Agent skill

Review Spec

by sd0xdev in sd0xdev/sd0x-harness

Review technical spec documents from completeness, feasibility, risk, and code consistency perspectives.

MITAuto-check passedDevelopment

Install Review Spec

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill review-spec -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness review-spec --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review-spec .claude/skills/review-spec && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-spec
GitHub stars
192
Token cost
~2.1k tokens
SKILL.md length
1,039 words
Files
1
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Review technical spec documents from completeness, feasibility, risk, and code consistency perspectives.

  • Works in 2 steps: Read the full document: cat ${FILE_PATH} → If long: cat ${FILE_PATH} | head -300…
  • Development work in your project
  • SKILL.md covers Trigger, When NOT to Use, Relationship to… and Codex Dispatch, plus 10 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Review Spec is an agent skill from sd0xdev/sd0x-harness. Review technical spec documents from completeness, feasibility, risk, and code consistency perspectives.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/review-spec”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash(git:*), Bash(node:*), Write

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Read the full document: cat ${FILE_PATH}
  2. If long: cat ${FILE_PATH} | head -300 then cat ${FILE_PATH} | tail -200

What it can do on your machine

Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash(git:*)
    • Bash(node:*)
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Spec loads about 2.1k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 1,039 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 1,039 words, ~2,102 tokens.

Download SKILL.mdSave it as .claude/skills/review-spec/SKILL.md (or your agent's skills folder).
name
review-spec
description
Review technical spec documents from completeness, feasibility, risk, and code consistency perspectives.
allowed-tools
Read, Grep, Glob, Bash(git:*), Bash(node:*), Write

Review Spec

Trigger

  • Keywords: review spec, spec review, tech spec review, review-spec

When NOT to Use

  • Code review (use /codex-review-fast)
  • General document review (use /codex-review-doc)
  • Writing a new spec (use /tech-spec)

Relationship to /codex-review-doc

Both are doc-plane producers of the same gate, dispatched over the same Codex exec transport (@skills/codex-code-review/references/codex-transport.md) and emitting the same sentinel pair. They differ only in review depth and dimensions: /review-spec is the design-landing depth (completeness, feasibility, risk, code consistency, test strategy), /codex-review-doc is the general document depth. Loop mechanics, severity calibration and [NIT_DEFERRED] handling are shared — see @skills/doc-review/SKILL.md.

Why not an Agent dispatch. The gate verdict is behaviour-layer: it comes from the reviewer's report, and review-state.js note records it (@rules/auto-loop.md § Enforcement — nothing parses reviewer output; hooks are reminders). What makes a verdict usable is that a contract-aware reviewer produced it against this family's template and sentinels. A built-in agent dispatched ad hoc is not that reviewer and its output closes nothing. Dispatching Codex over the shared transport is what makes the verdict this skill's to note. See @rules/auto-loop.md § Review Dispatch.

Codex Dispatch

Bind every placeholder before writing prompt.md. The body below is body-only, so nothing evaluates an expression inside it: ${FILE_PATH} and ${PROJECT_ROOT} must carry real values by the time the file is written, or the cat ${FILE_PATH} instructions reach Codex as literal text and cannot be run.

You are a senior technical spec reviewer. Perform a Document Review of the technical specification below, at design-landing depth.

Document Info

  • Path: ${FILE_PATH}
  • Type: technical specification
  • Project root: ${PROJECT_ROOT}

⚠️ Important: You must independently read and research the project ⚠️

Do NOT expect pre-provided file content. Read the spec and research the project yourself using your sandbox access. The spec makes concrete claims about this repository — verify them against the actual files rather than taking them on trust.

Document Reading (Priority)
  1. Read the full document: cat ${FILE_PATH}
  2. If long: cat ${FILE_PATH} | head -300 then cat ${FILE_PATH} | tail -200
Code-Documentation Consistency Research
  1. Project structure, discovered rather than assumed: ls at the repository root, then the directories it actually shows — do not assume a src/ layout; many repositories, this one included, have none
  2. Search for every file, function, flag and command the spec names: grep -rn "keyword" . -l --include="*.ts" --include="*.js" --include="*.sh" | head -10
  3. Read related files: cat <file-path> | head -100
  4. Verify: do referenced files exist? Are names correct? Do described behaviours match code?

Review Dimensions

#DimensionChecks
1CompletenessAre requirements, scope, risks and work breakdown all present and specific
2FeasibilityCan this be built as described, with the dependencies it names
3Risk AssessmentAre the real failure modes identified, and does each have a bound
4Code ConsistencyDo referenced files/functions exist and behave as described (verify with grep/cat)
5Test StrategyIs every acceptance criterion mapped to evidence; are guards two-directional

Severity Calibration ⚠️

A 🔴 blocks the document and costs a full review round. Reserve it for defects that would mislead a reader into building the wrong thing:

Mark 🔴Do NOT mark 🔴
A described file, function, flag or command that does not existWording that could be clearer
A described behaviour that contradicts what the code actually doesA section you would have structured differently
A security or data-handling design that is wrong or unsafeA missing section that no rule requires
An internal contradiction — two passages that cannot both be trueProse where a table would be tidier
A broken cross-reference, or a step whose stated dependency is not met by its own orderingHypothetical future concerns not present in the change

Do not manufacture findings to fill a section. An empty 🔴 section is a normal outcome.

Show full SKILL.md (433 more words)Show less

Output Format

Your report must begin with the literal line ## Document Review. Nothing parses it — the verdict is behaviour-layer and review-state.js records only an explicit note (@rules/auto-loop.md § Enforcement). The header matters for the reader: it is what tells a document review apart from a code or security review in a transcript.

Document Review

Review Summary
DimensionRating (1-5⭐)Notes
Completeness......
Feasibility......
Risk Assessment......
Code Consistency......
Test Strategy......
🔴 Must Fix (blocking — see Severity Calibration)
  • [Section/Line] Issue description -> Fix recommendation

(Write None if there are none.)

🟡 Suggested Changes (non-blocking)
  • [Section/Line] Issue description -> Fix recommendation
⚪ Optional Improvements
  • Suggestion
Deferred Findings

For every 🟡 and ⚪ above, emit one line here, starting at column 0:

[NIT_DEFERRED] <file:line> | <issue> | reason: sub-threshold-doc | <ISO8601 UTC>

Do not reorder the fields and do not use a different tag. Omit this section entirely if there are no 🟡 or ⚪ items.

Gate

End the report with exactly one verdict terminal, alone at column 0 on the final line — the same rule as @skills/doc-review/references/review-loop-doc.md, and what scripts/validate-family-sentinel.js doc accepts. As list items they are not a legal terminal.

  • No 🔴 findings → final line ✅ Mergeable
  • Any 🔴 finding → final line ⛔ Needs revision

Dispatch this body per @skills/codex-code-review/references/codex-transport.md § Start; the transport pins the sandbox and approval policy, so nothing is chosen here. Save the returned threadId — loop re-review continues the same thread per that reference's § Resume; see @skills/doc-review/references/review-loop-doc.md.

Task

Document to Review
$ARGUMENTS

If no path is given, auto-detect: git-modified 2-*.md under docs/features/ → staged .md → newest tech spec. Multiple candidates: list them and ask which to review.

Gate

SentinelMeaning
✅ MergeableNo 🔴 items — the spec may proceed to implementation
⛔ Needs revision🔴 items present — fix, then re-review on the same thread

These are the doc-plane sentinels (@rules/auto-loop.md § Gate Sentinels). No hook parses them — the verdict is behaviour-layer and review-state.js records only an explicit note. One thing does read them mechanically, and it is not a hook: scripts/validate-family-sentinel.js doc validates a fallback carrier's raw report before its verdict may be adopted. That is why the shape is fixed in both directions — a paraphrase reads as no verdict to a human, and fails the validator outright when a fallback produced it. Emit them verbatim.

🔴 only. 🟡 and ⚪ are non-blocking: log them via [NIT_DEFERRED] and proceed (@rules/auto-loop.md § Sub-Threshold Findings). Round cap and its ## Max Rounds override come from the shared contract (@rules/auto-loop.md § Tiers); still failing → report the blocker rather than spending another round.

Verification

  • Dispatched over the Codex exec transport (§ Start), not an Agent
  • The prompt asks for a Document Review, and the report opens with that header
  • Codex verified code-documentation consistency independently
  • Gate is one of ✅ Mergeable / ⛔ Needs revision

References

  • Shared loop mechanics and severity model: @skills/doc-review/SKILL.md
  • Re-review template: @skills/doc-review/references/review-loop-doc.md
  • Dispatch contract: @rules/codex-invocation.md

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/review-spec of sd0xdev/sd0x-harness.

Open the folder on GitHubat commit c9a2036

Compare with similar skills

Review Spec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Spec compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Spec this skillsd0xdev/sd0x-harness192—~2.1kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k24 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 24 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Guidelines

    akash-network/node

    Behavioral guidelines to reduce common LLM coding mistakes. An agent skill from akash-network/node.

    1.1k GitHub starsUsed in 22 repos~577 tokens
    DevelopmentAuto-check passed

More from sd0xdev/sd0x-harness

All 91 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Review Spec

What does Review Spec do?

Review technical spec documents from completeness, feasibility, risk, and code consistency perspectives. Review Spec is an agent skill from sd0xdev/sd0x-harness. Review technical spec documents from completeness, feasibility, risk, and code consistency perspectives.

When should I use Review Spec?

Review Spec fits situations like: development work in your project.

How do I install Review Spec in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill review-spec -a claude-code`. Or copy the skill folder (skills/review-spec in sd0xdev/sd0x-harness) into .claude/skills/review-spec in your project. Claude Code loads it when a task matches its description.

How do I install Review Spec in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill review-spec -a codex`. Or copy the skill folder (skills/review-spec in sd0xdev/sd0x-harness) into .agents/skills/review-spec in your project. Codex loads it when a task matches its description.

Can I use Review Spec in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill review-spec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-spec, .gemini/skills/review-spec, .github/skills/review-spec and .opencode/skills/review-spec in your project.

What does Review Spec need to run?

SKILL.md names no scripts, command-line tools or credentials: Review Spec is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash(git:*), Bash(node:*), Write.

Does Review Spec access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Review Spec safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Spec use?

Review Spec is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Spec use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Spec?

Skills that share tags, products or a category with Review Spec: Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars) and Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Spec?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.