Agent skill

Verify Spec

by Smana in Smana/cloud-native-ref

Verify that a merged design's success criteria are actually met in the live cluster.

Apache-2.0Auto-check passedBusiness, Finance & HR

Install Verify Spec

skills CLI
$ npx skills add Smana/cloud-native-ref --skill verify-spec -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Smana/cloud-native-ref verify-spec --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Smana/cloud-native-ref.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/verify-spec .claude/skills/verify-spec && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-spec
GitHub stars
103
Token cost
~1.5k tokens
SKILL.md length
483 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
Apache-2.0

At a glance

Verify that a merged design's success criteria are actually met in the live cluster.

  • Works in 7 steps: Locate inputs → Enumerate success criteria → Deploy the example (idempotent) → …
  • Tasks that involve Accounting and bookkeeping
  • SKILL.md covers Workflow, Safety rules and Related skills
  • Calls kubectl

What it does

Verify Spec is an agent skill from Smana/cloud-native-ref. Verify that a merged design's success criteria are actually met in the live cluster. Deploys the example manifest, watches Flux reconciliation, queries VictoriaMetrics/VictoriaLogs for evidence, writes docs/superpowers/specs/<topic-verification.md.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Business, Finance & HR, covering Accounting and bookkeeping. It works with Kubernetes. The repository describes itself as: Opiniated Cloud Native Platform Reference. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Accounting and bookkeeping

Example prompts

  • “/verify-spec”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Bash(kubectl:*), Bash(flux:*), Grep, Glob

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Locate inputs
  2. Enumerate success criteria
  3. Deploy the example (idempotent)
  4. Watch reconciliation (Flux MCP)
  5. Query observability (VictoriaMetrics / VictoriaLogs MCP)
  6. Write the verification report
  7. Summarize

What it can do on your machine

Read from SKILL.md and the folder at commit e5ee7e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash(kubectl:*)
    • Bash(flux:*)
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify Spec loads about 1.5k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 483 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Smana/cloud-native-ref at commit e5ee7e1, republished under its Apache-2.0 licence (© Smana). 483 words, ~1,506 tokens.

Download SKILL.mdSave it as .claude/skills/verify-spec/SKILL.md (or your agent's skills folder).
name
verify-spec
description
Verify that a merged design's success criteria are actually met in the live cluster. Deploys the example manifest, watches Flux reconciliation, queries VictoriaMetrics/VictoriaLogs for evidence, writes docs/superpowers/specs/<topic>-verification.md.
allowed-tools
Read, Write, Bash(kubectl:*), Bash(flux:*), Grep, Glob
when_to_use
When the user says "verify the design", "did that actually ship", "check this works", "post-merge verification", "UAT this feature", "prove the success…
disable-model-invocation
true
argument-hint
<design-doc> — path to a docs/superpowers/specs/*-design.md file
paths
docs/superpowers/**

Verify Spec Skill

Close the acceptance loop. Merged work is not "done" until the design's success criteria are observably met in the target cluster.

Workflow

1. Locate inputs

Resolve $ARGUMENTS to a design document under docs/superpowers/specs/. Accept a bare topic slug and glob for it. Abort with guidance if not found.

Read:

  • the design doc — its goals, its Testing table, and any explicit success criteria
  • the matching plan at docs/superpowers/plans/<same-date>-<same-topic>-plan.md, if present — its per-task verification commands are usually the best evidence source
  • any example manifests the design names

Archived specs under docs/specs/done/ are also accepted, for re-verifying older work. Those use the retired SC-XXX format; parse **SC-XXX**: <text> lines when you see them.

2. Enumerate success criteria

Superpowers designs state criteria in prose and in a Testing table rather than as numbered SC-XXX items. Extract one checkable claim per row or per bullet, and give each a stable local id (C-1, C-2, …) for the report. For each, infer a verification method:

Criterion patternVerification method
"pods can call AWS APIs …"kubectl run a test pod; try the API; check result
"reconciliation succeeds within Xs"flux get + time window check
"metrics emit"VictoriaMetrics query for the metric name
"logs appear"VictoriaLogs query for the log stream
"latency p95 < Y"VictoriaMetrics histogram_quantile(0.95, ...)
"eviction deterministic"deploy, fill, observe eviction counter
"resource X created"kubectl get X -l <label>
a literal shell command in the Testing tablerun it verbatim; compare to the stated expected output

If the method is unclear, list the criterion as MANUAL and ask the user how they want to verify.

3. Deploy the example (idempotent)

Prefer kubectl apply -k <dir>/examples/ or kubectl apply -f <dir>/examples/<name>.yaml. If the resource is a Flux HelmRelease / Kustomization, just wait for reconciliation — Flux owns deployment.

Do not deploy to production namespaces without explicit user approval. Confirm target cluster context before each apply.

Show full SKILL.md (175 more words)Show less
4. Watch reconciliation (Flux MCP)

For Crossplane/Flux-managed specs, use the Flux MCP tools:

mcp__flux-operator-mcp__get_kubernetes_resources (kind: Kustomization/HelmRelease)
mcp__flux-operator-mcp__reconcile_flux_kustomization (if stalled)
mcp__flux-operator-mcp__get_flux_instance

Report any resource whose Ready=False condition persists past the timeout named in the spec (default 5 min).

5. Query observability (VictoriaMetrics / VictoriaLogs MCP)

For metrics-based SCs: mcp__victoriametrics__query / query_range with the metric name extracted from the SC text. For log-based SCs: mcp__victorialogs__query with a LogsQL stream filter (respect the project's dot-notation convention: kubernetes.container_name, log.level, etc.).

6. Write the verification report

Emit to docs/superpowers/specs/<YYYY-MM-DD>-<topic>-verification.md, using the same date and topic as the design it verifies:

markdown
# Verification: <spec title>

**Design**: <design-doc filename>
**Cluster**: <context>  (`kubectl config current-context`)
**Verified**: <YYYY-MM-DD HH:MM TZ>
**Verifier**: Claude (verify-spec)

---

## Success criteria results

| ID  | Criterion (1 line)                      | Method              | Verdict | Evidence |
|-----|------------------------------------------|---------------------|---------|----------|
| C-1 | Pods call AWS APIs without credentials  | kubectl exec probe  | ✅ PASS | `aws-cli output snippet` |
| C-2 | Evictions deterministic                  | VictoriaMetrics q   | ❌ FAIL | metric `cache_evictions_total` absent |
| C-3 | IAM roles cleaned up on delete           | kubectl delete + re-query | ✅ PASS | no dangling roles |
| C-4 | Reconcile < 2 min                        | flux get            | ✅ PASS | 42s |

## Issues found

### C-2 FAIL — eviction metric absent

<diagnosis, root cause hypothesis, suggested fix>

## Deployment artifacts

- Namespace: `<ns>`
- Flux Kustomizations: `<names>` — all Ready=True
- Helm releases: `<names>`
- Crossplane XRs: `<names>` — Synced=True, Ready=True

## References

- Design: `docs/superpowers/specs/<name>-design.md`
- Plan: `docs/superpowers/plans/<name>-plan.md` (if present)
- Example applied: `<path>`
7. Summarize

Return to the main context:

  • Total criteria: N
  • Passed: N
  • Failed: N
  • Manual: N
  • Link to the verification report

If any criterion failed, suggest opening a follow-up issue and reference the verification report.

Safety rules

  • Never touch production namespaces without explicit user confirmation.
  • Never delete resources to "re-test" without the user's go-ahead.
  • If the cluster context is not what the user expects, stop and confirm before any apply.
  • superpowers:brainstorming — produced the design this verifies
  • superpowers:verification-before-completion — the generic evidence discipline
  • /gitops-cluster-debug (fluxcd plugin) — deep Flux troubleshooting

© Smana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/verify-spec of Smana/cloud-native-ref.

Open the folder on GitHubat commit e5ee7e1

Compare with similar skills

Verify Spec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify Spec compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify Spec this skillSmana/cloud-native-ref103—~1.5kAutomated safety check: PassApache-2.0
Sync Upstreamnyaruka/phonenumbers1.6k—~2.8kAutomated safety check: PassMIT
Longbridge Value Investinghelsome/folio2692 repos~1.2kAutomated safety check: PassMIT
Radiology Tablehuang-sir1/radiology-skills1.9k—~1.3kAutomated safety check: PassCustom licence
Odoo Agency Fleet Reviewerpipe-org/mcp-odoo420—~699Automated safety check: PassMIT
Beancount Closebex-co/beancount-io295—~1.4kAutomated safety check: PassMIT

Similar skills

  • Sync Upstream

    nyaruka/phonenumbers

    Sync this Go port with a new upstream google/libphonenumber release — regenerate the embedded metadata and reconcile the ported Java logic.

    1.6k GitHub stars~2.8k tokensUpdated 5 days ago
    Business, Finance & HRAuto-check passed
  • Value investing analysis using Graham (NCAV/net-net/defensive-investor) and Buffett (economic moat/ROE/FCF) methodologies.

    269 GitHub starsUsed in 2 repos~1.2k tokens
    Business, Finance & HRAuto-check passed
  • Radiology Table

    huang-sir1/radiology-skills

    Create/audit editable publication tables with source reconciliation; not figures or statistical inference.

    1.9k GitHub stars~1.3k tokensUpdated 16 days ago
    Business, Finance & HRAuto-check passed
  • Odoo Agency Fleet Review

    erpipe-org/mcp-odoo

    Review many client Odoo databases at once through odoo-mcp's cross-instance tools — fleet-wide accounting health, per-client aging, partial-failure triage — for agencies and partners managing 5–50…

    420 GitHub stars~699 tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed
  • Beancount Close

    bex-co/beancount-io

    Close an accounting period in a Beancount ledger by reconciling each active account through beancount-reconcile, checking assertions and recurring gaps, reviewing flags, then proposing a commit with…

    295 GitHub stars~1.4k tokensUpdated today
    Business, Finance & HRAuto-check passed
  • ERPClaw ERP Controller

    avansaber/erpclaw

    Operates the ERPClaw self-hosted ERP in plain language: accounting, invoicing, inventory, purchasing, tax, HR, payroll and reports, treating the ERP as the single source of truth.

    114 GitHub stars~15k tokensUpdated 2 days ago
    Business, Finance & HRAuto-check passed

More from Smana/cloud-native-ref

  • Commit

    Smana/cloud-native-ref

    Run pre-commit validation before committing. An agent skill from Smana/cloud-native-ref.

    103 GitHub stars~778 tokensUpdated today
    Auto-check passed
  • Ship It

    Smana/cloud-native-ref

    Take a finished branch through the full pre-merge pipeline in one pass — rebase onto origin/main, simplify, prune prose, run the repo's validators and cite their output, review the diff, act on…

    103 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Sync Branch

    Smana/cloud-native-ref

    Rebase the current branch onto the latest origin/main before pushing, reviewing, or opening a PR.

    103 GitHub stars~966 tokensUpdated today
    Auto-check passed
  • Create PR

    Smana/cloud-native-ref

    Create or update a Pull Request with AI-generated description, mermaid diagram, file walkthrough, and automatic design-doc detection.

    103 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Spec Research

    Smana/cloud-native-ref

    Research patterns, ecosystem tools, and best practices before writing a design.

    103 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Questions about Verify Spec

What does Verify Spec do?

Verify that a merged design's success criteria are actually met in the live cluster. Verify Spec is an agent skill from Smana/cloud-native-ref. Verify that a merged design's success criteria are actually met in the live cluster.

When should I use Verify Spec?

Verify Spec fits situations like: tasks that involve Accounting and bookkeeping.

How do I install Verify Spec in Claude Code?

Run `npx skills add Smana/cloud-native-ref --skill verify-spec -a claude-code`. Or copy the skill folder (.agents/skills/verify-spec in Smana/cloud-native-ref) into .claude/skills/verify-spec in your project. Claude Code loads it when a task matches its description.

How do I install Verify Spec in Codex?

Run `npx skills add Smana/cloud-native-ref --skill verify-spec -a codex`. Or copy the skill folder (.agents/skills/verify-spec in Smana/cloud-native-ref) into .agents/skills/verify-spec in your project. Codex loads it when a task matches its description.

Can I use Verify Spec in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Smana/cloud-native-ref --skill verify-spec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-spec, .gemini/skills/verify-spec, .github/skills/verify-spec and .opencode/skills/verify-spec in your project.

What does Verify Spec need to run?

Going by SKILL.md and its folder, Verify Spec needs the command-line tools its instructions call (kubectl). Its frontmatter pre-approves these tools: Read, Write, Bash(kubectl:*), Bash(flux:*), Grep, Glob.

Does Verify Spec access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Verify Spec safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify Spec use?

Verify Spec is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify Spec use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify Spec?

Skills that share tags, products or a category with Verify Spec: Sync Upstream (nyaruka/phonenumbers, 1.6k stars), Longbridge Value Investing (helsome/folio, 269 stars), Radiology Table (huang-sir1/radiology-skills, 1.9k stars) and Odoo Agency Fleet Review (erpipe-org/mcp-odoo, 420 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify Spec?

Smana (a GitHub user) maintains it in Smana/cloud-native-ref, which has 103 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 8, 2026.

Source: Smana/cloud-native-ref on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.