Agent skill

Necessity Audit

by sd0xdev in sd0xdev/sd0x-harness

Necessity audit for over-designed spec elements. An agent skill from sd0xdev/sd0x-harness.

MITAuto-check passedDevelopment

Install Necessity Audit

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill necessity-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness necessity-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/necessity-audit .claude/skills/necessity-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
necessity-audit
GitHub stars
192
Token cost
~2.7k tokens
SKILL.md length
908 words
Files
8 (incl. references)
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Necessity audit for over-designed spec elements. An agent skill from sd0xdev/sd0x-harness.

  • : auditing lifecycle spec (1-requirements / 2-tech-spec / 3-architecture) for YAGNI/KISS violations
  • SKILL.md covers Non-Negotiable Rules, Trigger, When NOT to Use and Arguments, plus 6 more sections
  • Calls node; needs AUDIT_TOKEN
  • Challenging necessity of FRs/NFRs/abstractions/configs via Codex adversarial debate

What it does

Necessity Audit is an agent skill from sd0xdev/sd0x-harness. Necessity audit for over-designed spec elements. Use when: auditing lifecycle spec (1-requirements / 2-tech-spec / 3-architecture) for YAGNI/KISS violations, challenging necessity of FRs/NFRs/abstractions/configs via Codex adversarial debate. Not for: FP reasoning validity (use /codex-review-spec), completeness check (use /feature-completeness), detail review (use /codex-review-doc), or code-level simplification (use /simplify).

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/dimensions.md`, `references/output-template.md` and `references/phase-a-classify.md`).

It sits in Development. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • : auditing lifecycle spec (1-requirements / 2-tech-spec / 3-architecture) for YAGNI/KISS violations
  • Challenging necessity of FRs/NFRs/abstractions/configs via Codex adversarial debate

Example prompts

  • “/necessity-audit”

Requirements

  • A credential in AUDIT_TOKEN
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Write, Bash(node:*), Bash(mktemp:*), Skill

What it can do on your machine

Read from SKILL.md and the folder at commit a4d4bc1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Write
    • Bash(node:*)
    • Bash(mktemp:*)
    • Skill

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AUDIT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Necessity Audit loads about 2.7k tokens when it runs, and up to ~7.3k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 908 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit a4d4bc1, republished under its MIT licence (© sd0xdev). 908 words, ~2,658 tokens.

Download SKILL.mdSave it as .claude/skills/necessity-audit/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
necessity-audit
description
Necessity audit for over-designed spec elements. Use when: auditing lifecycle spec (1-requirements / 2-tech-spec / 3-architecture) for YAGNI/KISS violations, challenging necessity of FRs/NFRs/abstractions/configs via Codex adversarial debate. Not for: FP reasoning validity (use /codex-review-spec), completeness check (use /feature-completeness), detail review (use /codex-review-doc), or code-level simplification (use /simplify).
allowed-tools
Read, Grep, Glob, Write, Bash(node:*), Bash(mktemp:*), Skill

Necessity Audit

3-phase necessity audit with Codex adversarial debate. Identifies over-designed elements in lifecycle specs via 6-dimension YAGNI rubric.

Non-Negotiable Rules

SKILL.md is the normative source. Reference files elaborate but do not override.

#RuleViolation =
1Phase A classification output must NOT appear in Phase B debate topicAudit invalid
2Phase B must invoke /codex-brainstorm via Skill tool — a raw transport dispatch for debate is invalidAudit invalid
3Phase C report must include non-empty debate.threadIdReport rejected
4Phase C report must include Debate Conclusion referencing specific rounds (not blank / placeholder)Report rejected
5Output must start with ## Necessity Audit header and end with ✅ Audit Clear OR ⛔ Audit Revise sentinelAuto-loop cannot parse

Trigger

  • Keywords: necessity audit, over-design, YAGNI audit, spec necessity, 過度設計, over-engineered

When NOT to Use

Alternatives by intent
IntentUseNot this skill
「這段推理站得住嗎?」/codex-review-spec (planned) / /review-spec—
「這個 spec 完成了嗎?」/feature-completeness (planned)—
「這個 code 是否過度抽象?」/simplify / /refactor—
「這個實作符合產業標準嗎?」/best-practices—
「這個 spec 是否過度設計?需要砍嗎?」/necessity-audit ← this skill—
Chain recommendation

/codex-review-doc (detail) → /codex-review-spec (reasoning, planned) → /necessity-audit (necessity, this skill) → /feature-completeness (completeness, planned) → /review-spec (synthesis)

Arguments

ArgRequiredDefaultPurpose
<path>Yes—Target lifecycle spec (repo-relative)
--depth brief|normal|deepNonormalDimension coverage + equilibrium strictness
--continue <threadId>No—Resume Phase C per @skills/codex-code-review/references/codex-transport.md § Resume
--skip-preflightNofalseSkip state-read advisory; emits [PREFLIGHT SKIPPED] banner
--include-feasibilityNofalseAccept 0-feasibility-study.md (emits override banner)
--override <id>:<rationale>No (repeatable, ;-separated)—Mark Cut element as kept with justification
--output markdown|jsonNomarkdownOutput format

Workflow

Phase 0 preflight → Phase A classify → Phase B Codex debate → Phase C consolidate → Redact → Emit
Phase 0: Preflight (executable)

Scratch directory — read this before running any step. Each Bash invocation is a fresh shell: a variable assigned in one step does not exist in the next. Do not write TMPDIR=$(mktemp -d) and then reference $TMPDIR later — on macOS TMPDIR is an ambient variable already pointing at the shared temp root (/var/folders/…/T/), so later steps silently read and write there, and the final rm -rf $TMPDIR would target that shared root.

Instead: run mktemp -d once, read the path it prints, and substitute that literal absolute path into every later command. The placeholder <AUDIT_TMP_DIR> below marks each substitution site. Never name the variable TMPDIR.

bash
mktemp -d
# → e.g. /var/folders/ab/cd1234/T/tmp.XyZ123 — reuse this literal path below as <AUDIT_TMP_DIR>

Immediately claim it. The claim mints a one-time capability token and stores it in a marker inside the directory; the cleanup step requires that exact token back. This is what binds the delete to this run's directory rather than to any directory that merely looks like one — or to another concurrent audit's directory, which also carries a valid marker:

bash
node scripts/skills/necessity-audit/cleanup.js --claim "<AUDIT_TMP_DIR>"
# → token=3f9c…  (48 hex chars) — reuse this literal token in Phase 4 as <AUDIT_TOKEN>

Read the token= line it prints and carry that literal value to the cleanup step, the same way you carry the directory path. Like <AUDIT_TMP_DIR>, it cannot be held in a shell variable — each Bash invocation is a fresh shell.

bash
node scripts/skills/necessity-audit/preflight.js \
  --path <path> --depth <depth> \
  [--skip-preflight] [--include-feasibility] \
  --output "<AUDIT_TMP_DIR>/preflight.json"

Non-zero exit = hard block. Read <AUDIT_TMP_DIR>/preflight.json to continue.

Phase A: Claude classify (LLM)

Read target file with Read tool. Apply references/phase-a-classify.md template substituting ${TARGET_PATH}, ${DOC_KIND}, ${ACTIVE_DIMENSIONS}, ${GREENFIELD} from preflight.

Extract elements (FR / NFR / Component / Abstraction / Extensibility / Config), score each against active dimensions only (depth=brief → dims 1-3; normal/deep → dims 1-6), assign initial Keep/Review/Cut.

Write result: Write tool → <AUDIT_TMP_DIR>/phase-a.json with schema { elements: ClassifiedElement[] } (only claude.* fields populated).

Phase B: Codex debate (Skill invocation)
bash
node scripts/skills/necessity-audit/debate-topic.js build \
  --preflight "<AUDIT_TMP_DIR>/preflight.json" \
  --output "<AUDIT_TMP_DIR>/topic.txt"

Read topic, invoke:

Skill("codex-brainstorm", <contents of <AUDIT_TMP_DIR>/topic.txt>)

Write raw response: Write tool → <AUDIT_TMP_DIR>/debate.txt.

bash
node scripts/skills/necessity-audit/debate-topic.js parse \
  --input "<AUDIT_TMP_DIR>/debate.txt" \
  --output "<AUDIT_TMP_DIR>/debate.json"
Phase C: Consolidate (executable)
bash
node scripts/skills/necessity-audit/consolidate.js \
  --phase-a "<AUDIT_TMP_DIR>/phase-a.json" \
  --debate "<AUDIT_TMP_DIR>/debate.json" \
  --preflight "<AUDIT_TMP_DIR>/preflight.json" \
  --overrides "<id>:<rationale>[;...]" \
  --depth <depth> \
  --output "<AUDIT_TMP_DIR>/report.json"

Applies 6 deterministic checks, under-coverage check, --override handling, gate selection.

Show full SKILL.md (366 more words)Show less
Assemble + Redact + Emit
bash
node scripts/skills/necessity-audit/report.js \
  --input "<AUDIT_TMP_DIR>/report.json" \
  --format markdown \
  --output "<AUDIT_TMP_DIR>/report.md"

node scripts/skills/necessity-audit/redact.js \
  --input "<AUDIT_TMP_DIR>/report.md" \
  --output "<AUDIT_TMP_DIR>/report.final.md"

Read <AUDIT_TMP_DIR>/report.final.md and emit as final user-visible message.

Cleanup. The path condition is enforced by the script, not by this paragraph. It refuses (exit 1, deleting nothing) on an unsubstituted placeholder, a relative path, a symlink, a non-directory, the filesystem root, anything that is not a direct child of this process's temp root — in particular the shared temp root itself, the path an ambient-TMPDIR mistake produces — any directory carrying no --claim marker, and, decisively, any directory whose marker was minted with a different token. That last check is what rules out a substitution naming a different, equally valid-looking scratch directory: shape is common to all of them and so is the marker, since every concurrent audit claims its own — only the token is unique to this run. Removal is idempotent, so re-running after a partial failure is safe:

bash
node scripts/skills/necessity-audit/cleanup.js --dir "<AUDIT_TMP_DIR>" --token "<AUDIT_TOKEN>"

Before running it, re-read the path you are substituting and confirm it is the exact absolute path Phase 0 printed. The guard refuses a wrong one, but a refusal is a stalled cleanup — getting the substitution right is still your job. If the guard does refuse, do not work around it with a manual rm: fix the substitution.

Output Format + Gate Selection

Output header, sections, sentinel: see references/output-template.md (normative). Gate-selection decision table + narrative rules: see references/phase-c-consolidate.md.

Invariant: ⚠️ Need Human NEVER appears as the final gate — only as a narrative line above the ✅ Audit Clear / ⛔ Audit Revise sentinel.

Review Loop (--continue)

After user revises the spec, re-run with --continue <threadId> to reuse the Codex debate context via @skills/codex-code-review/references/codex-transport.md § Resume. See references/review-loop.md.

References

  • references/dimensions.md — 6-dimension × 4-tier rubric (authoritative)
  • references/phase-a-classify.md — Phase A prompt template
  • references/phase-b-debate-topic.md — Phase B topic builder documentation
  • references/phase-c-consolidate.md — Phase C logic
  • references/output-template.md — Markdown report layout
  • references/review-loop.md — --continue flow
  • references/redaction-rules.md — Secret / PII patterns applied by redact.js

Verification

  • Phase B used Skill("codex-brainstorm"), not a raw transport dispatch
  • Report contains non-empty debate.threadId
  • Report contains non-empty Debate Conclusion
  • Output starts with ## Necessity Audit header
  • Output ends with ✅ Audit Clear OR ⛔ Audit Revise sentinel
  • Output contains NO doc-review gate sentinel (the Mergeable / Needs revision pair) anywhere — an audit must not be mistakable for a doc review
  • ⚠️ Need Human never used as gate (only as narrative)
  • Redaction applied before emission

Examples

Input: /necessity-audit docs/features/foo/2-tech-spec.md
Action: Phase 0 preflight → Phase A classify → Phase B debate → Phase C consolidate → report + redact → emit with sentinel

Input: /necessity-audit docs/features/foo/2-tech-spec.md --continue 019dab42-xxxx
Action: Resume per `@skills/codex-code-review/references/codex-transport.md` § Resume; re-run Phase C with updated spec; emit diff-focused report

Input: /necessity-audit docs/features/foo/1-requirements.md --depth brief --skip-preflight
Action: Only challenge dims 1-3; skip state advisory; emit [PREFLIGHT SKIPPED] banner

Input: /necessity-audit docs/features/foo/2-tech-spec.md --override FR-12:"needed for Q3 rollout"
Action: FR-12 kept with justification; final gate ✅ Audit Clear if no other Cut items remain

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/necessity-audit of sd0xdev/sd0x-harness.

  • SKILL.md
  • references/dimensions.md
  • references/output-template.md
  • references/phase-a-classify.md
  • references/phase-b-debate-topic.md
  • references/phase-c-consolidate.md
  • references/redaction-rules.md
  • references/review-loop.md

Open the folder on GitHubat commit a4d4bc1

Compare with similar skills

Necessity Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Necessity Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Necessity Audit this skillsd0xdev/sd0x-harness192—~2.7kAutomated safety check: PassMIT
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from sd0xdev/sd0x-harness

All 89 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated today
    Auto-check passed

Categories

Questions about Necessity Audit

What does Necessity Audit do?

Necessity audit for over-designed spec elements. An agent skill from sd0xdev/sd0x-harness. Necessity Audit is an agent skill from sd0xdev/sd0x-harness. Necessity audit for over-designed spec elements.

When should I use Necessity Audit?

Necessity Audit fits situations like: : auditing lifecycle spec (1-requirements / 2-tech-spec / 3-architecture) for YAGNI/KISS violations; challenging necessity of FRs/NFRs/abstractions/configs via Codex adversarial debate.

How do I install Necessity Audit in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill necessity-audit -a claude-code`. Or copy the skill folder (skills/necessity-audit in sd0xdev/sd0x-harness) into .claude/skills/necessity-audit in your project. Claude Code loads it when a task matches its description.

How do I install Necessity Audit in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill necessity-audit -a codex`. Or copy the skill folder (skills/necessity-audit in sd0xdev/sd0x-harness) into .agents/skills/necessity-audit in your project. Codex loads it when a task matches its description.

Can I use Necessity Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill necessity-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/necessity-audit, .gemini/skills/necessity-audit, .github/skills/necessity-audit and .opencode/skills/necessity-audit in your project.

What does Necessity Audit need to run?

Going by SKILL.md and its folder, Necessity Audit needs the command-line tools its instructions call (node) and credentials named AUDIT_TOKEN. Our summary lists: A credential in AUDIT_TOKEN. Its frontmatter pre-approves these tools: Read, Grep, Glob, Write, Bash(node:*), Bash(mktemp:*), Skill.

Does Necessity Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Necessity Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Necessity Audit use?

Necessity Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Necessity Audit use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.6k tokens, read only when the agent opens those files.

What are the alternatives to Necessity Audit?

Skills that share tags, products or a category with Necessity Audit: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Necessity Audit?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on October 8, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.