share tags, products or a category with Webspec Index: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Webspec Index?

SAP (a GitHub organization, an official publisher) maintains it in SAP/project-foxhound, which has 180 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 6, 2026.

Source: SAP/project-foxhound on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.