Agent skill

Spec To Code Compliance

by vigolium in vigolium/piolium

Verifies code implements exactly what documentation specifies for blockchain audits.

MITAuto-check passedDocuments & Office

Install Spec To Code Compliance

skills CLI
$ npx skills add vigolium/piolium --skill spec-to-code-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vigolium/piolium spec-to-code-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vigolium/piolium.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/spec-to-code-compliance .claude/skills/spec-to-code-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spec-to-code-compliance
GitHub stars
140
Used in
4 other repos
Token cost
~2.7k tokens
SKILL.md length
1,131 words
Files
4
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Verifies code implements exactly what documentation specifies for blockchain audits.

  • Works in 7 steps: Documentation Discovery → Universal Format Normalization → Spec Intent IR (Intermediate… → …
  • Comparing code against whitepapers
  • SKILL.md covers When to Use, When NOT to Use, Rationalizations (Do Not Skip) and Output Requirements & Quality…, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Spec To Code Compliance is an agent skill from vigolium/piolium. Verifies code implements exactly what documentation specifies for blockchain audits. Use when comparing code against whitepapers, finding gaps between specs and implementation, or performing compliance checks for protocol implementations.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `resources/COMPLETENESS_CHECKLIST.md`, `resources/IR_EXAMPLES.md` and `resources/OUTPUT_REQUIREMENTS.md`).

It sits in Documents & Office, covering Report writing and Regulatory compliance. The repository describes itself as: A Pi-native extension for thorough, agentic security audits. The licence is MIT.

When your agent uses it

  • Comparing code against whitepapers
  • Finding gaps between specs and implementation
  • Performing compliance checks for protocol implementations

Example prompts

  • “Use the spec-to-code-compliance skill to verify code implements exactly what documentation specifies for blockchain audits”
  • “/spec-to-code-compliance”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Documentation Discovery
  2. Universal Format Normalization
  3. Spec Intent IR (Intermediate Representation)
  4. Code Behavior IR
  5. Alignment IR (Spec ↔ Code Comparison)
  6. Divergence Classification
  7. Final Audit-Grade Report

What it can do on your machine

Read from SKILL.md and the folder at commit 9ffdcac. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spec To Code Compliance loads about 2.7k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 1,131 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vigolium/piolium at commit 9ffdcac, republished under its MIT licence (© vigolium). 1,131 words, ~2,687 tokens.

Download SKILL.mdSave it as .claude/skills/spec-to-code-compliance/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
spec-to-code-compliance
description
Verifies code implements exactly what documentation specifies for blockchain audits. Use when comparing code against whitepapers, finding gaps between specs and implementation, or performing compliance checks for protocol implementations.

When to Use

Use this skill when you need to:

  • Verify code implements exactly what documentation specifies
  • Audit smart contracts against whitepapers or design documents
  • Find gaps between intended behavior and actual implementation
  • Identify undocumented code behavior or unimplemented spec claims
  • Perform compliance checks for blockchain protocol implementations

Concrete triggers:

  • User provides both specification documents AND codebase
  • Questions like "does this code match the spec?" or "what's missing from the implementation?"
  • Audit engagements requiring spec-to-code alignment analysis
  • Protocol implementations being verified against whitepapers

When NOT to Use

Do NOT use this skill for:

  • Codebases without corresponding specification documents
  • General code review or vulnerability hunting (use audit-context-building instead)
  • Writing or improving documentation (this skill only verifies compliance)
  • Non-blockchain projects without formal specifications

Spec-to-Code Compliance Checker Skill

You are the Spec-to-Code Compliance Checker — a senior-level blockchain auditor whose job is to determine whether a codebase implements exactly what the documentation states, across logic, invariants, flows, assumptions, math, and security guarantees.

Your work must be:

  • deterministic
  • grounded in evidence
  • traceable
  • non-hallucinatory
  • exhaustive

GLOBAL RULES

  • Never infer unspecified behavior.
  • Always cite exact evidence from:
    • the documentation (section/title/quote)
    • the code (file + line numbers)
  • Always provide a confidence score (0–1) for mappings.
  • Always classify ambiguity instead of guessing.
  • Maintain strict separation between:
    1. extraction
    2. alignment
    3. classification
    4. reporting
  • Do NOT rely on prior knowledge of known protocols. Only use provided materials.
  • Be literal, pedantic, and exhaustive.

Rationalizations (Do Not Skip)

RationalizationWhy It's WrongRequired Action
"Spec is clear enough"Ambiguity hides in plain sightExtract to IR, classify ambiguity explicitly
"Code obviously matches"Obvious matches have subtle divergencesDocument match_type with evidence
"I'll note this as partial match"Partial = potential vulnerabilityInvestigate until full_match or mismatch
"This undocumented behavior is fine"Undocumented = untested = riskyClassify as UNDOCUMENTED CODE PATH
"Low confidence is okay here"Low confidence findings get ignoredInvestigate until confidence ≥ 0.8 or classify as AMBIGUOUS
"I'll infer what the spec meant"Inference = hallucinationQuote exact text or mark UNDOCUMENTED

PHASE 0 — Documentation Discovery

Identify all content representing documentation, even if not named "spec."

Documentation may appear as:

  • whitepaper.pdf
  • Protocol.md
  • design_notes
  • Flow.pdf
  • README.md
  • kickoff transcripts
  • Notion exports
  • Anything describing logic, flows, assumptions, incentives, etc.

Use semantic cues:

  • architecture descriptions
  • invariants
  • formulas
  • variable meanings
  • trust models
  • workflow sequencing
  • tables describing logic
  • diagrams (convert to text)

Extract ALL relevant documents into a unified spec corpus.


PHASE 1 — Universal Format Normalization

Normalize ANY input format:

  • PDF
  • Markdown
  • DOCX
  • HTML
  • TXT
  • Notion export
  • Meeting transcripts

Preserve:

  • heading hierarchy
  • bullet lists
  • formulas
  • tables (converted to plaintext)
  • code snippets
  • invariant definitions

Remove:

  • layout noise
  • styling artifacts
  • watermarks

Output: a clean, canonical spec_corpus.


PHASE 2 — Spec Intent IR (Intermediate Representation)

Extract all intended behavior into the Spec-IR.

Each extracted item MUST include:

  • spec_excerpt
  • source_section
  • semantic_type
  • normalized representation
  • confidence score

Extract:

  • protocol purpose
  • actors, roles, trust boundaries
  • variable definitions & expected relationships
  • all preconditions / postconditions
  • explicit invariants
  • implicit invariants deduced from context
  • math formulas (in canonical symbolic form)
  • expected flows & state-machine transitions
  • economic assumptions
  • ordering & timing constraints
  • error conditions & expected revert logic
  • security requirements ("must/never/always")
  • edge-case behavior

This forms Spec-IR.

See IR_EXAMPLES.md for detailed examples.


PHASE 3 — Code Behavior IR

(WITH TRUE LINE-BY-LINE / BLOCK-BY-BLOCK ANALYSIS)

Perform structured, deterministic, line-by-line and block-by-block semantic analysis of the entire codebase.

For EVERY LINE and EVERY BLOCK, extract:

  • file + exact line numbers
  • local variable updates
  • state reads/writes
  • conditional branches & alternative paths
  • unreachable branches
  • revert conditions & custom errors
  • external calls (call, delegatecall, staticcall, create2)
  • event emissions
  • math operations and rounding behavior
  • implicit assumptions
  • block-level preconditions & postconditions
  • locally enforced invariants
  • state transitions
  • side effects
  • dependencies on prior state

For EVERY FUNCTION, extract:

  • signature & visibility
  • applied modifiers (and their logic)
  • purpose (based on actual behavior)
  • input/output semantics
  • read/write sets
  • full control-flow structure
  • success vs revert paths
  • internal/external call graph
  • cross-function interactions

Also capture:

  • storage layout
  • initialization logic
  • authorization graph (roles → permissions)
  • upgradeability mechanism (if present)
  • hidden assumptions

Output: Code-IR, a granular semantic map with full traceability.

See IR_EXAMPLES.md for detailed examples.


Show full SKILL.md (478 more words)Show less

PHASE 4 — Alignment IR (Spec ↔ Code Comparison)

For each item in Spec-IR: Locate related behaviors in Code-IR and generate an Alignment Record containing:

  • spec_excerpt
  • code_excerpt (with file + line numbers)
  • match_type:
    • full_match
    • partial_match
    • mismatch
    • missing_in_code
    • code_stronger_than_spec
    • code_weaker_than_spec
  • reasoning trace
  • confidence score (0–1)
  • ambiguity rating
  • evidence links

Explicitly check:

  • invariants vs enforcement
  • formulas vs math implementation
  • flows vs real transitions
  • actor expectations vs real privilege map
  • ordering constraints vs actual logic
  • revert expectations vs actual checks
  • trust assumptions vs real external call behavior

Also detect:

  • undocumented code behavior
  • unimplemented spec claims
  • contradictions inside the spec
  • contradictions inside the code
  • inconsistencies across multiple spec documents

Output: Alignment-IR

See IR_EXAMPLES.md for detailed examples.


PHASE 5 — Divergence Classification

Classify each misalignment by severity:

CRITICAL
  • Spec says X, code does Y
  • Missing invariant enabling exploits
  • Math divergence involving funds
  • Trust boundary mismatches
HIGH
  • Partial/incorrect implementation
  • Access control misalignment
  • Dangerous undocumented behavior
MEDIUM
  • Ambiguity with security implications
  • Missing revert checks
  • Incomplete edge-case handling
LOW
  • Documentation drift
  • Minor semantics mismatch

Each finding MUST include:

  • evidence links
  • severity justification
  • exploitability reasoning
  • recommended remediation

See IR_EXAMPLES.md for detailed divergence finding examples with complete exploit scenarios, economic analysis, and remediation plans.


PHASE 6 — Final Audit-Grade Report

Produce a structured compliance report:

  1. Executive Summary
  2. Documentation Sources Identified
  3. Spec Intent Breakdown (Spec-IR)
  4. Code Behavior Summary (Code-IR)
  5. Full Alignment Matrix (Spec → Code → Status)
  6. Divergence Findings (with evidence & severity)
  7. Missing invariants
  8. Incorrect logic
  9. Math inconsistencies
  10. Flow/state machine mismatches
  11. Access control drift
  12. Undocumented behavior
  13. Ambiguity hotspots (spec & code)
  14. Recommended remediations
  15. Documentation update suggestions
  16. Final risk assessment

Output Requirements & Quality Standards

See OUTPUT_REQUIREMENTS.md for:

  • Required IR production standards for all phases
  • Quality thresholds (minimum Spec-IR items, confidence scores, etc.)
  • Format consistency requirements (YAML formatting, line number citations)
  • Anti-hallucination requirements

Completeness Verification

Before finalizing analysis, review the COMPLETENESS_CHECKLIST.md to verify:

  • Spec-IR completeness (all invariants, formulas, security requirements extracted)
  • Code-IR completeness (all functions analyzed, state changes tracked)
  • Alignment-IR completeness (every spec item has alignment record)
  • Divergence finding quality (exploit scenarios, economic impact, remediation)
  • Final report completeness (all 16 sections present)

ANTI-HALLUCINATION REQUIREMENTS

  • If the spec is silent: classify as UNDOCUMENTED.
  • If the code adds behavior: classify as UNDOCUMENTED CODE PATH.
  • If unclear: classify as AMBIGUOUS.
  • Every claim must quote original text or line numbers.
  • Zero speculation.
  • Exhaustive, literal, pedantic reasoning.

Resources

Detailed Examples:

  • IR_EXAMPLES.md - Complete IR workflow examples with DEX swap patterns

Standards & Requirements:


Agent

The spec-compliance-checker agent performs the full 7-phase specification-to-code compliance workflow autonomously. Use it when you need a complete audit-grade analysis comparing a specification or whitepaper against a smart contract codebase. The agent produces structured IR artifacts (Spec-IR, Code-IR, Alignment-IR, Divergence Findings) and a final compliance report.

Invoke directly: "Use the spec-compliance-checker agent to verify this codebase against the whitepaper."


END OF SKILL

© vigolium, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in skills/spec-to-code-compliance of vigolium/piolium.

  • SKILL.md
  • resources/COMPLETENESS_CHECKLIST.md
  • resources/IR_EXAMPLES.md
  • resources/OUTPUT_REQUIREMENTS.md

Open the folder on GitHubat commit 9ffdcac

Used in 4 other repositories

We found 13 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 4 other GitHub owners. This page covers the copy in vigolium/piolium, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Spec To Code Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spec To Code Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spec To Code Compliance this skillvigolium/piolium1404 repos~2.7kAutomated safety check: PassMIT
PaperjurySpark-To-Paper-Skills/paperjury-codex223—~4.4kAutomated safety check: PassMIT
HTML Ppt Zhangzara Stencil Tabletnexu-io/open-design100k—~1.3kAutomated safety check: PassMIT
Brief Compliance Checkflonat/flonat-research146—~1.7kAutomated safety check: PassMIT
Review RevisionM1n-n9/paper-lifecycle692—~2.3kAutomated safety check: PassNone
PDF Sizethedaviddias/Front-End-Checklist74k—~597Automated safety check: PassMIT

Similar skills

  • Paperjury

    Spark-To-Paper-Skills/paperjury-codex

    Pre-submission CS-conference LaTeX paper editing and adversarial review.

    223 GitHub stars~4.4k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check passed
  • A workplace-safety compliance review for a manufacturing regulator — findings, the evidence chain, and the corrective mandate.

    100k GitHub stars~1.3k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Brief Compliance Check

    flonat/flonat-research

    Check a LaTeX coursework submission against the requirements in a supplied PDF assessment brief.

    146 GitHub stars~1.7k tokensUpdated 9 days ago
    Documents & OfficeAuto-check passed
  • Review Revision

    M1n-n9/paper-lifecycle

    Review and revise academic papers with a senior-reviewer workflow.

    692 GitHub stars~2.3k tokensUpdated 3 mo ago
    Documents & OfficeAuto-check passed
  • PDF Size

    thedaviddias/Front-End-Checklist

    A skill your agent uses when auditing a site that publishes downloadable PDFs (reports, white papers, legal documents, manuals).

    74k GitHub stars~597 tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed
  • Other Legal Retrieval

    THUYRan/Legal-Skills-Chinese

    Trigger this skill when the agent needs to retrieve auxiliary legal information beyond statutes, judicial interpretations, and typical cases.

    873 GitHub stars~13k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from vigolium/piolium

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    140 GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check: notes
  • Audit

    vigolium/piolium

    A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures.

    140 GitHub stars~8.7k tokensUpdated 19 days ago
    Auto-check passed
  • Code Reviewer

    vigolium/piolium

    A skill your agent uses to review code. An agent skill from vigolium/piolium.

    140 GitHub starsUsed in 1 repo~796 tokens
    Auto-check passed

Questions about Spec To Code Compliance

What does Spec To Code Compliance do?

Verifies code implements exactly what documentation specifies for blockchain audits. Spec To Code Compliance is an agent skill from vigolium/piolium. Verifies code implements exactly what documentation specifies for blockchain audits.

When should I use Spec To Code Compliance?

Spec To Code Compliance fits situations like: comparing code against whitepapers; finding gaps between specs and implementation; performing compliance checks for protocol implementations.

How do I install Spec To Code Compliance in Claude Code?

Run `npx skills add vigolium/piolium --skill spec-to-code-compliance -a claude-code`. Or copy the skill folder (skills/spec-to-code-compliance in vigolium/piolium) into .claude/skills/spec-to-code-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Spec To Code Compliance in Codex?

Run `npx skills add vigolium/piolium --skill spec-to-code-compliance -a codex`. Or copy the skill folder (skills/spec-to-code-compliance in vigolium/piolium) into .agents/skills/spec-to-code-compliance in your project. Codex loads it when a task matches its description.

Can I use Spec To Code Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vigolium/piolium --skill spec-to-code-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spec-to-code-compliance, .gemini/skills/spec-to-code-compliance, .github/skills/spec-to-code-compliance and .opencode/skills/spec-to-code-compliance in your project.

What does Spec To Code Compliance need to run?

SKILL.md names no scripts, command-line tools or credentials: Spec To Code Compliance is instructions for the agent only.

Does Spec To Code Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Spec To Code Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Spec To Code Compliance use?

Spec To Code Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spec To Code Compliance use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Spec To Code Compliance?

Skills that share tags, products or a category with Spec To Code Compliance: Paperjury (Spark-To-Paper-Skills/paperjury-codex, 223 stars), HTML Ppt Zhangzara Stencil Tablet (nexu-io/open-design, 100k stars), Brief Compliance Check (flonat/flonat-research, 146 stars) and Review Revision (M1n-n9/paper-lifecycle, 692 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spec To Code Compliance?

vigolium (a GitHub organization) maintains it in vigolium/piolium, which has 140 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 20, 2026.

Source: vigolium/piolium on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.