spec-kitty-plan — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited spec-kitty-plan (Agent Skill) and scored it 87/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 3 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 3 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Source: This skill augments the baseline workflow located at ./workflows/spec-kitty.plan.md. It acts as an intelligent wrapper that is continuously improved with each execution.<!-- spec-kitty-command-version: 3.0.3 -->
Version: 0.11.0+
IMPORTANT: Plan works in the project root checkout. NO worktrees created.
# Run from project root (same directory as /spec-kitty.specify):
# You should already be here if you just ran /spec-kitty.specify
# Creates:
# - kitty-specs/###-feature/plan.md → In project root checkout
# - Commits to target branch
# - NO worktrees createdDo NOT cd anywhere. Stay in the project root checkout root.
In repos with multiple features, always pass `--feature <slug>` to every spec-kitty command.
$ARGUMENTSYou MUST consider the user input before proceeding (if not empty).
Before asking planning questions or generating artifacts, you must make the branch contract explicit.
plan.md.setup-plan --json/spec-kitty.tasksBefore planning interrogation, load constitution context for this action:
spec-kitty constitution context --action plan --jsonmode is bootstrap, apply JSON text as first-run governance context and follow referenced docs as needed.mode is compact, continue with condensed governance context.This command runs in the project root checkout, not in a worktree.
meta.json inspection:spec-kitty agent feature setup-plan --feature <feature-slug> --jsoncurrent_branch, target_branch / base_branch, and planning_base_branch / merge_target_branch (plus uppercase aliases) from that payloadbranch_matches_target from that payload to detect branch mismatch; do not probe branch state manually inside the promptkitty-specs/###-feature/Path reference rule: When you mention directories or files, provide either the absolute path or a path relative to the project root (for example, kitty-specs/<feature>/tasks/). Never refer to a folder by name alone.
Before executing any scripts or generating artifacts you must interrogate the specification and stakeholders.
WAITING_FOR_PLANNING_INPUTPlanning requirements (scale to complexity):
#, Question, Why it matters, and Current insight. Do not render this table to the user.WAITING_FOR_PLANNING_INPUT. Do not surface the table. Do not run the setup command yet.kitty-specs/<feature-slug>/...)spec-kitty agent feature setup-plan --json once without --featureavailable_features, stop and resolve one explicit feature slug before continuingspec-kitty agent feature setup-plan --feature <feature-slug> --json from the repository root and parse JSON for:result: "success" or error messagefeature_slug: Resolved feature slugspec_file: Absolute path to resolved spec.mdplan_file: Absolute path to the created plan.mdfeature_dir: Absolute path to the feature directorycurrent_branch: branch checked out when planning startedtarget_branch / base_branch (deterministic branch contract for downstream commands)planning_base_branch / merge_target_branch: explicit aliases for planning and merge intentbranch_strategy_summary: canonical sentence describing the branch strategyBefore proceeding, explicitly state to the user:
branch_matches_target says the current branch matches that intended targetExample:
# If detected feature is 020-my-feature:
spec-kitty agent feature setup-plan --feature 020-my-feature --jsonError handling: If the command fails with "Cannot detect feature" or "Multiple features found", verify your feature detection logic in step 2 and ensure you're passing the correct feature slug.
spec_file from setup-plan JSON output and .kittify/constitution/constitution.md if it exists. If the constitution file is missing, skip Constitution Check and note that it is absent. Load IMPL_PLAN template (already copied).[NEEDS CLARIFICATION: …] only when the user deliberately postpones a decision⚠️ CRITICAL: DO NOT proceed to task generation! The user must explicitly run /spec-kitty.tasks to generate work packages. Your job is COMPLETE after reporting the planning artifacts.
For each unknown in Technical Context:
Task: "Research {unknown} for {feature context}"
For each technology choice:
Task: "Find best practices for {tech} in {domain}"research.md using format:Output: research.md with all NEEDS CLARIFICATION resolved
Prerequisites: research.md complete
data-model.md:/contracts/Output: data-model.md, /contracts/*, quickstart.md, agent-specific file
This command is COMPLETE after generating planning artifacts.
After reporting:
plan.md pathresearch.md path (if generated)data-model.md path (if generated)contracts/ contents (if generated)YOU MUST STOP HERE.
Do NOT:
tasks.mdtasks/ subdirectoriesThe user will run /spec-kitty.tasks when they are ready to generate work packages.
Next suggested command: /spec-kitty.tasks (user must invoke this explicitly)
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.